Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
cXjy5Y6dXX.exe

Overview

General Information

Sample name:cXjy5Y6dXX.exe
renamed because original name is a hash value
Original sample name:c3159d554310d51982d1eaa16b3b5b87e8b5bc90598fd4f1749596d8bd8c9e4b.exe
Analysis ID:1571397
MD5:9725864712cc93935c58e8908dfa66d2
SHA1:40db5ea80d64ef64ec45d01c5e53767e44aadec0
SHA256:c3159d554310d51982d1eaa16b3b5b87e8b5bc90598fd4f1749596d8bd8c9e4b
Tags:C2-at-pastebin-yd1QnTjKexeuser-JAMESWT_MHT
Infos:

Detection

RHADAMANTHYS
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected RHADAMANTHYS Stealer
.NET source code contains potential unpacker
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Switches to a custom stack to bypass stack traces
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found inlined nop instructions (likely shell or obfuscated code)
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Searches for user specific document files
Sigma detected: Dllhost Internet Connection
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara detected Keylogger Generic

Classification

  • System is w10x64
  • cXjy5Y6dXX.exe (PID: 2172 cmdline: "C:\Users\user\Desktop\cXjy5Y6dXX.exe" MD5: 9725864712CC93935C58E8908DFA66D2)
    • OpenWith.exe (PID: 6532 cmdline: "C:\Windows\system32\openwith.exe" MD5: 0ED31792A7FFF811883F80047CBCFC91)
      • OpenWith.exe (PID: 5448 cmdline: "C:\Windows\system32\openwith.exe" MD5: E4A834784FA08C17D47A1E72429C5109)
        • wmplayer.exe (PID: 2172 cmdline: "C:\Program Files\Windows Media Player\wmplayer.exe" MD5: 89DCD2D4C0EC638AADC00D3530E07E1D)
    • dllhost.exe (PID: 2336 cmdline: "C:\Windows\system32\dllhost.exe" MD5: 08EB78E5BE019DF044C26B14703BD1FA)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
RhadamanthysAccording to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines.At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.
  • Sandworm
https://malpedia.caad.fkie.fraunhofer.de/details/win.rhadamanthys
{"C2 url": "https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e"}
SourceRuleDescriptionAuthorStrings
00000002.00000003.1892936653.000001D97E718000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmpJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
      00000002.00000003.1892527686.000001D97E718000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000002.00000003.1891865924.000001D97E718000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmpJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
            Click to see the 14 entries
            SourceRuleDescriptionAuthorStrings
            1.3.OpenWith.exe.5690000.7.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
              1.3.OpenWith.exe.5470000.6.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                0.3.cXjy5Y6dXX.exe.47d0000.7.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                  0.3.cXjy5Y6dXX.exe.45b0000.6.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                    Source: Network ConnectionAuthor: bartblaze: Data: DestinationIp: 193.124.205.63, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\System32\dllhost.exe, Initiated: true, ProcessId: 2336, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49767
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-12-09T10:57:17.773799+010028548242Potentially Bad Traffic193.124.205.637390192.168.2.449743TCP
                    2024-12-09T10:57:40.977743+010028548242Potentially Bad Traffic193.124.205.637390192.168.2.449766TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-12-09T10:56:30.769221+010028548021Domain Observed Used for C2 Detected193.124.205.637390192.168.2.449730TCP
                    2024-12-09T10:57:17.773799+010028548021Domain Observed Used for C2 Detected193.124.205.637390192.168.2.449743TCP
                    2024-12-09T10:57:40.977743+010028548021Domain Observed Used for C2 Detected193.124.205.637390192.168.2.449766TCP
                    2024-12-09T10:57:49.614905+010028548021Domain Observed Used for C2 Detected193.124.205.63443192.168.2.449767TCP
                    2024-12-09T10:57:56.693486+010028548021Domain Observed Used for C2 Detected193.124.205.63443192.168.2.449769TCP
                    2024-12-09T10:58:03.889138+010028548021Domain Observed Used for C2 Detected193.124.205.63443192.168.2.449770TCP
                    2024-12-09T10:58:11.168085+010028548021Domain Observed Used for C2 Detected193.124.205.63443192.168.2.449771TCP
                    2024-12-09T10:58:18.378284+010028548021Domain Observed Used for C2 Detected193.124.205.63443192.168.2.449772TCP
                    2024-12-09T10:58:25.530374+010028548021Domain Observed Used for C2 Detected193.124.205.63443192.168.2.449773TCP

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: cXjy5Y6dXX.exeAvira: detected
                    Source: cXjy5Y6dXX.exeMalware Configuration Extractor: Rhadamanthys {"C2 url": "https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e"}
                    Source: cXjy5Y6dXX.exeReversingLabs: Detection: 73%
                    Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                    Source: cXjy5Y6dXX.exeJoe Sandbox ML: detected
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C302258 CryptUnprotectData,2_3_00007DF41C302258
                    Source: cXjy5Y6dXX.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49767 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49769 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49770 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49771 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49772 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49773 version: TLS 1.2
                    Source: cXjy5Y6dXX.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: wkernel32.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1701161608.0000000002B00000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701232479.0000000004630000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703967518.0000000005590000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703898487.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2 source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: wkernelbase.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: ntdll.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1700442462.00000000047A0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700288468.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703408581.0000000005660000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703256425.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wntdll.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1700824435.0000000004750000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700675923.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703744621.0000000005610000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703610731.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: ntdll.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1700442462.00000000047A0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700288468.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703408581.0000000005660000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703256425.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wntdll.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1700824435.0000000004750000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700675923.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703744621.0000000005610000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703610731.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: win32u.pdb source: wmplayer.exe, 00000006.00000003.2474293998.0000019552AB0000.00000004.00000001.00020000.00000000.sdmp, wmplayer.exe, 00000006.00000003.2474329227.0000019552D90000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wkernelbase.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wkernel32.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1701161608.0000000002B00000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701232479.0000000004630000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703967518.0000000005590000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703898487.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: win32u.pdbGCTL source: wmplayer.exe, 00000006.00000003.2474293998.0000019552AB0000.00000004.00000001.00020000.00000000.sdmp, wmplayer.exe, 00000006.00000003.2474329227.0000019552D90000.00000004.00000001.00020000.00000000.sdmp
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppDataJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\DefaultJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\Local\Microsoft\InputPersonalization\TrainedDataStoreJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\Local\Microsoft\InputPersonalizationJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\LocalJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\Local\MicrosoftJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeCode function: 4x nop then dec esp2_3_00007DF41C30E261
                    Source: C:\Windows\System32\OpenWith.exeCode function: 4x nop then dec esp2_2_000001D97CC40511
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 4x nop then dec esp6_2_00000195528E5641

                    Networking

                    barindex
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:7390 -> 192.168.2.4:49730
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:7390 -> 192.168.2.4:49766
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:443 -> 192.168.2.4:49767
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:7390 -> 192.168.2.4:49743
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:443 -> 192.168.2.4:49770
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:443 -> 192.168.2.4:49773
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:443 -> 192.168.2.4:49772
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:443 -> 192.168.2.4:49769
                    Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 193.124.205.63:443 -> 192.168.2.4:49771
                    Source: Malware configuration extractorURLs: https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e
                    Source: global trafficTCP traffic: 193.124.205.63 ports 7390,0,3,443,7,9
                    Source: global trafficTCP traffic: 192.168.2.4:49730 -> 193.124.205.63:7390
                    Source: Joe Sandbox ViewASN Name: AS-REGRU AS-REGRU
                    Source: Joe Sandbox ViewJA3 fingerprint: caec7ddf6889590d999d7ca1b76373b6
                    Source: Network trafficSuricata IDS: 2854824 - Severity 2 - ETPRO JA3 HASH Suspected Malware Related Response : 193.124.205.63:7390 -> 192.168.2.4:49766
                    Source: Network trafficSuricata IDS: 2854824 - Severity 2 - ETPRO JA3 HASH Suspected Malware Related Response : 193.124.205.63:7390 -> 192.168.2.4:49743
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: unknownTCP traffic detected without corresponding DNS query: 193.124.205.63
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C334520 WSARecv,2_3_00007DF41C334520
                    Source: OpenWith.exe, OpenWith.exe, 00000002.00000003.1905007083.000001D97E725000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2254977500.000001D97E72B000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2265166668.000001D97E724000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1904967740.000001D97E721000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2265320418.000001D97E72B000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891561606.000001D97E738000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2572823315.000001D97E671000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000002.2576770717.000001D97E673000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2260947776.000001D97E72C000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1860501152.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2512051542.000001D97E728000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1886690134.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000002.2577025289.000001D97E72E000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2255219401.000001D97E725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e
                    Source: OpenWith.exe, 00000001.00000002.1802162479.000000000309C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e(
                    Source: OpenWith.exe, 00000001.00000002.1803067572.000000000594A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmpString found in binary or memory: https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3ekernelbasentdllkernel32GetProcessMitigation
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                    Source: OpenWith.exe, 00000002.00000003.1904637498.000001D97F173000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://discord.com
                    Source: OpenWith.exe, 00000002.00000003.1904637498.000001D97F173000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://discordapp.com
                    Source: OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
                    Source: OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
                    Source: OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                    Source: OpenWith.exe, 00000002.00000003.1894898672.000001D97E764000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E764000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com
                    Source: OpenWith.exe, 00000002.00000003.1901858513.000001D97E689000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894017600.000001D97E67B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016
                    Source: OpenWith.exe, 00000002.00000003.1892322694.000001D97F16F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples
                    Source: OpenWith.exe, 00000002.00000003.1901858513.000001D97E689000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894017600.000001D97E67B000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E764000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17
                    Source: OpenWith.exe, 00000002.00000003.1892322694.000001D97F16F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install
                    Source: OpenWith.exe, 00000002.00000003.1892527686.000001D97E764000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893118476.000001D97E764000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E764000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17t.mc_id=EnterPK201694ba2e0b-6
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
                    Source: OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49767 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49769 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49770 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49771 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49772 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 193.124.205.63:443 -> 192.168.2.4:49773 version: TLS 1.2
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DirectInput8Creatememstr_49afc89a-f
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: GetRawInputDatamemstr_a452f6ad-5
                    Source: Yara matchFile source: 1.3.OpenWith.exe.5690000.7.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 1.3.OpenWith.exe.5470000.6.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.3.cXjy5Y6dXX.exe.47d0000.7.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.3.cXjy5Y6dXX.exe.45b0000.6.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: cXjy5Y6dXX.exe PID: 2172, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: OpenWith.exe PID: 6532, type: MEMORYSTR
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E6430C7 NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,RtlFreeHeap,RtlFreeHeap,2_3_000001D97E6430C7
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30AC0C NtAcceptConnectPort,2_3_00007DF41C30AC0C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30ACE8 NtAcceptConnectPort,2_3_00007DF41C30ACE8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30ACC8 NtAcceptConnectPort,2_3_00007DF41C30ACC8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30BCC0 NtAcceptConnectPort,NtAcceptConnectPort,free,2_3_00007DF41C30BCC0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30AD14 NtAcceptConnectPort,2_3_00007DF41C30AD14
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30ADD4 NtAcceptConnectPort,2_3_00007DF41C30ADD4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30BE6C NtAcceptConnectPort,2_3_00007DF41C30BE6C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30AE5C NtAcceptConnectPort,2_3_00007DF41C30AE5C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30AF60 NtAcceptConnectPort,2_3_00007DF41C30AF60
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30AF40 NtAcceptConnectPort,2_3_00007DF41C30AF40
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30C7CC NtAcceptConnectPort,2_3_00007DF41C30C7CC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30D3C0 NtAcceptConnectPort,NtAcceptConnectPort,2_3_00007DF41C30D3C0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30B498 NtAcceptConnectPort,calloc,DuplicateHandle,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,2_3_00007DF41C30B498
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30C47C NtAcceptConnectPort,2_3_00007DF41C30C47C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30C70C NtAcceptConnectPort,2_3_00007DF41C30C70C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30C10C NtAcceptConnectPort,2_3_00007DF41C30C10C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30D2F4 NtAcceptConnectPort,NtAcceptConnectPort,2_3_00007DF41C30D2F4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_2_000001D97CC40AC8 NtAcceptConnectPort,NtAcceptConnectPort,2_2_000001D97CC40AC8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_2_000001D97CC415AC NtAcceptConnectPort,2_2_000001D97CC415AC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_2_000001D97CC41CD0 NtAcceptConnectPort,CloseHandle,2_2_000001D97CC41CD0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_2_000001D97CC41A90 NtAcceptConnectPort,NtAcceptConnectPort,2_2_000001D97CC41A90
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_00007DF4C3601CE8 calloc,CreateProcessW,NtResumeThread,CloseHandle,free,6_3_00007DF4C3601CE8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_00007DF4C3601958 calloc,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory,6_3_00007DF4C3601958
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F2990 NtAcceptConnectPort,6_2_00000195528F2990
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F29D4 NtAcceptConnectPort,6_2_00000195528F29D4
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F27B8 NtAcceptConnectPort,6_2_00000195528F27B8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F288C NtAcceptConnectPort,6_2_00000195528F288C
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F28B8 NtAcceptConnectPort,6_2_00000195528F28B8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F28E8 NtAcceptConnectPort,6_2_00000195528F28E8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F252C NtAcceptConnectPort,6_2_00000195528F252C
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F2418 NtAcceptConnectPort,6_2_00000195528F2418
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F2C64 NtAcceptConnectPort,6_2_00000195528F2C64
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00007DF4C3612704 NtQuerySystemInformation,malloc,NtQuerySystemInformation,6_2_00007DF4C3612704
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E65579385C NtQuerySystemInformation,8_2_000002E65579385C
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00C00BC10_2_00C00BC1
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E64279C2_3_000001D97E64279C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E641BA62_3_000001D97E641BA6
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E644A382_3_000001D97E644A38
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E645E7C2_3_000001D97E645E7C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E64557C2_3_000001D97E64557C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E6458FC2_3_000001D97E6458FC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E6424F72_3_000001D97E6424F7
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_000001D97E642C3C2_3_000001D97E642C3C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2E26342_3_00007DF41C2E2634
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3BEBE42_3_00007DF41C3BEBE4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2E5C242_3_00007DF41C2E5C24
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C34DC542_3_00007DF41C34DC54
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C386C602_3_00007DF41C386C60
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C32FDE02_3_00007DF41C32FDE0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3C3D842_3_00007DF41C3C3D84
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3D6DAC2_3_00007DF41C3D6DAC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3CAE002_3_00007DF41C3CAE00
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2F1E542_3_00007DF41C2F1E54
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C319F4C2_3_00007DF41C319F4C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3C9F682_3_00007DF41C3C9F68
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C310F042_3_00007DF41C310F04
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C33B7B82_3_00007DF41C33B7B8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3CA8BC2_3_00007DF41C3CA8BC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C30996C2_3_00007DF41C30996C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2FF95C2_3_00007DF41C2FF95C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2FD9F02_3_00007DF41C2FD9F0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3C69A82_3_00007DF41C3C69A8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C33CA382_3_00007DF41C33CA38
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C359AE02_3_00007DF41C359AE0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C32FA942_3_00007DF41C32FA94
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C349B382_3_00007DF41C349B38
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2FFB242_3_00007DF41C2FFB24
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C339B702_3_00007DF41C339B70
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3DCB042_3_00007DF41C3DCB04
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C32F3B82_3_00007DF41C32F3B8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3BA3D42_3_00007DF41C3BA3D4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3493F42_3_00007DF41C3493F4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3243F82_3_00007DF41C3243F8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C33A4302_3_00007DF41C33A430
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3CA4A02_3_00007DF41C3CA4A0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3325242_3_00007DF41C332524
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3495D02_3_00007DF41C3495D0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3375E42_3_00007DF41C3375E4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C33D5942_3_00007DF41C33D594
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2EF6242_3_00007DF41C2EF624
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3496E02_3_00007DF41C3496E0
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C35CFB42_3_00007DF41C35CFB4
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3DBFCC2_3_00007DF41C3DBFCC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3CAF802_3_00007DF41C3CAF80
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2E10582_3_00007DF41C2E1058
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C32F02C2_3_00007DF41C32F02C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3520BC2_3_00007DF41C3520BC
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3AA1682_3_00007DF41C3AA168
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C33B1042_3_00007DF41C33B104
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C37E24C2_3_00007DF41C37E24C
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3D72C82_3_00007DF41C3D72C8
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C3CB3182_3_00007DF41C3CB318
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_2_000001D97CC40C5C2_2_000001D97CC40C5C
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AC1F406_3_0000019552AC1F40
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AC027B6_3_0000019552AC027B
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AC27186_3_0000019552AC2718
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AC170E6_3_0000019552AC170E
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AC36606_3_0000019552AC3660
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_00007DF4C360392C6_3_00007DF4C360392C
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_00007DF4C3604EFC6_3_00007DF4C3604EFC
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_00007DF4C36022046_3_00007DF4C3602204
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528EC25C6_2_00000195528EC25C
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F2D246_2_00000195528F2D24
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528E26286_2_00000195528E2628
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955291E9846_2_000001955291E984
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955291F1D06_2_000001955291F1D0
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529159186_2_0000019552915918
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955291F9406_2_000001955291F940
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529001746_2_0000019552900174
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F5ADC6_2_00000195528F5ADC
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552914A506_2_0000019552914A50
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552923A4D6_2_0000019552923A4D
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552913A386_2_0000019552913A38
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529202706_2_0000019552920270
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F72706_2_00000195528F7270
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528F6F246_2_00000195528F6F24
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528FC7506_2_00000195528FC750
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552913F706_2_0000019552913F70
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529070946_2_0000019552907094
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529148D06_2_00000195529148D0
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528FD0106_2_00000195528FD010
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955291A81C6_2_000001955291A81C
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955290D8546_2_000001955290D854
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529208746_2_0000019552920874
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552920D906_2_0000019552920D90
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529155B06_2_00000195529155B0
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529195D46_2_00000195529195D4
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552914DE86_2_0000019552914DE8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552906D186_2_0000019552906D18
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529076846_2_0000019552907684
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529086B46_2_00000195529086B4
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552903EA46_2_0000019552903EA4
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_0000019552915EC86_2_0000019552915EC8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528FBEB86_2_00000195528FBEB8
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528FF6186_2_00000195528FF618
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528FE3986_2_00000195528FE398
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529104786_2_0000019552910478
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528E14D06_2_00000195528E14D0
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955291ECE46_2_000001955291ECE4
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528FDCE46_2_00000195528FDCE4
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_000001955291CC006_2_000001955291CC00
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195529264346_2_0000019552926434
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00007DF4C36222CC6_2_00007DF4C36222CC
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E65579737C8_2_000002E65579737C
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B3B408_2_000002E6557B3B40
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557963CF8_2_000002E6557963CF
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A53C88_2_000002E6557A53C8
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557BEBAC8_2_000002E6557BEBAC
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B2AA08_2_000002E6557B2AA0
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B22548_2_000002E6557B2254
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A92D48_2_000002E6557A92D4
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A9D308_2_000002E6557A9D30
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557C1E088_2_000002E6557C1E08
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E65579D6048_2_000002E65579D604
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E655798DF48_2_000002E655798DF4
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E655796DD18_2_000002E655796DD1
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E65579C5D48_2_000002E65579C5D4
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B25B48_2_000002E6557B25B4
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E65579BC688_2_000002E65579BC68
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557AE51C8_2_000002E6557AE51C
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557BC5008_2_000002E6557BC500
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A27A48_2_000002E6557A27A4
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557967848_2_000002E655796784
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557AF76C8_2_000002E6557AF76C
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A98188_2_000002E6557A9818
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E65579BFE48_2_000002E65579BFE4
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A6E948_2_000002E6557A6E94
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557BC6688_2_000002E6557BC668
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B46608_2_000002E6557B4660
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557BF6F18_2_000002E6557BF6F1
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A8EB88_2_000002E6557A8EB8
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A99988_2_000002E6557A9998
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557971928_2_000002E655797192
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557A89808_2_000002E6557A8980
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B41448_2_000002E6557B4144
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557B32108_2_000002E6557B3210
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557AA8608_2_000002E6557AA860
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557970BD8_2_000002E6557970BD
                    Source: cXjy5Y6dXX.exe, 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilename4 vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1700675923.00000000046D3000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701161608.0000000002B00000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \[FileVersionProductVersionFileDescriptionCompanyNameProductNameOriginalFilenameInternalNameLegalCopyright vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1700288468.0000000004728000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1700442462.0000000004926000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000049B1000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenameKernelbase.dllj% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1700824435.000000000487D000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701161608.0000000002B92000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenamekernel32j% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701232479.0000000004680000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenamekernel32j% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701232479.0000000004630000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \[FileVersionProductVersionFileDescriptionCompanyNameProductNameOriginalFilenameInternalNameLegalCopyright vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exe, 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: OriginalFilenameKernelbase.dllj% vs cXjy5Y6dXX.exe
                    Source: cXjy5Y6dXX.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 2.2.OpenWith.exe.1d97eead970.2.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                    Source: 2.3.OpenWith.exe.1d97eead970.2.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                    Source: 2.3.OpenWith.exe.1d97eead970.6.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                    Source: 2.3.OpenWith.exe.1d97eead970.3.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                    Source: 2.3.OpenWith.exe.1d97eead970.4.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                    Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@9/0@0/1
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C2E2634 CreateToolhelp32Snapshot,Thread32First,Thread32Next,CloseHandle,SuspendThread,2_3_00007DF41C2E2634
                    Source: C:\Windows\SysWOW64\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\MSCTF.Asm.{00000009-4fb3f26-9d18-66b568-627b8a85e4b6}
                    Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                    Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                    Source: OpenWith.exe, 00000002.00000003.1889277529.000001D97F1D6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890507524.000001D97F1D6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891731098.000001D97F16F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                    Source: OpenWith.exe, 00000002.00000003.1855797044.000001D97E7CD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2576319056.00007DF41C3E2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2570391467.000001D97ED1A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1847713311.000001D97E7CE000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
                    Source: cXjy5Y6dXX.exeReversingLabs: Detection: 73%
                    Source: unknownProcess created: C:\Users\user\Desktop\cXjy5Y6dXX.exe "C:\Users\user\Desktop\cXjy5Y6dXX.exe"
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"
                    Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\wmplayer.exe "C:\Program Files\Windows Media Player\wmplayer.exe"
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\wmplayer.exe "C:\Program Files\Windows Media Player\wmplayer.exe"Jump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"Jump to behavior
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeSection loaded: apphelp.dllJump to behavior
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: version.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: mpr.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: powrprof.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: umpdc.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: netapi32.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: dpapi.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: wkscli.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: cscapi.dllJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\System32\dllhost.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Windows\System32\dllhost.exeSection loaded: iphlpapi.dllJump to behavior
                    Source: C:\Windows\System32\dllhost.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Windows\System32\dllhost.exeSection loaded: dhcpcsvc.dllJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\7.0\Outlook\Profiles\OutlookJump to behavior
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                    Source: cXjy5Y6dXX.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                    Source: cXjy5Y6dXX.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: wkernel32.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1701161608.0000000002B00000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701232479.0000000004630000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703967518.0000000005590000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703898487.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2 source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: wkernelbase.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: ntdll.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1700442462.00000000047A0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700288468.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703408581.0000000005660000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703256425.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wntdll.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1700824435.0000000004750000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700675923.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703744621.0000000005610000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703610731.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: ntdll.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1700442462.00000000047A0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700288468.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703408581.0000000005660000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703256425.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wntdll.pdb source: cXjy5Y6dXX.exe, 00000000.00000003.1700824435.0000000004750000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1700675923.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703744621.0000000005610000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703610731.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: win32u.pdb source: wmplayer.exe, 00000006.00000003.2474293998.0000019552AB0000.00000004.00000001.00020000.00000000.sdmp, wmplayer.exe, 00000006.00000003.2474329227.0000019552D90000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wkernelbase.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: wkernel32.pdbUGP source: cXjy5Y6dXX.exe, 00000000.00000003.1701161608.0000000002B00000.00000004.00000001.00020000.00000000.sdmp, cXjy5Y6dXX.exe, 00000000.00000003.1701232479.0000000004630000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703967518.0000000005590000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000003.1703898487.0000000005470000.00000004.00000001.00020000.00000000.sdmp
                    Source: Binary string: win32u.pdbGCTL source: wmplayer.exe, 00000006.00000003.2474293998.0000019552AB0000.00000004.00000001.00020000.00000000.sdmp, wmplayer.exe, 00000006.00000003.2474329227.0000019552D90000.00000004.00000001.00020000.00000000.sdmp
                    Source: cXjy5Y6dXX.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                    Source: cXjy5Y6dXX.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                    Source: cXjy5Y6dXX.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                    Source: cXjy5Y6dXX.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                    Source: cXjy5Y6dXX.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

                    Data Obfuscation

                    barindex
                    Source: 2.3.OpenWith.exe.1d97eead970.2.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.3.OpenWith.exe.1d97eead970.2.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: 2.3.OpenWith.exe.1d97eea9d60.5.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.3.OpenWith.exe.1d97eea9d60.5.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: 2.3.OpenWith.exe.1d97eead970.3.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.3.OpenWith.exe.1d97eead970.3.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: 2.2.OpenWith.exe.1d97eead970.2.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.2.OpenWith.exe.1d97eead970.2.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: 2.3.OpenWith.exe.1d97eead970.4.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.3.OpenWith.exe.1d97eead970.4.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: 2.2.OpenWith.exe.1d97eea9d60.1.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.2.OpenWith.exe.1d97eea9d60.1.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: 2.3.OpenWith.exe.1d97eead970.6.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                    Source: 2.3.OpenWith.exe.1d97eead970.6.raw.unpack, Runtime.cs.Net Code: CoreMain
                    Source: cXjy5Y6dXX.exeStatic PE information: section name: .textbss
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C06A80 push edx; ret 0_3_00C06A81
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C04C95 push es; retf 0_3_00C04C91
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C04C62 push es; retf 0_3_00C04C91
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C05E69 push ebx; iretd 0_3_00C05E6A
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C061E2 push eax; retf 0_3_00C061F1
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C047A2 push ebp; iretd 0_3_00C047A3
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C02F50 push eax; retf 0_3_00C02F51
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C04170 push ecx; iretd 0_3_00C0417C
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C06777 push esi; ret 0_3_00C06782
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C04130 pushad ; ret 0_3_00C04138
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BAC01A push ds; iretd 0_2_00BAC036
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00C012F4 push ecx; ret 0_2_00C01307
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BA1436 push ds; retf 0_2_00BA143B
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BAE5F8 push ebx; ret 0_2_00BAE5F9
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C4B00 push edx; ret 1_3_030C4B01
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C2D15 push es; retf 1_3_030C2D11
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C21B0 pushad ; ret 1_3_030C21B8
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C0FD0 push eax; retf 1_3_030C0FD1
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C47F7 push esi; ret 1_3_030C4802
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C21F0 push ecx; iretd 1_3_030C21FC
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C2822 push ebp; iretd 1_3_030C2823
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C4262 push eax; retf 1_3_030C4271
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C3EE9 push ebx; iretd 1_3_030C3EEA
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C2CE2 push es; retf 1_3_030C2D11
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AB64B1 push rcx; retn 0023h6_3_0000019552AB64B2
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AB59B8 push rcx; ret 6_3_0000019552AB59B9
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_3_0000019552AB1AB8 push rax; iretd 6_3_0000019552AB1B01
                    Source: C:\Windows\System32\dllhost.exeCode function: 8_2_000002E6557C3590 push ebx; retf 8_2_000002E6557C3592
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\dllhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\dllhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior

                    Malware Analysis System Evasion

                    barindex
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeAPI/Special instruction interceptor: Address: 7FFE2220D044
                    Source: C:\Windows\SysWOW64\OpenWith.exeAPI/Special instruction interceptor: Address: 7FFE2220D044
                    Source: C:\Windows\SysWOW64\OpenWith.exeAPI/Special instruction interceptor: Address: 57FA83A
                    Source: C:\Windows\System32\dllhost.exeCode function: GetAdaptersInfo,8_2_000002E655792AC4
                    Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                    Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C369F04 GetSystemInfo,2_3_00007DF41C369F04
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppDataJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\DefaultJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\Local\Microsoft\InputPersonalization\TrainedDataStoreJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\Local\Microsoft\InputPersonalizationJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\LocalJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\Default\AppData\Local\MicrosoftJump to behavior
                    Source: OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkmbolicLinkSymbolicLink
                    Source: OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkLinkcLinkSymbolicLink
                    Source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp
                    Source: OpenWith.exe, 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DisableGuestVmNetworkConnectivity
                    Source: OpenWith.exe, 00000002.00000003.1861667423.000001D97E718000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMCIDevSymbol
                    Source: OpenWith.exe, 00000001.00000002.1802200658.00000000030F8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000001.00000002.1802200658.0000000003135000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmp, wmplayer.exe, 00000006.00000002.2913582811.0000019552B13000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                    Source: OpenWith.exe, 00000002.00000003.1904926871.000001D97E710000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-
                    Source: OpenWith.exe, 00000002.00000003.1861667423.000001D97E718000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: k&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkymbolicLinkcLinkSymbolicLink
                    Source: OpenWith.exe, 00000002.00000003.1904926871.000001D97E710000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&0
                    Source: OpenWith.exe, 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: EnableGuestVmNetworkConnectivity
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeProcess information queried: ProcessInformationJump to behavior
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF9AB4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00BF9AB4
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_3_00C02277 mov eax, dword ptr fs:[00000030h]0_3_00C02277
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00C02277 mov eax, dword ptr fs:[00000030h]0_2_00C02277
                    Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 1_3_030C0283 mov eax, dword ptr fs:[00000030h]1_3_030C0283
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF4E5A GetProcessHeap,RtlAllocateHeap,GetModuleFileNameW,_wcsrchr,lstrlenW,GetProcessHeap,RtlFreeHeap,MulDiv,0_2_00BF4E5A
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF9AB4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00BF9AB4
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF5A33 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00BF5A33
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF55A9 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00BF55A9

                    HIPS / PFW / Operating System Protection Evasion

                    barindex
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeMemory allocated: C:\Windows\System32\dllhost.exe base: 2E655790000 protect: page read and writeJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeMemory written: C:\Windows\System32\dllhost.exe base: 2E655790000Jump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeMemory written: C:\Windows\System32\dllhost.exe base: 7FF70F3314E0Jump to behavior
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\wmplayer.exe "C:\Program Files\Windows Media Player\wmplayer.exe"Jump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"Jump to behavior
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF5845 cpuid 0_2_00BF5845
                    Source: C:\Windows\System32\OpenWith.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                    Source: C:\Windows\SysWOW64\OpenWith.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\dllhost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C301B18 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,2_3_00007DF41C301B18
                    Source: C:\Users\user\Desktop\cXjy5Y6dXX.exeCode function: 0_2_00BF5490 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00BF5490
                    Source: C:\Windows\SysWOW64\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                    Stealing of Sensitive Information

                    barindex
                    Source: Yara matchFile source: 00000000.00000003.1699421762.0000000000CF0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1733027808.00000000053DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1702483647.0000000004BC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000003.1702281326.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000002.1802524391.0000000004BF0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: OpenWith.exe, 00000002.00000003.1905007083.000001D97E725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: !CP:Defichain-Electrum
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\ElectronCash\config
                    Source: OpenWith.exe, 00000002.00000003.1905007083.000001D97E725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \user\AppData\Roaming\com.liberty.jaxx
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: passphrase.json
                    Source: OpenWith.exe, 00000002.00000003.1905007083.000001D97E725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Exodus
                    Source: OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\Coinomi\Coinomi\wallets
                    Source: OpenWith.exe, 00000002.00000002.2576620197.000001D97CCA8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \??\C:\Users\user\AppData\Roaming\Ledger Liveletsg
                    Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Bitcoin\Bitcoin-QtJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Martin Prikryl\WinSCP 2\Configuration\SecurityJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrialsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_storeJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web ApplicationsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension SettingsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\NetworkJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_storeJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session StorageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\bde1cb97-a9f1-4568-9626-b993438e38e1Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\fccd7e85-a1ff-4466-9ff5-c20d62f6e0a2Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_agimnkijcaahngcdmfeangaknmldoomlJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension RulesJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\4d5b179f-bba0-432a-b376-b1fb347ae64fJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync DataJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code CacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\settings\main\ms-language-packs\browser\newtabJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\defJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\settingsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\z6bny8rn.defaultJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download ServiceJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension ScriptsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadataJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasmJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldbJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databasesJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest ResourcesJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\SessionsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\FilesJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\57328c1e-640f-4b62-a5a0-06d479b676c2Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\safebrowsingJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_dbJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache\Cache_DataJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cache2\doomedJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\settings\main\ms-language-packs\browserJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement TrackerJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dirJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mpnpojknpmmopombnjdcgaaiekajbnjbJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\jsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\2cb4572a-4cab-4e12-9740-762c0a50285fJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldbJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dirJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_dbJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\CacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\extJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\startupCacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aghbiahbpaijignceidepookljebhfakJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\TempJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\e8d04e65-de13-4e7d-b232-291855cace25Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local StorageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\thumbnailsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\03a1fc40-7474-4824-8fa1-eaa75003e98aJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local StorageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\StorageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\ProfilesJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-releaseJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\safebrowsing\google4Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhiJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cache2\trash16598Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloadsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\8ad0d94c-ca05-4c9d-8177-48569175e875Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cache2\entriesJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session StorageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\DefaultJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmiedaJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_prediction_model_downloads\5bc1a347-c482-475c-a573-03c10998aeeaJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cache2Jump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\jsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM StoreJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync App SettingsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation PlatformJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabaseJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics DatabaseJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm\index-dirJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\WebStorageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code CacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js\index-dirJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fhihpiojkbmbpdjeoajapmgkhlnakfjfJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\NetworkJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabaseJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension SettingsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\settings\mainJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fqs92o4p.default-release\settings\main\ms-language-packsJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasmJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storageJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension StateJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kefjledonklijopmnomlcbpllchaibagJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\EncryptionJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCacheJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_dbJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDBJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncmJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookJump to behavior
                    Source: C:\Windows\System32\OpenWith.exeDirectory queried: C:\Users\user\Documents\DVWHKMNFNNJump to behavior
                    Source: Yara matchFile source: 00000002.00000003.1892936653.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1892527686.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1891865924.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: OpenWith.exe PID: 5448, type: MEMORYSTR

                    Remote Access Functionality

                    barindex
                    Source: Yara matchFile source: 00000000.00000003.1699421762.0000000000CF0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1733027808.00000000053DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000003.1702483647.0000000004BC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000003.1702281326.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000002.1802524391.0000000004BF0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C301B18 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,2_3_00007DF41C301B18
                    Source: C:\Windows\System32\OpenWith.exeCode function: 2_3_00007DF41C334088 socket,bind,2_3_00007DF41C334088
                    Source: C:\Program Files\Windows Media Player\wmplayer.exeCode function: 6_2_00000195528ECDF4 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,6_2_00000195528ECDF4
                    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                    Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
                    Windows Management Instrumentation
                    1
                    DLL Side-Loading
                    212
                    Process Injection
                    1
                    Virtualization/Sandbox Evasion
                    1
                    OS Credential Dumping
                    1
                    System Time Discovery
                    Remote Services1
                    Email Collection
                    22
                    Encrypted Channel
                    Exfiltration Over Other Network MediumAbuse Accessibility Features
                    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                    DLL Side-Loading
                    212
                    Process Injection
                    21
                    Input Capture
                    131
                    Security Software Discovery
                    Remote Desktop Protocol21
                    Input Capture
                    1
                    Non-Standard Port
                    Exfiltration Over BluetoothNetwork Denial of Service
                    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
                    Obfuscated Files or Information
                    1
                    Credentials in Registry
                    1
                    Virtualization/Sandbox Evasion
                    SMB/Windows Admin Shares1
                    Archive Collected Data
                    1
                    Ingress Tool Transfer
                    Automated ExfiltrationData Encrypted for Impact
                    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                    Software Packing
                    NTDS2
                    Process Discovery
                    Distributed Component Object Model21
                    Data from Local System
                    11
                    Application Layer Protocol
                    Traffic DuplicationData Destruction
                    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                    DLL Side-Loading
                    LSA Secrets1
                    System Network Configuration Discovery
                    SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials11
                    File and Directory Discovery
                    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync136
                    System Information Discovery
                    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    cXjy5Y6dXX.exe74%ReversingLabsWin32.Spyware.Rhadamanthys
                    cXjy5Y6dXX.exe100%AviraTR/Redcap.olqyx
                    cXjy5Y6dXX.exe100%Joe Sandbox ML
                    No Antivirus matches
                    No Antivirus matches
                    No Antivirus matches
                    SourceDetectionScannerLabelLink
                    https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e0%Avira URL Cloudsafe
                    https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e(0%Avira URL Cloudsafe
                    https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3ekernelbasentdllkernel32GetProcessMitigation0%Avira URL Cloudsafe
                    No contacted domains info
                    NameMaliciousAntivirus DetectionReputation
                    https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3etrue
                    • Avira URL Cloud: safe
                    unknown
                    NameSourceMaliciousAntivirus DetectionReputation
                    https://ac.ecosia.org/autocomplete?q=OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://duckduckgo.com/chrome_newtabOpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        https://discord.comOpenWith.exe, 00000002.00000003.1904637498.000001D97F173000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://duckduckgo.com/ac/?q=OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17t.mc_id=EnterPK201694ba2e0b-6OpenWith.exe, 00000002.00000003.1892527686.000001D97E764000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893118476.000001D97E764000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E764000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://www.google.com/images/branding/product/ico/googleg_lodp.icoOpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://support.office.comOpenWith.exe, 00000002.00000003.1894898672.000001D97E764000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E764000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3e(OpenWith.exe, 00000001.00000002.1802162479.000000000309C000.00000004.00000010.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17InstallOpenWith.exe, 00000002.00000003.1892322694.000001D97F16F000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchOpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://discordapp.comOpenWith.exe, 00000002.00000003.1904637498.000001D97F173000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016OpenWith.exe, 00000002.00000003.1901858513.000001D97E689000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894017600.000001D97E67B000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016ExamplesOpenWith.exe, 00000002.00000003.1892322694.000001D97F16F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                high
                                                https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17OpenWith.exe, 00000002.00000003.1901858513.000001D97E689000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894017600.000001D97E67B000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E764000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  https://www.ecosia.org/newtab/OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    high
                                                    https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=OpenWith.exe, 00000002.00000003.1896175031.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1900847894.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1898559412.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1887761148.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892936653.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1890892896.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894325206.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1888694128.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1892527686.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1897381631.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1899031471.000001D97E6BC000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1891865924.000001D97E6B8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1894799613.000001D97E6BA000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000003.1889700748.000001D97E6BD000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      high
                                                      https://193.124.205.63:7390/1d7c07d7f0b063/xtt6wabb.8qt3ekernelbasentdllkernel32GetProcessMitigationOpenWith.exe, 00000001.00000002.1803067572.000000000594A000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      • No. of IPs < 25%
                                                      • 25% < No. of IPs < 50%
                                                      • 50% < No. of IPs < 75%
                                                      • 75% < No. of IPs
                                                      IPDomainCountryFlagASNASN NameMalicious
                                                      193.124.205.63
                                                      unknownRussian Federation
                                                      197695AS-REGRUtrue
                                                      Joe Sandbox version:41.0.0 Charoite
                                                      Analysis ID:1571397
                                                      Start date and time:2024-12-09 10:55:31 +01:00
                                                      Joe Sandbox product:CloudBasic
                                                      Overall analysis duration:0h 8m 22s
                                                      Hypervisor based Inspection enabled:false
                                                      Report type:full
                                                      Cookbook file name:default.jbs
                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                      Number of analysed new started processes analysed:9
                                                      Number of new started drivers analysed:0
                                                      Number of existing processes analysed:0
                                                      Number of existing drivers analysed:0
                                                      Number of injected processes analysed:0
                                                      Technologies:
                                                      • HCA enabled
                                                      • EGA enabled
                                                      • AMSI enabled
                                                      Analysis Mode:default
                                                      Analysis stop reason:Timeout
                                                      Sample name:cXjy5Y6dXX.exe
                                                      renamed because original name is a hash value
                                                      Original Sample Name:c3159d554310d51982d1eaa16b3b5b87e8b5bc90598fd4f1749596d8bd8c9e4b.exe
                                                      Detection:MAL
                                                      Classification:mal100.troj.spyw.evad.winEXE@9/0@0/1
                                                      EGA Information:
                                                      • Successful, ratio: 80%
                                                      HCA Information:
                                                      • Successful, ratio: 61%
                                                      • Number of executed functions: 156
                                                      • Number of non-executed functions: 20
                                                      Cookbook Comments:
                                                      • Found application associated with file extension: .exe
                                                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                                      • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                      • Execution Graph export aborted for target OpenWith.exe, PID 6532 because there are no executed function
                                                      • Not all processes where analyzed, report is missing behavior information
                                                      • Report size getting too big, too many NtOpenFile calls found.
                                                      • Report size getting too big, too many NtOpenKeyEx calls found.
                                                      • Report size getting too big, too many NtQueryValueKey calls found.
                                                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                      • VT rate limit hit for: cXjy5Y6dXX.exe
                                                      TimeTypeDescription
                                                      04:57:44API Interceptor1x Sleep call for process: wmplayer.exe modified
                                                      No context
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      AS-REGRUSRT68.exeGet hashmaliciousFormBookBrowse
                                                      • 194.58.112.174
                                                      New Order.exeGet hashmaliciousFormBookBrowse
                                                      • 31.31.196.17
                                                      72STaC6BmljfbIQ.exeGet hashmaliciousFormBookBrowse
                                                      • 194.58.112.174
                                                      attached invoice.exeGet hashmaliciousFormBookBrowse
                                                      • 31.31.196.17
                                                      specification and drawing.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                                      • 194.58.112.174
                                                      Pre Alert PO TVKJEANSA00967.bat.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                                      • 194.58.112.174
                                                      DO-COSU6387686280.pdf.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                                      • 37.140.192.206
                                                      Fi#U015f.exeGet hashmaliciousFormBookBrowse
                                                      • 31.31.196.177
                                                      ZAMOWIEN.BAT.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                      • 31.31.196.177
                                                      CV Lic H&S Olivetti Renzo.exeGet hashmaliciousFormBookBrowse
                                                      • 194.58.112.174
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      caec7ddf6889590d999d7ca1b76373b6payload_1.vbsGet hashmaliciousGuLoader, RHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      List of Required items xlsx.vbsGet hashmaliciousGuLoader, RHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      ab.vbsGet hashmaliciousGuLoader, RHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      download.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      wE1inOhJA5.msiGet hashmaliciousRemcos, RHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      0a0#U00a0.jsGet hashmaliciousRHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      UGcjMkPWwW.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      XAhzDHAVZ2.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      TctqdRX5Wq.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      g753nr4GI9.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                      • 193.124.205.63
                                                      No context
                                                      No created / dropped files found
                                                      File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                      Entropy (8bit):5.554215795001397
                                                      TrID:
                                                      • Win32 Executable (generic) a (10002005/4) 99.96%
                                                      • Generic Win/DOS Executable (2004/3) 0.02%
                                                      • DOS Executable Generic (2002/1) 0.02%
                                                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                      File name:cXjy5Y6dXX.exe
                                                      File size:433'152 bytes
                                                      MD5:9725864712cc93935c58e8908dfa66d2
                                                      SHA1:40db5ea80d64ef64ec45d01c5e53767e44aadec0
                                                      SHA256:c3159d554310d51982d1eaa16b3b5b87e8b5bc90598fd4f1749596d8bd8c9e4b
                                                      SHA512:33727107b4cd3b52656d0f90c43692bb203fe70ff09f11ea3ff3a91ed0768db4863a6e9e2fd4658a0b9d707c3746fe834e2ded711cd531b981cad67d9146ea19
                                                      SSDEEP:6144:YAYM3ZEWqf/qwPF7LR5W8ZJ74zmRiOFBbMh9q/JSW3ChNeK06iiRzmi0F9:YWBqf/qq3R5W8ZB4zmRzba5sViRUF9
                                                      TLSH:1A94F14CB5D2C175E9724A32C85496F05E3DBD50CB179EE773A43E293A302E05E32A7A
                                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......UP.|.1@/.1@/.1@/ZIC..1@/ZIE..1@/ZID..1@/.NE.71@/.ND..1@/.NC..1@/ZIA..1@/.1A/v1@/+.D..1@/.1@/.1@/+../.1@/+.B..1@/Rich.1@/.......
                                                      Icon Hash:100109193979390f
                                                      Entrypoint:0x455235
                                                      Entrypoint Section:.text
                                                      Digitally signed:false
                                                      Imagebase:0x400000
                                                      Subsystem:windows gui
                                                      Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                      Time Stamp:0x645F7B5F [Sat May 13 11:58:23 2023 UTC]
                                                      TLS Callbacks:
                                                      CLR (.Net) Version:
                                                      OS Version Major:6
                                                      OS Version Minor:0
                                                      File Version Major:6
                                                      File Version Minor:0
                                                      Subsystem Version Major:6
                                                      Subsystem Version Minor:0
                                                      Import Hash:1cda62d85d4d631949032bd51ab17a29
                                                      Instruction
                                                      call 00007F0CC851DE08h
                                                      jmp 00007F0CC851D9DFh
                                                      push ebp
                                                      mov ebp, esp
                                                      mov eax, dword ptr [ebp+08h]
                                                      push esi
                                                      mov ecx, dword ptr [eax+3Ch]
                                                      add ecx, eax
                                                      movzx eax, word ptr [ecx+14h]
                                                      lea edx, dword ptr [ecx+18h]
                                                      add edx, eax
                                                      movzx eax, word ptr [ecx+06h]
                                                      imul esi, eax, 28h
                                                      add esi, edx
                                                      cmp edx, esi
                                                      je 00007F0CC851DB7Bh
                                                      mov ecx, dword ptr [ebp+0Ch]
                                                      cmp ecx, dword ptr [edx+0Ch]
                                                      jc 00007F0CC851DB6Ch
                                                      mov eax, dword ptr [edx+08h]
                                                      add eax, dword ptr [edx+0Ch]
                                                      cmp ecx, eax
                                                      jc 00007F0CC851DB6Eh
                                                      add edx, 28h
                                                      cmp edx, esi
                                                      jne 00007F0CC851DB4Ch
                                                      xor eax, eax
                                                      pop esi
                                                      pop ebp
                                                      ret
                                                      mov eax, edx
                                                      jmp 00007F0CC851DB5Bh
                                                      push esi
                                                      call 00007F0CC851E2F5h
                                                      test eax, eax
                                                      je 00007F0CC851DB82h
                                                      mov eax, dword ptr fs:[00000018h]
                                                      mov esi, 004798E4h
                                                      mov edx, dword ptr [eax+04h]
                                                      jmp 00007F0CC851DB66h
                                                      cmp edx, eax
                                                      je 00007F0CC851DB72h
                                                      xor eax, eax
                                                      mov ecx, edx
                                                      lock cmpxchg dword ptr [esi], ecx
                                                      test eax, eax
                                                      jne 00007F0CC851DB52h
                                                      xor al, al
                                                      pop esi
                                                      ret
                                                      mov al, 01h
                                                      pop esi
                                                      ret
                                                      push ebp
                                                      mov ebp, esp
                                                      cmp dword ptr [ebp+08h], 00000000h
                                                      jne 00007F0CC851DB69h
                                                      mov byte ptr [004798E8h], 00000001h
                                                      call 00007F0CC851E0E0h
                                                      call 00007F0CC851EDC4h
                                                      test al, al
                                                      jne 00007F0CC851DB66h
                                                      xor al, al
                                                      pop ebp
                                                      ret
                                                      call 00007F0CC85218D3h
                                                      test al, al
                                                      jne 00007F0CC851DB6Ch
                                                      push 00000000h
                                                      call 00007F0CC851EDCBh
                                                      pop ecx
                                                      jmp 00007F0CC851DB4Bh
                                                      mov al, 01h
                                                      pop ebp
                                                      ret
                                                      push ebp
                                                      mov ebp, esp
                                                      cmp byte ptr [004798E9h], 00000000h
                                                      je 00007F0CC851DB66h
                                                      mov al, 01h
                                                      NameVirtual AddressVirtual Size Is in Section
                                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_IMPORT0x7794c0x50.rdata
                                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x7b0000x1498.rsrc
                                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x7d0000xf40.reloc
                                                      IMAGE_DIRECTORY_ENTRY_DEBUG0x76e400x1c.rdata
                                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x76d800x40.rdata
                                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_IAT0x720000x164.rdata
                                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                      .text0x10000x605330x6060045fcf518887f4fc5fe7868d86ca89d6aFalse0.6513785870622568data5.481499832906695IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                      .textbss0x620000x100000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                      .rdata0x720000x611e0x6200a34d227343b26b448c2fbf0c5a1bcb3eFalse0.4164540816326531data4.833087325483854IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                      .data0x790000x13200xa0062f04be8889719ef402cb8fde140eaa0False0.1546875DOS executable (block device driver \277DN)2.040813955897899IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                      .rsrc0x7b0000x14980x1600f89593d6580680aa51828d8936d570bdFalse0.2762784090909091data3.8859060526590135IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                      .reloc0x7d0000xf400x1000aee597d25215ac27829b6f1ddaaf38bdFalse0.755615234375data6.454880869273466IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                                      RT_ICON0x7b0f00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2834 x 2834 px/mEnglishUnited States0.2619606003752345
                                                      RT_GROUP_ICON0x7c1980x14dataEnglishUnited States1.1
                                                      RT_VERSION0x7c1b00x2e4dataEnglishUnited States0.4554054054054054
                                                      DLLImport
                                                      KERNEL32.dllCloseHandle, HeapCreate, HeapDestroy, HeapAlloc, HeapFree, GetProcessHeap, WaitForSingleObject, CreateEventA, GetModuleFileNameW, GetModuleHandleA, MulDiv, lstrlenW, WriteConsoleW, CreateFileW, SetFilePointerEx, GetConsoleMode, GetConsoleOutputCP, FlushFileBuffers, HeapReAlloc, HeapSize, LCMapStringW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetStartupInfoW, IsProcessorFeaturePresent, GetModuleHandleW, GetCurrentProcess, TerminateProcess, RtlUnwind, GetLastError, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, EncodePointer, RaiseException, GetStdHandle, WriteFile, ExitProcess, GetModuleHandleExW, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetStdHandle, GetFileType, GetStringTypeW, DecodePointer
                                                      USER32.dllLoadImageA, GetIconInfo, DialogBoxParamA, EndDialog, SendMessageW, InflateRect, SetForegroundWindow, OffsetRect, GetWindowLongA, SendDlgItemMessageA, GetDlgItem, SetWindowPos, UnionRect
                                                      ole32.dllCoInitializeEx, CoTaskMemFree
                                                      Language of compilation systemCountry where language is spokenMap
                                                      EnglishUnited States
                                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                      2024-12-09T10:56:30.769221+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.637390192.168.2.449730TCP
                                                      2024-12-09T10:57:17.773799+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.637390192.168.2.449743TCP
                                                      2024-12-09T10:57:17.773799+01002854824ETPRO JA3 HASH Suspected Malware Related Response2193.124.205.637390192.168.2.449743TCP
                                                      2024-12-09T10:57:40.977743+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.637390192.168.2.449766TCP
                                                      2024-12-09T10:57:40.977743+01002854824ETPRO JA3 HASH Suspected Malware Related Response2193.124.205.637390192.168.2.449766TCP
                                                      2024-12-09T10:57:49.614905+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.63443192.168.2.449767TCP
                                                      2024-12-09T10:57:56.693486+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.63443192.168.2.449769TCP
                                                      2024-12-09T10:58:03.889138+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.63443192.168.2.449770TCP
                                                      2024-12-09T10:58:11.168085+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.63443192.168.2.449771TCP
                                                      2024-12-09T10:58:18.378284+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.63443192.168.2.449772TCP
                                                      2024-12-09T10:58:25.530374+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1193.124.205.63443192.168.2.449773TCP
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Dec 9, 2024 10:56:29.266041040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:29.385760069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:29.388334036 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:29.388516903 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:29.507842064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:30.642461061 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:30.647236109 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:30.769221067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.041929960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.058027983 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.177429914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475562096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475626945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475646973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475658894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475671053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475672960 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.475693941 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.475879908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475891113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475903034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475914955 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.475915909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.475931883 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.484177113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.484231949 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.486864090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.486984968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.487025976 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.596806049 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.640372038 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.669027090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.669115067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.669159889 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.672894001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.674273968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.674323082 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.674452066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.678677082 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.678733110 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.678828955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.686338902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.686408043 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.686515093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.693977118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.693999052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.694041967 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.702315092 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.702369928 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.702600956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.709254026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.709304094 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.709417105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.716866970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.716921091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.717015982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.724447012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.724458933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.724488020 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.734200001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.734211922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.735089064 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.740206957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.740220070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.740262985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.762207985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.762222052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.762280941 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.790204048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.843489885 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.859714031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.859829903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.859870911 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.863540888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.863636017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.863673925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.871184111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.873917103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.873961926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.873964071 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.881664038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.881685019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.881706953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.889240026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.889288902 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.889343023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.896941900 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.896994114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.897031069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.911461115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.911514997 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.911546946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.911561012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.911601067 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.911647081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.915095091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.915132999 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.915148020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.918313980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.918364048 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.918430090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.922956944 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.923028946 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.923130035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.927575111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.927638054 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.927644968 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.932182074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.932245970 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.932292938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.936697960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.936753988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.936860085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.941488028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.941538095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.941538095 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.946012974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.946176052 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.946261883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.950536966 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.950587988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.950628996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.955239058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.955277920 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.955369949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.959856987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.959906101 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.960026026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.964296103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.964334011 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:31.964376926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.968879938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:31.968924046 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.052011013 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.052138090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.052248001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.054215908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.054281950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.054330111 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.058655977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.058813095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.058862925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.063096046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.063209057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.063251019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.067627907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.067747116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.067794085 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.071912050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.071980953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.072029114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.075917959 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.076064110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.076109886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.079902887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.080013037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.080058098 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.083781004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.083821058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.083863020 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.087395906 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.087498903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.087544918 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.091072083 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.091140985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.091181993 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.094727039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.094837904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.094875097 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.098001957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.098128080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.098176003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.101104975 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.101124048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.101161957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.104157925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.104340076 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.104378939 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.107702017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.107779026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.107819080 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.110568047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.110625982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.110667944 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.113723040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.113780975 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.113820076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.116058111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.116226912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.116265059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.118997097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.119185925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.119230986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.122085094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.122176886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.122216940 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.125145912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.125158072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.125197887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.128118992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.128238916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.128278017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.131092072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.131247044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.131288052 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.134135962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.134433031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.134475946 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.137132883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.137356043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.137399912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.140063047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.140218019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.140259027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.143213034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.143299103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.143335104 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.146172047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.146222115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.146266937 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.149502993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.149600983 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.149641991 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.152106047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.152312994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.152359009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.155200005 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.202883959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.244259119 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.245522022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.245573997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.245599985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.246192932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.246237040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.248239994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.248255014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.248300076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.252861023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.252872944 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.252916098 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.254196882 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.254209995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.254261017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.255645990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.255659103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.255702019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.258060932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.258071899 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.258115053 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.260284901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.262227058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.262294054 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.263487101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.263511896 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.263572931 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.266228914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.266247034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.266299963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.268660069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.268672943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.268718958 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.270214081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.270226002 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.270281076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.272592068 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.272603035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.272660971 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.274230003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.274244070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.274292946 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.275862932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.275882006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.275922060 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.278081894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.278094053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.278145075 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.279916048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.282025099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.282056093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.282063961 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.282181978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.282217026 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.284265041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.285834074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.285876036 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.288367987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.288378954 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.288391113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.288403034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.288419962 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.288455009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.291546106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.291558027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.291610003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.293119907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.293131113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.293169975 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.296964884 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.296977997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.296991110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.297003031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.297019005 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.297048092 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.300338984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.300355911 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.300405025 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.302217007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.302229881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.302264929 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.304770947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.304783106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.304795980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.304838896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.306195974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.306241035 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.309246063 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.309263945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.309276104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.309309959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.310204983 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.310247898 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.313327074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.313338995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.313349009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.313359976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.313390017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.313412905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.315362930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.315375090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.315408945 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.317327023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.317337990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.317393064 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.321391106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.321403027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.321413040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.321444988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.322190046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.322243929 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.323463917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.325875044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.325891018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.325906038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.325927019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.325942993 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.327831984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.327845097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.327889919 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.330193996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.330205917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.330248117 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.332370043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.332381964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.332421064 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.334193945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.334206104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.334249020 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.335890055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.337912083 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.337943077 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.337958097 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.338186026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.338227987 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.340351105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.340362072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.340400934 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.342221022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.342233896 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.342273951 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.344261885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.344274044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.344312906 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.347358942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.347371101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.347410917 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.349296093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.349308014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.349345922 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.352391958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.352404118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.352416039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.352447033 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.354198933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.354243040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.356174946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.356187105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.356228113 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.436716080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.436729908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.436887026 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.437364101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.437779903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.437827110 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.441731930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.441749096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.441792965 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.441894054 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.441906929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.441945076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.443803072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.443938017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.443979025 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.445436001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.445569992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.445609093 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.447098017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.447118044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.447159052 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.448472023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.448483944 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.448523045 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.450094938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.450218916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.450262070 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.451637030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.451649904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.451689959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.453212023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.453345060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.453386068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.454689980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.454833031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.454873085 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.456243038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.456257105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.456288099 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.457577944 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.457727909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.457767010 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.459352970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.459527969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.459577084 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.459815979 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.460273027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.460314035 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.461961031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.462106943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.462148905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.463500977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.463520050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.463557959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.464781046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.464792967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.464824915 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.464831114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.465029955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.465070963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.466197968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.466665983 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.466708899 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.467806101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.467818022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.467850924 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.469057083 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.469069004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.469124079 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.470566988 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.470578909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.470623970 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.471780062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.471904039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.471945047 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.473640919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.473653078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.473695040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.474560022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.474580050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.474613905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.475857019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.475868940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.475970984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.477169991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.477644920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.477688074 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.478569031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.478585005 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.478621006 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.479795933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.480195999 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.480236053 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.482815027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.482826948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.482839108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.482851982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.482860088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.482889891 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.483956099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.483969927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.484112978 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.485500097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.485517025 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.485589981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.486325979 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.486454964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.486498117 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.487853050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.487865925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.487907887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.489013910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.489087105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.489126921 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.490346909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.490428925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.490468979 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.491934061 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.492032051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.492068052 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.492892981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.493637085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.493683100 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.494298935 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.494494915 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.494534969 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.495732069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.495748043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.495789051 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.496953011 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.498234987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.498250008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.498281002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.498405933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.498445034 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.499510050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.499747038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.499783993 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.500833988 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.500920057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.500960112 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.502322912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.502348900 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.502383947 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.503540993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.503689051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.503730059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.504796982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.504967928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.505007029 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.506169081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.506217957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.506253958 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.507606983 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.507623911 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.507661104 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.508938074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.508951902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.508991957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.510138035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.562280893 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.636976004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.637023926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.637084961 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.637454033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.637494087 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.637528896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.638602018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.638617039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.638653040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.639462948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.639579058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.639621019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.640686035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.640701056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.640733004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.641556978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.641654015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.641691923 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.642544031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.642652035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.642688036 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.643517971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.643680096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.643713951 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.644546986 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.644687891 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.644722939 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.645632029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.645692110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.645726919 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.646678925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.646689892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.646723032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.647587061 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.647799969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.647844076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.648591995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.648694038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.648734093 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.649638891 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.649717093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.649751902 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.650684118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.650765896 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.650804996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.651792049 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.651804924 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.651839018 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.652652979 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.652718067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.652755022 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.653744936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.653794050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.653831959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.654743910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.654756069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.654792070 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.655774117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.655858994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.655889034 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.656781912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.656831026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.656877041 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.658051968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.658063889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.658093929 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.658881903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.658894062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.658921003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.659830093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.659914970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.659946918 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.660832882 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.660926104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.660964966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.661883116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.661946058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.661981106 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.663052082 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.663063049 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.663090944 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.663909912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.664026022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.664061069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.664910078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.665050983 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.665086031 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.665923119 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.666075945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.666115046 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.666943073 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.667166948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.667206049 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.667951107 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.668046951 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.668085098 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.669017076 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.669075012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.669111967 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.670027971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.670047045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.670084953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.671040058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.671140909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.671180010 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.672034025 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.672157049 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.672195911 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.673089027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.673141956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.673178911 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.674092054 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.674269915 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.674309969 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.675086021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.675225019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.675278902 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.676115990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.676265955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.676305056 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.677155018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.677222967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.677261114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.678241014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.678252935 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.678303957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.679224014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.679259062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.679291010 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.680172920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.680352926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.680388927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.681238890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.681375980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.681416988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.682229042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.682396889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.682431936 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.683289051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.683362007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.683397055 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.684257984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.684392929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.684431076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.685338974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.685408115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.685445070 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.686304092 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.686348915 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.686387062 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.687320948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.687365055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.687396049 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.688343048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.688451052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.688493967 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.689378023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.689471006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.689508915 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.690387964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.734138966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.821057081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.821244001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.821301937 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.821474075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.821486950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.821618080 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.822441101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.822560072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.822607040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.823519945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.823546886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.823580980 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.824551105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.824800968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.824840069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.825506926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.825639963 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.825675964 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.826518059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.826772928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.826807022 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.827528000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.827727079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.827764988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.828788996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.828907013 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.828946114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.829570055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.829670906 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.829709053 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.830682039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.830697060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.830743074 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.831588984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.832531929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.832578897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.832678080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.832757950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.832794905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.833688021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.833976984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.834022045 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.834781885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.834795952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.834830999 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.835779905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.835793972 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.835830927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.836790085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.836803913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.836853027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.837749958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.837866068 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.837905884 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.838747025 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.838937998 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.838980913 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.839848995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.839862108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.839895964 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.840903997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.840917110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.840946913 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.841799974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.841906071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.841939926 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.842803001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.843369007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.843414068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.843859911 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.843966007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.844005108 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.844800949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.845602989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.845648050 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.845855951 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.845907927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.845946074 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.846927881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.846952915 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.846986055 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.848001957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.848016024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.848057032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.849070072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.849083900 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.849114895 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.850893021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.850905895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.850944042 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.851118088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.851135969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.851171970 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.852229118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.852241993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.852273941 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.852946997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.853123903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.853163004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.854085922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.854099035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.854137897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.855005026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.855154037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.855189085 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.856116056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.856128931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.856172085 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.857009888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.857156992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.857198954 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.858112097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.858129978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.858167887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.859179974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.859236956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.859289885 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.860208988 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.860219955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.860256910 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.861167908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.861179113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.861208916 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.862303019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.862313986 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.862348080 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.863239050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.863251925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.863289118 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.864316940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.864330053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.864372015 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.865303993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.865315914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.865350962 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.869482994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.869502068 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.869514942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.869530916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.869544983 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.869566917 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.869786024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.869966984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.869999886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.871233940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.871277094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.871321917 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.871737003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.871898890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.871929884 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.872848034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.872869015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.872906923 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.873792887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.873941898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.873991013 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.874845982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.875020027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.875061989 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:32.875785112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:32.921952009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.013484955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.013499022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.013567924 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.014010906 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.014023066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.014075041 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.014585018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.014651060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.014688015 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.015588999 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.015602112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.015634060 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.016426086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.017494917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.017508030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.017535925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.018197060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.018244028 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.018569946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.018583059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.018610001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.019618034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.019630909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.019659996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.020539045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.021545887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.021559000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.021594048 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.022192001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.022233009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.022702932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.022716045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.022756100 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.023797035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.023809910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.023848057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.024842024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.024854898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.024884939 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.025794983 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.025809050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.025842905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.026822090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.026834011 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.026865005 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.027883053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.027895927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.027944088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.028740883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.028753042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.028781891 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.029860020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.029872894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.029902935 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.030767918 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.030781031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.030827999 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.031867981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.031879902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.031918049 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.032742023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.033747911 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.033797026 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.033811092 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.034770966 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.034782887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.034820080 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.035293102 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.035331964 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.035834074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.035851002 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.035886049 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.037182093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.037194967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.037226915 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.038295031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.038306952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.038337946 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.039170027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.039181948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.039211035 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.040064096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.040429115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.040478945 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.040891886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.041944981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.041958094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.041989088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.042078972 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.042115927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.043030024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.043041945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.043071985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.044002056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.044112921 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.044167042 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.045833111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.045845985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.045891047 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.046020985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.046088934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.046127081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.047033072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.047162056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.047207117 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.052109003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052124977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052167892 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.052181959 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052195072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052206993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052221060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052238941 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.052265882 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.052571058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052599907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052611113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052622080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.052634001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.052650928 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.053097010 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.053206921 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.053246021 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.054168940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.054265976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.054311037 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.055151939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.055279016 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.055321932 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.056420088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.056433916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.056468010 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.057241917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.057292938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.057337046 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.058202982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.058325052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.058365107 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.062433958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.062448978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.062458992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.062472105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.062482119 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.062508106 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.062737942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.062752008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.062781096 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.063703060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.063842058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.063885927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.064704895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.064995050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.065030098 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.065815926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.065984964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.066025019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.066962957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.067121029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.067158937 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.067401886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.109162092 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.205990076 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.206007957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.206213951 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.206306934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.206429958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.206473112 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.207288980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.207545042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.207586050 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.208349943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.208364010 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.208403111 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.209254026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.209438086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.209475994 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.210329056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.210434914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.210474014 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.211363077 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.211378098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.211416006 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.212368965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.212388039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.212424040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.213416100 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.213428974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.213469028 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.214415073 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.214428902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.214468956 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.215379000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.215835094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.215876102 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.216557026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.216569901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.216609001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.217443943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.217518091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.217559099 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.218405962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.218456030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.218512058 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.219435930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.219469070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.219505072 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.220487118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.220571995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.220612049 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.221462965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.221554041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.221594095 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.222542048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.222635984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.222676992 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.223548889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.223562956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.223608017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.224618912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.224637985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.224673986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.225647926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.225661039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.225694895 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.226562023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.226665020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.226700068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.227721930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.227735043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.227767944 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.228789091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.228805065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.228878021 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.229628086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.229984045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.230035067 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.230684996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.230770111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.230811119 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.231725931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.231739044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.231795073 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.232728958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.232850075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.232888937 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.233711004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.234220982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.234276056 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.234796047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.234817982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.234859943 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.235865116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.235877991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.235933065 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.236871958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.236885071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.236937046 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.237951040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.237962961 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.237998962 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.238791943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.239840031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.239850998 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.239877939 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.240675926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.240715027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.240909100 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.241179943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.241219044 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.241915941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.242878914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.242889881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.242918968 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.242954969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.242986917 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.243890047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.244184017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.244225025 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.244925022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.244936943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.244968891 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.246097088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.246948957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.246959925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.246985912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.247158051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.247198105 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.248016119 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.248028040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.248058081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.248961926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.249494076 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.249535084 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.250361919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.250876904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.250926018 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.251224041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.251236916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.251280069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.252209902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.252576113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.252610922 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.253083944 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.253097057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.253134966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.254205942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.254553080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.254590034 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.255131960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.256125927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.256141901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.256167889 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.256202936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.256239891 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.257123947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.258276939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.258289099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.258320093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.258322001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.258356094 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.259306908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.312259912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.397831917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.397895098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.397939920 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.398283958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.398443937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.398482084 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.399241924 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.399394989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.399430037 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.400289059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.401392937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.401406050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.401438951 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.401451111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.401484966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.402565956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.402620077 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.402657032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.403352976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.403788090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.403820992 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.404428005 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.404515028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.404547930 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.405381918 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.406213045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.406255007 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.406413078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.406425953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.406466007 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.407443047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.407597065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.407635927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.408977032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.408991098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.409029007 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.409636021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.409650087 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.409686089 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.410556078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.411010981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.411061049 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.411562920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.411575079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.411607981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.413034916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.413047075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.413083076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.413515091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.414216995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.414249897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.414546967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.414558887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.414592981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.415606976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.416131973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.416178942 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.416717052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.416898012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.416938066 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.417798042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.418133974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.418174982 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.418704987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.419569016 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.419610023 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.419696093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.419713974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.419744015 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.420675039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.421224117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.421262980 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.421685934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.422499895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.422559977 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.422655106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.422667980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.422710896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.423717022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.423729897 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.423774004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.424746990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.424876928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.424918890 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.425954103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.425966978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.426003933 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.427051067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.427063942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.427097082 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.427809000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.428157091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.428194046 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.428926945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.428940058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.428978920 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.429811954 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.430205107 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.430247068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.431149006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.431160927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.431191921 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.432054043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.432065964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.432095051 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.432868004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.432881117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.432912111 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.433900118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.433913946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.433949947 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.435005903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.435018063 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.435059071 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.435975075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.435986996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.436028004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.437036991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.437048912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.437087059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.437988043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.438000917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.438040018 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.438958883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.440093994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.440112114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.440124035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.440139055 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.440162897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.441087008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.442126036 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.442137957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.442174911 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.442176104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.442210913 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.443126917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.443337917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.443381071 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.444109917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.444123030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.444150925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.445266962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.445844889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.445878983 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.446228981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.446242094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.446274996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.447114944 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.447360039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.447402954 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.448432922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.449085951 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.449132919 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.449137926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.450084925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.450126886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.450189114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.450268030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.450304031 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.451208115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.499874115 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.590229034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.590629101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.590641022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.590652943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.590687990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.590715885 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.591515064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.592577934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.592592001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.592618942 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.593664885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.593679905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.593705893 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.594199896 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.594240904 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.595617056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.595630884 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.595670938 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.596549988 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.596564054 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.596601009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.597174883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.597188950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.597218990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.597870111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.598206043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.598239899 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.599695921 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.599709034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.599720001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.599744081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.600688934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.600702047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.600737095 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.601696014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.601708889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.601736069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.602128029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.602161884 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.603619099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.603631973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.603665113 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.603784084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.603795052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.603832960 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.604950905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.604964018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.605000973 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.605830908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.605844021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.605878115 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.607847929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.607861042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.607872009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.608030081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.608266115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.608304977 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.609940052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.609951973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.609987020 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.610033035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.610044003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.610084057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.611032009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.612276077 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.612286091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.612297058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.612320900 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.612344027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.613260984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.613342047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.613374949 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.614059925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.615034103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.615045071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.615084887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.616012096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.616022110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.616055012 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.616995096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.617007017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.617036104 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.617974043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.617985010 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.618010044 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.618977070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.618988037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.619024992 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.619276047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.619311094 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.620261908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.620273113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.620309114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.621037960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.622210026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.622220993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.622258902 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.623064995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.623075008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.623106956 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.624191999 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.624203920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.624236107 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.625365973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.625377893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.625411987 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.626040936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.626077890 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.626190901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.627142906 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.627154112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.627187967 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.628161907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.628173113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.628206015 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.629177094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.629188061 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.629219055 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.630209923 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.630249023 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.630270004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.630280972 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.630311966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.631934881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.631946087 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.631979942 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.632262945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.632273912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.632316113 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.633255005 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.634197950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.634238005 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.635296106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.635307074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.635334969 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.635340929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.636324883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.636336088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.636362076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.637377977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.637389898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.637399912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.637418985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.637432098 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.638432980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.638444901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.638472080 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.639805079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.639816046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.639858007 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.641453981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.641464949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.641475916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.641500950 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.642191887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.642222881 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.642570972 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.642581940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.642606974 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.643436909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.687263012 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.782526970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.782857895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.782926083 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.782973051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.782987118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.783129930 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.783961058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.784079075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.784126997 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.785262108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.785507917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.785547018 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.786075115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.786340952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.786381006 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.787026882 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.787081957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.787122011 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.787899971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.788085938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.788124084 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.788953066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.789123058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.789175987 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.789999008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.790050030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.790081978 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.791014910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.791299105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.791341066 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.792069912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.792298079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.792337894 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.793006897 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.793150902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.793190002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.794061899 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.794714928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.794758081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.795087099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.795211077 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.795245886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.796209097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.796396017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.796437025 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.797149897 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.798409939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.798425913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.798439026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.798469067 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.798491001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.799218893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.799319029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.799364090 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.800151110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.800426006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.800482988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.801214933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.801948071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.802001953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.802272081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.802807093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.802879095 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.803183079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.804128885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.804168940 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.804244041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.804256916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.804307938 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.805347919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.806130886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.806190968 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.806230068 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.806391954 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.806444883 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.807394028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.808139086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.808197975 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.808377981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.809351921 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.809365034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.809402943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.809406042 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.809438944 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.810578108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.810636044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.810679913 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.811539888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.811649084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.811703920 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.812650919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.812860012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.812906027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.813643932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.814209938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.814256907 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.814564943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.814846992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.814891100 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.815438032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.816128016 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.816175938 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.816468000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.816482067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.816524982 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.817500114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.818481922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.818502903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.818535089 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.818542004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.818614006 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.819752932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.819989920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.820041895 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.820827007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.821204901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.821260929 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.821715117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.821893930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.821942091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.822717905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.823636055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.823652029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.823693991 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.823704958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.823751926 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.824613094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.825557947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.825613976 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.825706005 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.825719118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.825763941 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.826661110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.827708006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.827722073 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.827759981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.827830076 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.827905893 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.828664064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.828766108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.828814030 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.829725981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.830029964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.830081940 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.830768108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.830878019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.830928087 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.831773996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.832067013 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.832115889 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.832931042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.833082914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.833133936 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.833758116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.833987951 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.834039927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.834883928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.835529089 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.835592985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.835865021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.890460968 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.974800110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.974818945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.974999905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.975202084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.975378990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.975421906 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.976212025 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.976397991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.976443052 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.977247953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.977452040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.977504969 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.978240967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.978780985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.978837013 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.979242086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.979460955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.979510069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.980353117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.980433941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.980484009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.981277943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.981314898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.981368065 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.982320070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.982728958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.982801914 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.983345032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.983683109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.983731985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.984360933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.984507084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.984559059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.985533953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.985548973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.985589981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.986555099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.987339973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.987395048 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.987416029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.987731934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.987772942 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.988523006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.988599062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.988641977 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.989491940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.989583015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.989629030 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.990462065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.990853071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.990894079 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.991472960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.991554022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.991595984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.992511034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.993038893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.993079901 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.993524075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.993535995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.993566990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.994575977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.994751930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.994793892 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.995538950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.996107101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.996144056 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.996596098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.996920109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.996963978 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.997575998 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.997723103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.997765064 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.998584032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.998670101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.998711109 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:33.999641895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.999778986 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:33.999821901 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.000646114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.001065969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.001121044 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.001677990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.002402067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.002454996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.002626896 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.002646923 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.002684116 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.003667116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.004117966 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.004167080 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.004709005 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.004983902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.005032063 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.005731106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.006119013 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.006161928 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.006738901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.006901979 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.006944895 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.007778883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.008083105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.008131027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.008774042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.009684086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.009732008 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.009823084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.009860039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.009901047 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.010873079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.011569977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.011616945 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.011811972 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.011957884 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.012003899 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.012893915 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.012906075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.012954950 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.013953924 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.013987064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.014025927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.014916897 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.015958071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.015969992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.016000986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.016011953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.016057014 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.017075062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.017983913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.017998934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.018039942 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.018100023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.018143892 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.018965006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.019171953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.019217014 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.020083904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.020204067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.020260096 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.021153927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.021539927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.021584034 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.022027969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.022308111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.022345066 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.023052931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.023169041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.023211002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.024107933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.024415970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.024460077 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.025149107 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.026125908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.026139021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.026170969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.026175022 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.026206017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.027179003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.027384043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.027427912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.028086901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.078015089 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.167027950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.167432070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.167447090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.167490959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.167603016 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.167638063 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.167936087 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.168745041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.168790102 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.168912888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.169751883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.169802904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.169806004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.170681000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.170734882 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.170890093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.171819925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.171835899 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.171880960 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.173108101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.173151970 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.173192978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.174180031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.174227953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.174262047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.174972057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.175017118 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.175254107 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.176001072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.176023006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.176047087 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.176819086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.176865101 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.177149057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.177874088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.177923918 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.178196907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.178853989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.178901911 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.179080009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.179876089 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.179923058 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.180080891 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.180859089 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.180907011 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.181222916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.181906939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.181961060 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.182138920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.182924032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.182976961 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.183784962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.184024096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.184072971 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.184233904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.184937954 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.184990883 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.185139894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.185992002 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.186013937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.186039925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.187026978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.187068939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.187077999 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.187963009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.188014984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.188288927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.189340115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.189393997 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.189977884 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.190193892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.190207958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.190270901 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.191045046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.191096067 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.191147089 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.192091942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.192153931 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.192842007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.193098068 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.193150043 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.194046021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.194116116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.194128036 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.194168091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.195096970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.195157051 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.195349932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.196249008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.196299076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.196557999 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.197186947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.197237015 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.197267056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.198271990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.198340893 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.199229002 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.199243069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.199297905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.199361086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.200212002 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.200268030 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.200278997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.201220036 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.201273918 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.201944113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.202351093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.202397108 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.202773094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.203274965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.203339100 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.203901052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.204432964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.204495907 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.204837084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.205331087 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.205401897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.205729008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.206423044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.206449032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.206480980 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.207362890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.207415104 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.207439899 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.208419085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.208477020 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.208623886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.209391117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.209404945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.209434986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.210433960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.210491896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.211422920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.211467028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.211479902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.211522102 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.212419033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.212471008 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.212692022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.213521004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.213574886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.213658094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.214471102 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.214536905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.215502977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.215517044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.215545893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.215570927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.216499090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.216546059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.216620922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.217530012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.217566967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.217573881 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.218600988 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.218668938 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.219038963 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.219563007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.219608068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.219645977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.265398979 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.359535933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.359808922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.359862089 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.360001087 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.360182047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.360320091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.361342907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.361692905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.361732960 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.362104893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.362204075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.362257004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.363008022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.363028049 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.363079071 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.364008904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.364334106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.364387035 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.365045071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.365250111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.365289927 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.366143942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.366265059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.366313934 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.367176056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.367372036 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.367420912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.371303082 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.371325970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.371386051 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.371489048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.371501923 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.371537924 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.371543884 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.371551991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.371591091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.372529984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.372541904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.372587919 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.373481989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.373852968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.373900890 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.374690056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.374982119 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.375025988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.375475883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.375650883 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.375688076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.376507044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.376527071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.376564980 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.376738071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.376761913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.376800060 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.377530098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.377543926 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.377593994 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.380865097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.380880117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.380939960 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.381835938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.381849051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.381894112 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.382010937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.382179976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.382213116 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.382870913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.383969069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.383981943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.384016037 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.384169102 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.384210110 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.384960890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.385629892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.385680914 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.385926962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.386276960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.386318922 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.387059927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.387406111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.387449980 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.387866020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.388228893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.388267994 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.388854027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.388865948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.388906002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.389832020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.390345097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.390403986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.390809059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.390989065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.391026974 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.391786098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.391932011 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.391973972 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.392915964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.393395901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.393441916 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.393892050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.393903971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.393944979 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.394751072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.395653009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.395694017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.395778894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.395956039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.395993948 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.397140026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.397279978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.397325993 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.397943020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.398113012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.398154974 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.399072886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.399085999 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.399132013 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.399986029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.400091887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.400132895 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.400140047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.401218891 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.401267052 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.401974916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.402086020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.402126074 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.402890921 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.402904987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.402950048 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.403733015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.404459000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.404473066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.404484034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.404504061 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.404525042 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.405462027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.405474901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.405514002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.405946970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.406480074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.406533003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.406903982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.407257080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.407289982 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.408109903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.408430099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.408463955 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.409023046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.409817934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.409854889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.409866095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.409868956 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.409895897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.410864115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.411011934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.411056042 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.411941051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.412081957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.412123919 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.412930965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.457865953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.551884890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.552119970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.552162886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.552391052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.552547932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.552587032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.553447008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.553523064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.553566933 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.554609060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.554899931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.554944992 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.556169033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.556184053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.556230068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.557673931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.557687998 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.557702065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.557719946 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.558208942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.558244944 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.559222937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.559237003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.559271097 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.559863091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.559875011 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.559906960 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.561233997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.562086105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.562098980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.562119961 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.563215971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.563229084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.563256025 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.564241886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.564282894 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.564630032 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.564640045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.564682007 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.566327095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.566343069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.566381931 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.566504002 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.566514969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.566549063 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.567799091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.567810059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.567848921 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.568568945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.568579912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.568620920 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.570204973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.570271969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.570283890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.570311069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.570626974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.570669889 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.571898937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.571911097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.571923018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.571945906 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.573025942 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.573038101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.573061943 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.573884010 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.573920965 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.575467110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.575479031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.575490952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.575520039 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.576231956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.576270103 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.576827049 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.576838970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.576872110 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.577435017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.578419924 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.578433037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.578444004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.578466892 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.578486919 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.579551935 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.579564095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.579602957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.580297947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.580311060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.580359936 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.581038952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.581049919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.581083059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.582205057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.582880020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.582890034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.582901955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.582927942 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.582952023 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.584132910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.584145069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.584183931 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.585216999 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.586374044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.586385012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.586416006 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.587276936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.587287903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.587327003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.588072062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.588083029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.588114977 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.588227987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.588267088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.589077950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.589088917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.589133024 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.590245962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.590256929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.590306997 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.591566086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.591577053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.591619015 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.592170000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.592183113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.592226982 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.593235970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.593247890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.593296051 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.594122887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.594136000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.594177961 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.595194101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.595205069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.595237970 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.596107960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.596179008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.596237898 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.597167015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.597178936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.597218990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.598306894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.598320007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.598359108 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.599483013 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.599494934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.599529028 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.600229025 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.601291895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.601303101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.601336002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.602241039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.602252960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.602283955 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.602835894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.602875948 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.603230000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.604248047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.604259014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.604290009 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.606204033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.606214046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.606250048 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.744545937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.745105982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.745119095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.745187044 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.745242119 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.745282888 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.746090889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.746350050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.746395111 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.747371912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.747384071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.747423887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.748147964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.748276949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.748321056 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.749133110 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.749216080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.749259949 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.750173092 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.750394106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.750436068 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.751193047 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.751720905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.751763105 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.752247095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.752299070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.752340078 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.753246069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.753312111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.753348112 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.754245043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.754420042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.754461050 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.755273104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.755398989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.755441904 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.756372929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.757478952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.757489920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.757502079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.757524967 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.757554054 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.758338928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.758491039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.758532047 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.759327888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.759541035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.759578943 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.760554075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.760644913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.760688066 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.761409044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.761420965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.761456966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.762535095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.762797117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.762840986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.763681889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.764296055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.764339924 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.764486074 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.764566898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.764602900 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.765470028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.765566111 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.765604019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.766479015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.767496109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.767544031 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.767751932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.767764091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.767803907 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.768518925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.768672943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.768712044 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.769535065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.769640923 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.769682884 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.770617008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.771579027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.771591902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.771617889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.771619081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.771651030 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.772559881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.773804903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.773818016 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.773829937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.773848057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.773873091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.774792910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.775579929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.775624990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.775782108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.776175976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.776216984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.776634932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.777165890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.777208090 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.777669907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.777682066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.777717113 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.778681993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.778723955 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.778763056 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.779690027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.779794931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.779834986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.780704975 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.780818939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.780859947 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.781721115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.781949997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.781991959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.782718897 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.784013987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.784027100 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.784039021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.784054995 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.784080029 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.784996033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.785458088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.785495043 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.786140919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.786241055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.786278963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.787049055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.787308931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.787350893 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.788053989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.788065910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.788104057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.789094925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.789726019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.789767027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.790199995 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.790417910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.790455103 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.791173935 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.791186094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.791224003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.792172909 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.792185068 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.792221069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.793132067 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.793595076 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.793636084 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.794037104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.794219017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.794258118 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.794997931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.795141935 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.795183897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.796060085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.796128035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.796164036 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.797074080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.797121048 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.797158957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.797991037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.843566895 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.936860085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.936949015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.937100887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.937391043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.937403917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.937437057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.938347101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.938503981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.938549042 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.939352989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.939791918 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.939831018 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.940399885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.940440893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.940481901 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.941466093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.941540003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.941577911 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.942467928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.942780018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.942819118 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.943567038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.943768024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.943798065 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.944437981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.945013046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.945050955 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.945487022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.945512056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.945540905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.946533918 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.947602034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.947613001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.947626114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.947644949 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.947669029 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.948574066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.948585987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.948616982 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.949568987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.949776888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.949819088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.950632095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.950865030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.950902939 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.951699018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.951836109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.951873064 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.952657938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.952867031 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.952903032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.953732014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.954241037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.954279900 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.954725027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.955528975 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.955569983 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.955877066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.956100941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.956137896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.956990004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.957220078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.957252026 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.958298922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.958312035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.958353996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.959393024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.959558964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.959590912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.960186958 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.960443974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.960479975 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.961338043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.961349010 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.961381912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.962276936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.962344885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.962383032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.963327885 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.963958979 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.963996887 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.964160919 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.964302063 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.964332104 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.965162039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.966017962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.966058969 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.966094017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.966111898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.966140985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.966881990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.967072964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.967113018 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.967942953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.968059063 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.968097925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.968897104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.969671011 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.969712019 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.969978094 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.970168114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.970210075 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.970954895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.971519947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.971560955 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.971999884 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.972100019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.972131014 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.972953081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.973001003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.973037004 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.973987103 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.974245071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.974282026 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.975023985 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.975123882 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.975159883 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.976329088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.977288008 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.977299929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.977313042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.977330923 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.977355957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.978276014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.978295088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.978331089 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.979177952 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.979494095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.979540110 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.980123043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.980334044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.980376005 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.981173038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.981518030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.981556892 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.982218027 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.982320070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.982362986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.983258009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.984198093 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.984240055 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.984333992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.984353065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.984386921 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.985409021 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.985518932 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.985557079 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.986417055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.986435890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.986469984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.987242937 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.987350941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.987396002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.988300085 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.988375902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.988415003 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.989470959 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.989938974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:34.989979029 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:34.990468025 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.031136990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.129100084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.129245996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.129295111 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.129631996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.129834890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.129875898 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.130753040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.130980015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.131015062 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.131598949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.131855011 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.131895065 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.132683992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.132695913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.132729053 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.133683920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.134438038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.134480953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.134696960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.134708881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.134736061 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.135683060 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.135977030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.136008024 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.136815071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.136894941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.136933088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.139863014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.139899015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.139940023 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.139995098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.140007973 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.140047073 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.140439987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.140520096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.140562057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.148762941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.148905039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.148917913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.148950100 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149033070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149044991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149056911 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149070978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149071932 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149094105 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149251938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149285078 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149326086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149338007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149360895 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149369001 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149373055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149385929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149403095 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149679899 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149691105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149709940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149723053 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149749041 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.149766922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149780989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.149808884 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.150238991 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.150338888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.150371075 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.151367903 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.152045965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.152057886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.152081966 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.152118921 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.152168989 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.153048992 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.154088974 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.154099941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.154129028 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.154167891 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.154201984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.155277014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.155563116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.155597925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.156156063 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.156677961 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.156711102 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.157252073 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.157263994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.157298088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.158137083 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.158310890 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.158344984 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.159202099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.159212112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.159254074 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.160207033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.160337925 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.160377026 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.161206961 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.161359072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.161398888 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.162223101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.162235022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.162267923 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.163213968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.163893938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.163925886 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.164264917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.164278030 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.164308071 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.165329933 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.165390015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.165421963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.166327953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.167319059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.167331934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.167351007 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.167450905 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.167484045 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.168329000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.168342113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.168385029 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.169361115 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.170572042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.170587063 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.170612097 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.170619965 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.170640945 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.171365976 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.171427965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.171471119 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.172384977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.172518969 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.172554016 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.173656940 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.173710108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.173764944 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.174437046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.175081968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.175123930 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.175415993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.175950050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.175987959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.176436901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.177292109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.177339077 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.177499056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.177510023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.177547932 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.178476095 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.179440975 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.179481983 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.179573059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.179589987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.179625034 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.180517912 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.181077003 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.181114912 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.181562901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.181576014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.181624889 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.183039904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.234144926 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.325648069 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.325664997 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.325902939 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.326009989 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.326531887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.326570034 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.326899052 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.327208042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.327249050 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.327898026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.328084946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.328121901 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.328902006 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.329505920 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.329545021 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.329982042 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.330137014 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.330171108 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.331154108 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.331166029 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.331197977 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.331959963 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.332087040 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.332117081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.333112001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.333565950 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.333600044 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.334052086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.334064007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.334091902 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.335011959 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.335505009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.335544109 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.336051941 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.336432934 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.336467981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.337083101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.337095022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.337131023 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.338092089 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.338197947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.338234901 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.339114904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.339127064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.339162111 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.340168953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.340398073 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.340436935 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.341171026 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.341182947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.341226101 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.342140913 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.342228889 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.342258930 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.343283892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.343549967 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.343588114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.344218016 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.344352007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.344392061 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.345251083 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.345581055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.345618963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.346287012 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.346962929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.346998930 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.347239971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.348076105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.348110914 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.348277092 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.348289013 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.348325968 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.349265099 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.349806070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.349848986 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.350389957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.350462914 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.350500107 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.351306915 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.351933956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.351975918 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.352319956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.352490902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.352521896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.353389978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.353400946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.353440046 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.354398966 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.354998112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.355029106 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.355456114 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.355581045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.355621099 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.356403112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.356836081 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.356875896 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.357448101 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.358340979 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.358385086 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.358498096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.358510971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.358550072 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.359463930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.359808922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.359850883 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.360486984 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.361517906 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.361531019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.361557961 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.361617088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.361654997 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.362600088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.362988949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.363025904 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.363702059 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.363790989 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.363828897 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.364583015 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.364732981 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.364772081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.365852118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.365864038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.365906000 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.366640091 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.366826057 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.366862059 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.367728949 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.367742062 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.367774963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.369287968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.369704962 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.369715929 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.369728088 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.369746923 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.369764090 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.370707035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.371088982 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.371128082 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.371675968 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.372035980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.372076988 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.372725964 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.372905970 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.372937918 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.373807907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.374059916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.374094963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.374736071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.374880075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.374918938 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.376141071 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.376157045 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.376204014 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.376786947 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.377103090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.377146959 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.377825022 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.377922058 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.377959967 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.378787994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.422210932 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.517579079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.517720938 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.517766953 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.518086910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.518311977 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.518356085 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.518484116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.519340038 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.519354105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.519382000 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.520311117 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.520359039 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.520766020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.521337986 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.521378040 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.521722078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.522363901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.522403002 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.522599936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.523382902 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.523422956 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.523927927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.524396896 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.524436951 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.525474072 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.525486946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.525525093 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.526043892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.526460886 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.526477098 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.526495934 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.527419090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.527456045 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.527470112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.528475046 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.528517962 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.528765917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.529484034 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.529517889 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.529675007 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.530494928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.530534983 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.530752897 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.531558990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.531584978 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.531593084 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.532541037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.532574892 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.532743931 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.533559084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.533591032 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.533723116 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.534833908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.534869909 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.534893036 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.535604000 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.535646915 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.536147118 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.536719084 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.536758900 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.537646055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.537658930 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.537688971 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.537694931 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.538631916 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.538671017 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.539098024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.539673090 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.539709091 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.539772987 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.540718079 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.540759087 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.541388035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.541721106 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.541732073 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.541758060 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.542712927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.542753935 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.542922020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.543766975 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.543806076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.544095039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.544745922 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.544784069 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.545279980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.545804024 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.545836926 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.545869112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.546780109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.546812057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.547399998 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.547880888 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.547894001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.547919989 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.548839092 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.548878908 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.549320936 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.549876928 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.549915075 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.550059080 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.550919056 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.550960064 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.551785946 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.551925898 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.551954985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.552078009 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.552978039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.553015947 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.554143906 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.554156065 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.554183960 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.554188013 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.554960966 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.555006981 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.555737972 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.556160927 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.556200027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.556355953 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.557218075 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.557257891 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.557703018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.558007956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.558043957 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.558629990 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.559050083 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.559061050 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.559078932 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.560034037 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.560065985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.560892105 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.561096907 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.561108112 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.561140060 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.562072039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.562114954 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.562530994 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.563102961 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.563146114 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.564136028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.564146996 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.564177990 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.564182043 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.565100908 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.565140963 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.565736055 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.566154957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.566194057 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.566195965 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.567253113 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.567293882 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.567831039 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.568219900 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.568258047 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.569220066 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.569231033 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.569262028 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.569267035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.570229053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.570267916 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.570940018 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.624757051 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.709860086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.710330963 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.710375071 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.710443020 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.710500956 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.710530996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.711163044 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.711227894 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.711262941 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.712223053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.712709904 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.712745905 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.713196993 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.714225054 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.714262962 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.714293957 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.714307070 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.714340925 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.715277910 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.715358019 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.715393066 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.716274023 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.716814041 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.716850996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.717398882 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.717829943 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.717871904 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.718317986 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.718767881 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.718810081 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.719378948 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.719778061 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.719816923 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.720334053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.720769882 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.720807076 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.721369028 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.722357035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.722392082 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.722402096 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.722414017 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.722445965 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.723376036 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.724123001 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.724153996 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.724376917 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.724617004 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.724647045 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.725474119 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.725485086 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.725522041 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.726461887 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.727592945 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.727605104 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.727624893 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.727632999 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.727663994 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.728571892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.729554892 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.729567051 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.729587078 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.729588985 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.729618073 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.730523109 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.731036901 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.731069088 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.731605053 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.732182980 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.732218027 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.732503891 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.732543945 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.742099047 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.751377106 CET497307390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:35.861283064 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:35.870707035 CET739049730193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:46.278003931 CET497377390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:46.397377014 CET739049737193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:46.397459030 CET497377390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:46.397629023 CET497377390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:46.516870975 CET739049737193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:46.517136097 CET739049737193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:56.266412973 CET497417390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:56.385653019 CET739049741193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:56.386446953 CET497417390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:56.386558056 CET497417390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:56:56.505738974 CET739049741193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:56:56.505916119 CET739049741193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:06.281614065 CET497427390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:06.401031971 CET739049742193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:06.401133060 CET497427390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:06.401230097 CET497427390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:06.520423889 CET739049742193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:06.520585060 CET739049742193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:16.281713009 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:16.401024103 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:16.401155949 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:16.401232004 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:16.520570040 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:17.646162987 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:17.646198988 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:17.646384001 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:17.654349089 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:17.773798943 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.046154976 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.046387911 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:18.165638924 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.434278965 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.436899900 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:18.556163073 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.556384087 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:18.675611019 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.944106102 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:18.946760893 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.066992998 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.067188978 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.186505079 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.455012083 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.455053091 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.455096006 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.560704947 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.560821056 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.560906887 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.561007977 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680006027 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680128098 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680139065 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680232048 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680272102 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680335999 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680401087 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680411100 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680433989 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680458069 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680478096 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680813074 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680823088 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680831909 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680840969 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680850029 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680859089 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.680874109 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680874109 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680902958 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.680902958 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.799635887 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.799659967 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.799772978 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.799773932 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.799830914 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.799844027 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.799899101 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.799962997 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800010920 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.800038099 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800080061 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.800116062 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800165892 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.800282001 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800292015 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800363064 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800364971 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.800412893 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.800441027 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800493956 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.800535917 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.800587893 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.919163942 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919217110 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919285059 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:19.919296980 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919332981 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919428110 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919459105 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919591904 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919666052 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919718981 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919783115 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919836998 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919847012 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919856071 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919889927 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.919986010 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920001984 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920062065 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920070887 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920116901 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920176983 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920298100 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920314074 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920474052 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920655012 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920665026 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920708895 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920747042 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920768023 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920913935 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:19.920926094 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:20.038661957 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:20.038695097 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:20.038786888 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:20.458767891 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:20.500092983 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:21.308222055 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:21.308310032 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:21.308371067 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:21.308434010 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:21.427531004 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427593946 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:21.427615881 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427628994 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427654028 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427853107 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427861929 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427927017 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.427936077 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.428008080 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.428025007 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.428034067 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.428143978 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.428153038 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.547108889 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.818455935 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:21.859477997 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.427567005 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.427663088 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.427759886 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.427855968 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.427912951 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.427968025 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:22.547636986 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.547765970 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.547779083 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.547904968 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548046112 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548078060 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548155069 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548168898 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548223972 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548252106 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548260927 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548319101 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548327923 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548356056 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548365116 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548398972 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548408031 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548417091 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.548429012 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.837728024 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:22.890835047 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:23.828331947 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:23.947788954 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:23.947885036 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:24.067975044 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:24.361188889 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:24.361265898 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:24.361321926 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:24.361351967 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:24.361437082 CET497437390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:24.481770039 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:24.481812954 CET739049743193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:29.375484943 CET497657390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:29.494712114 CET739049765193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:29.494865894 CET497657390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:29.494940042 CET497657390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:29.614865065 CET739049765193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:29.615055084 CET739049765193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:39.392484903 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:39.511846066 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:39.511953115 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:39.512037039 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:39.631341934 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:40.828773975 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:40.828819990 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:40.828866959 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:40.858448029 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:40.977742910 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:41.291785955 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:41.292143106 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:41.411709070 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:41.713466883 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:41.716109037 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:41.835479021 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:41.835613966 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:41.955949068 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.300779104 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.305226088 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.424561977 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.424670935 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.544964075 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.874305010 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.877573013 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.877587080 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.877599955 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.877684116 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.877731085 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.877779961 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.885874987 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.885936022 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.885936975 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.893279076 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.893399000 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.893484116 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.901804924 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.901823997 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.901882887 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.906644106 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.906691074 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.906730890 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.915054083 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.915110111 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:42.915169954 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:42.969064951 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:43.082885981 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.082906008 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.082979918 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:43.086766958 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.088320971 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.088376045 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:43.088414907 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.096642971 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.096657991 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.096709013 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:43.104783058 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:43.104831934 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.141117096 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.260549068 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.260848999 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.380345106 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.722237110 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.722296000 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.722384930 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.722415924 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.730551958 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.730627060 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.731990099 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.732161999 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.732220888 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.740387917 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.740415096 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.740478992 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.745647907 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.745666981 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.745713949 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.753966093 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.753983021 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.754026890 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.761986017 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.762131929 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.762178898 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.770194054 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.770328999 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.770370960 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.778247118 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.778367043 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.778414011 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.786616087 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.786631107 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.786679983 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.794831038 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.794843912 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.794888973 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.803221941 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.803385019 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.803426981 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.811258078 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.811273098 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.811322927 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.819257975 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.819308043 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.819354057 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.827384949 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.827497005 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.827583075 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.835829020 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.835845947 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.835895061 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.844218016 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.844233036 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.844305038 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.914475918 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.914491892 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.914568901 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.918440104 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.918452978 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:45.918493032 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:45.981936932 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.101505041 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.101562977 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.221080065 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.547394991 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.547660112 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.547724009 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.549663067 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.553277969 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.553294897 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.553364038 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.555499077 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.555545092 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.556031942 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.558526993 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.558578968 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.558584929 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.563364029 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.563421011 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.563971996 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.563986063 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.564033985 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.568511963 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.569273949 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.569327116 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.569379091 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.573918104 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.573937893 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.573982954 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.578414917 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.578562975 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.580012083 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.580148935 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.580198050 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.584645033 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.584733009 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.584785938 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.589212894 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.590832949 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.590890884 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.590946913 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.595350027 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.595477104 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.595545053 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.600003958 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.600188971 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.600255966 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.604593992 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.604681969 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.604729891 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.609123945 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.609224081 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.609289885 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.613603115 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.613706112 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.613754988 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.618252993 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.618582010 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.618638039 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.622788906 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.622889996 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.622936010 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.627305984 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.627394915 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.627444983 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.631871939 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.631968021 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.632144928 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.636425018 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.636513948 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.636567116 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.641057014 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.641109943 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.641164064 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.645597935 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.645668983 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.645726919 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.650353909 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.650456905 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.650527954 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.654726028 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.654786110 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.654855013 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.662293911 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.662312031 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.662385941 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.667830944 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.667968988 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.668024063 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.740048885 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.740186930 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.740267992 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.742861032 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.742877960 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.742933035 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.747067928 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.787576914 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.787756920 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.787776947 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.789577007 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.789634943 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.789737940 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.794995070 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.795010090 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.795048952 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.799240112 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.799252987 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.799293995 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.803354025 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.803366899 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.803397894 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.804794073 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.804838896 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.804980040 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.806390047 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.806401014 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.806444883 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.808003902 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.808015108 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.808058023 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.809495926 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.809514046 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.809539080 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.810926914 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.810970068 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.811110020 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.812475920 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.812525988 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.812628984 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.814127922 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.814140081 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.814172983 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.815695047 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.815706015 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.815737963 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.817112923 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.817157030 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.817270994 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.818742990 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.818753958 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.818792105 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.820173025 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.820249081 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.820477009 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.821769953 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.821825981 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.821902990 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.823380947 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.823398113 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.823435068 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.824757099 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.824806929 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.824929953 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.826349974 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.826361895 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.826401949 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.827375889 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.827428102 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.827652931 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.828857899 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.828916073 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.829006910 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.830265045 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.830349922 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.830365896 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.831667900 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.831717014 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.831769943 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.833296061 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.833308935 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.833352089 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.834737062 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.834783077 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.834816933 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.839370966 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.839386940 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.839396954 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.839409113 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.839421034 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.839451075 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.840127945 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.840183973 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.840301037 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.841727018 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.841772079 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.842045069 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.844846010 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.844899893 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.845026016 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.845037937 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.845074892 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.845185041 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.846338034 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.846394062 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.846498966 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.847867966 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.847881079 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.847930908 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.849328995 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.849375963 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.849467039 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.850950956 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.850961924 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.850997925 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.852541924 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.852598906 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.852694988 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.860517979 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.860620975 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.860682964 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.861304998 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.861351967 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.861615896 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.863168955 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.863325119 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.863342047 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.864423990 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.864468098 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.864598036 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.906985044 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.907190084 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.907253027 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.907336950 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.908202887 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.908217907 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.908252954 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.909466982 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.909565926 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.909607887 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.911123991 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.911170959 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.911290884 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.914532900 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.914655924 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.914740086 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.915322065 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.915445089 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.915488958 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.916995049 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.917113066 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.917218924 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.918759108 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.918872118 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.918929100 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.922882080 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.922945976 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.922988892 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.923619986 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.923727989 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.923846960 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.931704998 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.931773901 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.931998968 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.932410002 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.932588100 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.932626963 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.933984995 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.934077024 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.934262991 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.935439110 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.937410116 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.937457085 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.937475920 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.938113928 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.938167095 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.938230991 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.939657927 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.939708948 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.939784050 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.941198111 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.941245079 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.941684961 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.941795111 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.941843987 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.942590952 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.942683935 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.942820072 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.944099903 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.944199085 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.944246054 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:46.945765972 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.945775986 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:46.945826054 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.168076992 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.287467003 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:47.287564993 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.407429934 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:47.769740105 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:47.770303965 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:47.770379066 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.770411968 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:47.770461082 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.770478964 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.770526886 CET497667390192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:47.889982939 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:47.889998913 CET739049766193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:48.141407013 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:48.141530037 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:48.141633987 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:48.141733885 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:48.141756058 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:49.610512018 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:49.610646009 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:49.614892006 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:49.614905119 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:49.615178108 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:49.616597891 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:49.663333893 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:54.321156025 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:54.321233988 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:54.321329117 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:54.321379900 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:54.321402073 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:54.321423054 CET49767443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:54.321429014 CET44349767193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:55.313322067 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:55.313381910 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:55.313476086 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:55.313524961 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:55.313532114 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:56.689126968 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:56.689261913 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:56.693473101 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:56.693485975 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:56.693756104 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:57:56.694441080 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:57:56.735340118 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:01.489490032 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:01.489597082 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:01.489700079 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:01.492840052 CET49769443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:01.492861032 CET44349769193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:02.511610985 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:02.511655092 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:02.511708975 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:02.511763096 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:02.511768103 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:03.882015944 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:03.882093906 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:03.889125109 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:03.889137983 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:03.889437914 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:03.890161037 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:03.935329914 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:08.684653997 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:08.684736967 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:08.684961081 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:08.685116053 CET49770443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:08.685133934 CET44349770193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:09.695456982 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:09.695502996 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:09.695600986 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:09.695708036 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:09.695717096 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:11.163784981 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:11.163877010 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:11.168071985 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:11.168085098 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:11.168390989 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:11.169042110 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:11.215333939 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:15.963964939 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:15.964050055 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:15.964117050 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:15.964200020 CET49771443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:15.964210987 CET44349771193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:16.954371929 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:16.954415083 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:16.954477072 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:16.954595089 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:16.954605103 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:18.324892998 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:18.325006008 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:18.378254890 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:18.378283978 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:18.378632069 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:18.389861107 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:18.431339979 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:23.128103018 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:23.128180027 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:23.128230095 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:23.128277063 CET49772443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:23.128293991 CET44349772193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:24.142082930 CET49773443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:24.142148972 CET44349773193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:24.142215014 CET49773443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:24.142296076 CET49773443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:24.142303944 CET44349773193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:25.525794983 CET44349773193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:25.525974035 CET49773443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:25.530360937 CET49773443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:25.530374050 CET44349773193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:25.530639887 CET44349773193.124.205.63192.168.2.4
                                                      Dec 9, 2024 10:58:25.531337976 CET49773443192.168.2.4193.124.205.63
                                                      Dec 9, 2024 10:58:25.579335928 CET44349773193.124.205.63192.168.2.4

                                                      Click to jump to process

                                                      Click to jump to process

                                                      Click to dive into process behavior distribution

                                                      Click to jump to process

                                                      Target ID:0
                                                      Start time:04:56:21
                                                      Start date:09/12/2024
                                                      Path:C:\Users\user\Desktop\cXjy5Y6dXX.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:"C:\Users\user\Desktop\cXjy5Y6dXX.exe"
                                                      Imagebase:0xba0000
                                                      File size:433'152 bytes
                                                      MD5 hash:9725864712CC93935C58E8908DFA66D2
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Yara matches:
                                                      • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000000.00000003.1701632877.00000000047D0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000000.00000003.1699421762.0000000000CF0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000000.00000003.1702281326.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000000.00000003.1701458726.00000000045B0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                                      Reputation:low
                                                      Has exited:true

                                                      Target ID:1
                                                      Start time:04:56:25
                                                      Start date:09/12/2024
                                                      Path:C:\Windows\SysWOW64\OpenWith.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:"C:\Windows\system32\openwith.exe"
                                                      Imagebase:0xcc0000
                                                      File size:107'368 bytes
                                                      MD5 hash:0ED31792A7FFF811883F80047CBCFC91
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Yara matches:
                                                      • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000001.00000003.1704117814.0000000005470000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000001.00000003.1704399379.0000000005690000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000001.00000003.1733027808.00000000053DF000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000001.00000003.1702483647.0000000004BC0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000001.00000002.1802524391.0000000004BF0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                      Reputation:moderate
                                                      Has exited:true

                                                      Target ID:2
                                                      Start time:04:56:35
                                                      Start date:09/12/2024
                                                      Path:C:\Windows\System32\OpenWith.exe
                                                      Wow64 process (32bit):false
                                                      Commandline:"C:\Windows\system32\openwith.exe"
                                                      Imagebase:0x7ff6d5b20000
                                                      File size:123'984 bytes
                                                      MD5 hash:E4A834784FA08C17D47A1E72429C5109
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Yara matches:
                                                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000003.1892936653.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000003.1892527686.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000003.1891865924.000001D97E718000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000002.00000003.1857372783.000001D97EE61000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000003.1893822395.000001D97E6B7000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000002.00000003.2575850909.000001D97F061000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000002.00000003.1857755210.000001D97EF14000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                      Reputation:high
                                                      Has exited:true

                                                      Target ID:6
                                                      Start time:04:57:42
                                                      Start date:09/12/2024
                                                      Path:C:\Program Files\Windows Media Player\wmplayer.exe
                                                      Wow64 process (32bit):false
                                                      Commandline:"C:\Program Files\Windows Media Player\wmplayer.exe"
                                                      Imagebase:0x7ff61f310000
                                                      File size:171'008 bytes
                                                      MD5 hash:89DCD2D4C0EC638AADC00D3530E07E1D
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:false

                                                      Target ID:8
                                                      Start time:04:57:46
                                                      Start date:09/12/2024
                                                      Path:C:\Windows\System32\dllhost.exe
                                                      Wow64 process (32bit):true
                                                      Commandline:"C:\Windows\system32\dllhost.exe"
                                                      Imagebase:0x8c0000
                                                      File size:21'312 bytes
                                                      MD5 hash:08EB78E5BE019DF044C26B14703BD1FA
                                                      Has elevated privileges:true
                                                      Has administrator privileges:true
                                                      Programmed in:C, C++ or other language
                                                      Reputation:moderate
                                                      Has exited:false

                                                      Reset < >

                                                        Execution Graph

                                                        Execution Coverage:2%
                                                        Dynamic/Decrypted Code Coverage:0%
                                                        Signature Coverage:1.7%
                                                        Total number of Nodes:1670
                                                        Total number of Limit Nodes:22
                                                        execution_graph 6859 bf783a 6860 bf7848 ___except_validate_context_record 6859->6860 6868 bf6913 6860->6868 6862 bf784e 6863 bf788d 6862->6863 6864 bf78b3 6862->6864 6867 bf78ab 6862->6867 6863->6867 6881 bf7c59 6863->6881 6864->6867 6884 bf72d1 6864->6884 6935 bf6921 6868->6935 6870 bf6918 6870->6862 6949 bfc79c 6870->6949 6873 bf91b7 6875 bf91e0 6873->6875 6876 bf91c1 IsProcessorFeaturePresent 6873->6876 6985 bf8a3f 6875->6985 6878 bf91cd 6876->6878 6880 bf9ab4 _unexpected 8 API calls 6878->6880 6880->6875 7307 bf7c71 6881->7307 6883 bf7c6c 6883->6867 6888 bf72f1 __FrameHandler3::FrameUnwindToState 6884->6888 6885 bf7604 6886 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 6885->6886 6897 bf760a 6885->6897 6887 bf7675 6886->6887 6888->6885 6891 bf73d3 6888->6891 6892 bf6913 _unexpected 78 API calls 6888->6892 6889 bf75d9 6889->6885 6890 bf75d7 6889->6890 7341 bf7676 6889->7341 6894 bf6913 _unexpected 78 API calls 6890->6894 6891->6889 6893 bf745c 6891->6893 6934 bf73d9 type_info::operator== 6891->6934 6895 bf7353 6892->6895 6900 bf7573 __InternalCxxFrameHandler 6893->6900 7326 bf6cc4 6893->7326 6894->6885 6895->6897 6899 bf6913 _unexpected 78 API calls 6895->6899 6897->6867 6902 bf7361 6899->6902 6900->6890 6901 bf75a3 6900->6901 6903 bf75c8 6900->6903 6904 bf75ad 6900->6904 6901->6890 6901->6904 6905 bf6913 _unexpected 78 API calls 6902->6905 6906 bf7d59 __InternalCxxFrameHandler 68 API calls 6903->6906 6907 bf6913 _unexpected 78 API calls 6904->6907 6914 bf7369 6905->6914 6908 bf75d1 6906->6908 6909 bf75b8 6907->6909 6908->6890 6910 bf7634 6908->6910 6911 bf6913 _unexpected 78 API calls 6909->6911 6913 bf6913 _unexpected 78 API calls 6910->6913 6911->6934 6912 bf6913 _unexpected 78 API calls 6915 bf73b2 6912->6915 6916 bf7639 6913->6916 6914->6885 6914->6912 6915->6891 6920 bf6913 _unexpected 78 API calls 6915->6920 6917 bf6913 _unexpected 78 API calls 6916->6917 6921 bf7641 6917->6921 6919 bf747d ___TypeMatch 6919->6900 7331 bf7251 6919->7331 6922 bf73bc 6920->6922 7367 bf6eb7 RtlUnwind 6921->7367 6923 bf6913 _unexpected 78 API calls 6922->6923 6927 bf73c7 6923->6927 6926 bf7614 __InternalCxxFrameHandler 7364 bf7f46 6926->7364 7321 bf7d59 6927->7321 6928 bf7655 6930 bf7c59 __InternalCxxFrameHandler 78 API calls 6928->6930 6932 bf7661 __InternalCxxFrameHandler 6930->6932 7368 bf7bd0 6932->7368 6934->6926 7358 bf90eb 6934->7358 6936 bf692d GetLastError 6935->6936 6937 bf692a 6935->6937 6988 bf6c04 6936->6988 6937->6870 6940 bf6961 6941 bf69a7 SetLastError 6940->6941 6941->6870 6943 bf695b _unexpected 6943->6940 6944 bf6983 6943->6944 6945 bf6c3f ___vcrt_FlsSetValue 6 API calls 6943->6945 6946 bf6c3f ___vcrt_FlsSetValue 6 API calls 6944->6946 6947 bf6997 6944->6947 6945->6944 6946->6947 6948 bf9127 ___vcrt_freefls@4 14 API calls 6947->6948 6948->6940 7010 bfc6ca 6949->7010 6952 bfc7e1 6953 bfc7ed __FrameHandler3::FrameUnwindToState 6952->6953 6954 bf98f1 __dosmaperr 14 API calls 6953->6954 6955 bfc83d 6953->6955 6957 bfc84f _unexpected 6953->6957 6962 bfc81e _unexpected 6953->6962 6954->6962 6956 bf9d91 __dosmaperr 14 API calls 6955->6956 6958 bfc842 6956->6958 6959 bfc885 _unexpected 6957->6959 7021 bfb43d EnterCriticalSection 6957->7021 6960 bf9cb0 ___std_exception_copy 29 API calls 6958->6960 6964 bfc9bf 6959->6964 6965 bfc8c2 6959->6965 6975 bfc8f0 6959->6975 6981 bfc827 6960->6981 6962->6955 6962->6957 6962->6981 6967 bfc9ca 6964->6967 7053 bfb485 LeaveCriticalSection 6964->7053 6965->6975 7022 bf97a0 GetLastError 6965->7022 6968 bf8a3f _unexpected 21 API calls 6967->6968 6974 bfc9d2 __FrameHandler3::FrameUnwindToState 6968->6974 6971 bf97a0 _unexpected 68 API calls 6977 bfc945 6971->6977 6973 bf97a0 _unexpected 68 API calls 6973->6975 7054 bfcd97 EnterCriticalSection 6974->7054 7049 bfc96b 6975->7049 6978 bf97a0 _unexpected 68 API calls 6977->6978 6977->6981 6978->6981 6979 bfca22 7066 bfca53 6979->7066 6980 bfc9e9 _unexpected 6980->6979 7055 bfcc15 6980->7055 6981->6873 6986 bf88af _unexpected 21 API calls 6985->6986 6987 bf8a50 6986->6987 6998 bf6aa3 6988->6998 6991 bf6c36 TlsGetValue 6992 bf6942 6991->6992 6992->6940 6992->6941 6993 bf6c3f 6992->6993 6994 bf6aa3 ___vcrt_FlsFree 5 API calls 6993->6994 6995 bf6c59 6994->6995 6996 bf6c74 TlsSetValue 6995->6996 6997 bf6c68 6995->6997 6996->6997 6997->6943 6999 bf6ac4 6998->6999 7000 bf6ac0 6998->7000 6999->7000 7002 bf6b2c GetProcAddress 6999->7002 7003 bf6b1d 6999->7003 7005 bf6b43 LoadLibraryExW 6999->7005 7000->6991 7000->6992 7002->7000 7003->7002 7004 bf6b25 FreeLibrary 7003->7004 7004->7002 7006 bf6b5a GetLastError 7005->7006 7007 bf6b8a 7005->7007 7006->7007 7008 bf6b65 ___vcrt_FlsFree 7006->7008 7007->6999 7008->7007 7009 bf6b7b LoadLibraryExW 7008->7009 7009->6999 7011 bfc6d6 __FrameHandler3::FrameUnwindToState 7010->7011 7016 bfb43d EnterCriticalSection 7011->7016 7013 bfc6e4 7017 bfc726 7013->7017 7016->7013 7020 bfb485 LeaveCriticalSection 7017->7020 7019 bf91ac 7019->6873 7019->6952 7020->7019 7021->6959 7023 bf97b6 7022->7023 7024 bf97bc 7022->7024 7025 bfc373 _unexpected 6 API calls 7023->7025 7026 bfc3b2 _unexpected 6 API calls 7024->7026 7028 bf97c0 SetLastError 7024->7028 7025->7024 7027 bf97d8 7026->7027 7027->7028 7030 bf9da4 _unexpected 14 API calls 7027->7030 7031 bf9855 7028->7031 7032 bf9850 7028->7032 7033 bf97ed 7030->7033 7069 bf91a7 7031->7069 7032->6973 7034 bf9806 7033->7034 7035 bf97f5 7033->7035 7038 bfc3b2 _unexpected 6 API calls 7034->7038 7037 bfc3b2 _unexpected 6 API calls 7035->7037 7040 bf9803 7037->7040 7041 bf9812 7038->7041 7045 bf9e01 ___free_lconv_mon 14 API calls 7040->7045 7042 bf982d 7041->7042 7043 bf9816 7041->7043 7046 bf95ce _unexpected 14 API calls 7042->7046 7044 bfc3b2 _unexpected 6 API calls 7043->7044 7044->7040 7045->7028 7047 bf9838 7046->7047 7048 bf9e01 ___free_lconv_mon 14 API calls 7047->7048 7048->7028 7050 bfc96f 7049->7050 7051 bfc937 7049->7051 7080 bfb485 LeaveCriticalSection 7050->7080 7051->6971 7051->6977 7051->6981 7053->6967 7054->6980 7056 bfcc2a _unexpected 7055->7056 7057 bfcc3c 7056->7057 7058 bfcc31 7056->7058 7084 bfcbac 7057->7084 7081 bfcb0b 7058->7081 7062 bfcc37 _unexpected 7062->6979 7064 bfcc5d 7097 bfdf04 7064->7097 7306 bfcdab LeaveCriticalSection 7066->7306 7068 bfca41 7068->6873 7070 bfc79c _unexpected 2 API calls 7069->7070 7071 bf91ac 7070->7071 7072 bf91b7 7071->7072 7073 bfc7e1 _unexpected 67 API calls 7071->7073 7074 bf91c1 IsProcessorFeaturePresent 7072->7074 7079 bf91e0 7072->7079 7073->7072 7076 bf91cd 7074->7076 7075 bf8a3f _unexpected 21 API calls 7077 bf91ea 7075->7077 7078 bf9ab4 _unexpected 8 API calls 7076->7078 7078->7079 7079->7075 7080->7051 7108 bfca5f 7081->7108 7085 bfcbc5 7084->7085 7089 bfcbec 7084->7089 7086 bfd3f4 _unexpected 29 API calls 7085->7086 7085->7089 7087 bfcbe1 7086->7087 7130 bfe723 7087->7130 7089->7062 7090 bfd3f4 7089->7090 7091 bfd415 7090->7091 7092 bfd400 7090->7092 7091->7064 7093 bf9d91 __dosmaperr 14 API calls 7092->7093 7094 bfd405 7093->7094 7095 bf9cb0 ___std_exception_copy 29 API calls 7094->7095 7096 bfd410 7095->7096 7096->7064 7098 bfdf15 7097->7098 7099 bfdf22 7097->7099 7100 bf9d91 __dosmaperr 14 API calls 7098->7100 7101 bfdf6b 7099->7101 7103 bfdf49 7099->7103 7106 bfdf1a 7100->7106 7102 bf9d91 __dosmaperr 14 API calls 7101->7102 7104 bfdf70 7102->7104 7288 bfde62 7103->7288 7105 bf9cb0 ___std_exception_copy 29 API calls 7104->7105 7105->7106 7106->7062 7109 bfca6b __FrameHandler3::FrameUnwindToState 7108->7109 7116 bfb43d EnterCriticalSection 7109->7116 7111 bfca75 _unexpected 7112 bfcae1 7111->7112 7117 bfc9d3 7111->7117 7125 bfcaff 7112->7125 7116->7111 7118 bfc9df __FrameHandler3::FrameUnwindToState 7117->7118 7128 bfcd97 EnterCriticalSection 7118->7128 7120 bfc9e9 _unexpected 7121 bfca22 7120->7121 7123 bfcc15 _unexpected 68 API calls 7120->7123 7122 bfca53 _unexpected LeaveCriticalSection 7121->7122 7124 bfca41 7122->7124 7123->7121 7124->7111 7129 bfb485 LeaveCriticalSection 7125->7129 7127 bfcaed 7127->7062 7128->7120 7129->7127 7132 bfe72f __FrameHandler3::FrameUnwindToState 7130->7132 7131 bfe737 7131->7089 7132->7131 7133 bfe770 7132->7133 7134 bfe7b6 7132->7134 7135 bf9c33 ___std_exception_copy 29 API calls 7133->7135 7141 bfb636 EnterCriticalSection 7134->7141 7135->7131 7137 bfe7da 7168 bfe82c 7137->7168 7138 bfe7bc 7138->7137 7142 bfe834 7138->7142 7141->7138 7143 bfe85c 7142->7143 7167 bfe87f _unexpected 7142->7167 7144 bfe860 7143->7144 7146 bfe8bb 7143->7146 7145 bf9c33 ___std_exception_copy 29 API calls 7144->7145 7145->7167 7147 bfe8d9 7146->7147 7171 bfeed8 7146->7171 7174 bfe3b0 7147->7174 7151 bfe938 7155 bfe94c 7151->7155 7156 bfe9a1 WriteFile 7151->7156 7152 bfe8f1 7153 bfe8f9 7152->7153 7154 bfe920 7152->7154 7153->7167 7181 bfe348 7153->7181 7186 bfdf81 GetConsoleOutputCP 7154->7186 7159 bfe98d 7155->7159 7160 bfe954 7155->7160 7158 bfe9c3 GetLastError 7156->7158 7156->7167 7158->7167 7214 bfe42d 7159->7214 7163 bfe979 7160->7163 7164 bfe959 7160->7164 7206 bfe5f1 7163->7206 7164->7167 7199 bfe508 7164->7199 7167->7137 7287 bfb659 LeaveCriticalSection 7168->7287 7170 bfe832 7170->7131 7221 bfee55 7171->7221 7173 bfeef1 7173->7147 7243 bfeb3b 7174->7243 7176 bfe426 7176->7151 7176->7152 7177 bfe3c2 7177->7176 7178 bfe3f0 7177->7178 7252 bf9350 7177->7252 7178->7176 7180 bfe40a GetConsoleMode 7178->7180 7180->7176 7182 bfe39f 7181->7182 7185 bfe36a 7181->7185 7182->7167 7183 bfeef6 5 API calls _unexpected 7183->7185 7184 bfe3a1 GetLastError 7184->7182 7185->7182 7185->7183 7185->7184 7187 bfdff3 7186->7187 7196 bfdffa CatchIt 7186->7196 7188 bf9350 _unexpected 64 API calls 7187->7188 7188->7196 7189 bf5a25 CatchGuardHandler 5 API calls 7190 bfe341 7189->7190 7190->7167 7191 bfd2c1 64 API calls _unexpected 7191->7196 7192 bfed31 5 API calls _unexpected 7192->7196 7193 bfe2b0 7193->7189 7193->7193 7195 bfe229 WriteFile 7195->7196 7197 bfe31f GetLastError 7195->7197 7196->7191 7196->7192 7196->7193 7196->7195 7198 bfe267 WriteFile 7196->7198 7284 bfb2b9 7196->7284 7197->7193 7198->7196 7198->7197 7204 bfe517 _unexpected 7199->7204 7200 bfe5d6 7201 bf5a25 CatchGuardHandler 5 API calls 7200->7201 7203 bfe5ef 7201->7203 7202 bfe58c WriteFile 7202->7204 7205 bfe5d8 GetLastError 7202->7205 7203->7167 7204->7200 7204->7202 7205->7200 7213 bfe600 _unexpected 7206->7213 7207 bfe708 7208 bf5a25 CatchGuardHandler 5 API calls 7207->7208 7209 bfe721 7208->7209 7209->7167 7210 bfb2b9 _unexpected WideCharToMultiByte 7210->7213 7211 bfe70a GetLastError 7211->7207 7212 bfe6bf WriteFile 7212->7211 7212->7213 7213->7207 7213->7210 7213->7211 7213->7212 7220 bfe43c _unexpected 7214->7220 7215 bfe4ed 7216 bf5a25 CatchGuardHandler 5 API calls 7215->7216 7217 bfe506 7216->7217 7217->7167 7218 bfe4ac WriteFile 7219 bfe4ef GetLastError 7218->7219 7218->7220 7219->7215 7220->7215 7220->7218 7227 bfb70d 7221->7227 7223 bfee67 7224 bfee83 SetFilePointerEx 7223->7224 7226 bfee6f _unexpected 7223->7226 7225 bfee9b GetLastError 7224->7225 7224->7226 7225->7226 7226->7173 7228 bfb72f 7227->7228 7229 bfb71a 7227->7229 7232 bf9d7e __dosmaperr 14 API calls 7228->7232 7234 bfb754 7228->7234 7240 bf9d7e 7229->7240 7235 bfb75f 7232->7235 7233 bf9d91 __dosmaperr 14 API calls 7237 bfb727 7233->7237 7234->7223 7236 bf9d91 __dosmaperr 14 API calls 7235->7236 7238 bfb767 7236->7238 7237->7223 7239 bf9cb0 ___std_exception_copy 29 API calls 7238->7239 7239->7237 7241 bf98f1 __dosmaperr 14 API calls 7240->7241 7242 bf9d83 7241->7242 7242->7233 7244 bfeb48 7243->7244 7245 bfeb55 7243->7245 7246 bf9d91 __dosmaperr 14 API calls 7244->7246 7247 bfeb61 7245->7247 7248 bf9d91 __dosmaperr 14 API calls 7245->7248 7249 bfeb4d 7246->7249 7247->7177 7250 bfeb82 7248->7250 7249->7177 7251 bf9cb0 ___std_exception_copy 29 API calls 7250->7251 7251->7249 7253 bf9360 7252->7253 7258 bfd232 7253->7258 7259 bfd249 7258->7259 7260 bf937d 7258->7260 7259->7260 7266 bfc027 7259->7266 7262 bfd290 7260->7262 7263 bf938a 7262->7263 7264 bfd2a7 7262->7264 7263->7178 7264->7263 7279 bfae4d 7264->7279 7267 bfc033 __FrameHandler3::FrameUnwindToState 7266->7267 7268 bf97a0 _unexpected 68 API calls 7267->7268 7269 bfc03c 7268->7269 7270 bfb43d _unexpected EnterCriticalSection 7269->7270 7276 bfc082 7269->7276 7271 bfc05a 7270->7271 7272 bfc0a8 _unexpected 14 API calls 7271->7272 7273 bfc06b 7272->7273 7274 bfc087 _unexpected LeaveCriticalSection 7273->7274 7275 bfc07e 7274->7275 7275->7276 7277 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7275->7277 7276->7260 7278 bfc0a7 7277->7278 7280 bf97a0 _unexpected 68 API calls 7279->7280 7281 bfae52 7280->7281 7282 bfad65 _unexpected 68 API calls 7281->7282 7283 bfae5d 7282->7283 7283->7263 7286 bfb2cc _unexpected 7284->7286 7285 bfb30a WideCharToMultiByte 7285->7196 7286->7285 7287->7170 7289 bfde6e __FrameHandler3::FrameUnwindToState 7288->7289 7301 bfb636 EnterCriticalSection 7289->7301 7291 bfde7d 7292 bfdec2 7291->7292 7294 bfb70d _unexpected 29 API calls 7291->7294 7293 bf9d91 __dosmaperr 14 API calls 7292->7293 7295 bfdec9 7293->7295 7296 bfdea9 FlushFileBuffers 7294->7296 7302 bfdef8 7295->7302 7296->7295 7297 bfdeb5 GetLastError 7296->7297 7299 bf9d7e __dosmaperr 14 API calls 7297->7299 7299->7292 7301->7291 7305 bfb659 LeaveCriticalSection 7302->7305 7304 bfdee1 7304->7106 7305->7304 7306->7068 7308 bf7c7d __FrameHandler3::FrameUnwindToState 7307->7308 7309 bf6913 _unexpected 78 API calls 7308->7309 7310 bf7c98 __CallSettingFrame@12 __FrameHandler3::FrameUnwindToState 7309->7310 7311 bf7d18 7310->7311 7316 bf7d3f 7310->7316 7313 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7311->7313 7315 bf7d1d __FrameHandler3::FrameUnwindToState 7311->7315 7314 bf7d58 7313->7314 7315->6883 7317 bf6913 _unexpected 78 API calls 7316->7317 7318 bf7d44 7317->7318 7319 bf7d4f 7318->7319 7320 bf6913 _unexpected 78 API calls 7318->7320 7319->7311 7320->7319 7322 bf7ded 7321->7322 7325 bf7d6d ___TypeMatch 7321->7325 7323 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7322->7323 7324 bf7df2 7323->7324 7325->6891 7327 bf6ce2 7326->7327 7328 bf6d18 7327->7328 7329 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7327->7329 7328->6919 7330 bf6d33 7329->7330 7332 bf7270 7331->7332 7333 bf7263 7331->7333 7387 bf6eb7 RtlUnwind 7332->7387 7383 bf71b8 7333->7383 7336 bf7285 7337 bf7c71 __FrameHandler3::FrameUnwindToState 78 API calls 7336->7337 7338 bf7296 __FrameHandler3::FrameUnwindToState 7337->7338 7388 bf7a01 7338->7388 7340 bf72be CatchIt 7340->6919 7342 bf768c 7341->7342 7343 bf77a1 7341->7343 7344 bf6913 _unexpected 78 API calls 7342->7344 7343->6890 7345 bf7693 7344->7345 7346 bf769a EncodePointer 7345->7346 7347 bf76d5 7345->7347 7350 bf6913 _unexpected 78 API calls 7346->7350 7347->7343 7348 bf77a6 7347->7348 7349 bf76f2 7347->7349 7351 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7348->7351 7352 bf6cc4 __InternalCxxFrameHandler 68 API calls 7349->7352 7354 bf76a8 7350->7354 7353 bf77ab 7351->7353 7356 bf7709 7352->7356 7354->7347 7355 bf6d91 __InternalCxxFrameHandler 78 API calls 7354->7355 7355->7347 7356->7343 7357 bf7251 CatchIt 79 API calls 7356->7357 7357->7356 7359 bf90f7 __FrameHandler3::FrameUnwindToState 7358->7359 7360 bf97a0 _unexpected 68 API calls 7359->7360 7363 bf90fc 7360->7363 7361 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7362 bf9126 7361->7362 7363->7361 7365 bf7f8d RaiseException 7364->7365 7366 bf7f60 7364->7366 7365->6910 7366->7365 7367->6928 7369 bf7bdc __EH_prolog3_catch 7368->7369 7370 bf6913 _unexpected 78 API calls 7369->7370 7371 bf7be1 7370->7371 7372 bf7c04 7371->7372 7448 bf7e7c 7371->7448 7374 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7372->7374 7379 bf7c09 7374->7379 7377 bf7c55 7377->6885 7379->7377 7381 bf6913 _unexpected 78 API calls 7379->7381 7382 bf7c4b 7381->7382 7382->6885 7384 bf71c4 __FrameHandler3::FrameUnwindToState 7383->7384 7402 bf707a 7384->7402 7386 bf71ec CatchIt ___AdjustPointer 7386->7332 7387->7336 7389 bf7a0d __FrameHandler3::FrameUnwindToState 7388->7389 7409 bf6f3b 7389->7409 7392 bf6913 _unexpected 78 API calls 7393 bf7a39 7392->7393 7394 bf6913 _unexpected 78 API calls 7393->7394 7395 bf7a44 7394->7395 7396 bf6913 _unexpected 78 API calls 7395->7396 7397 bf7a4f 7396->7397 7398 bf6913 _unexpected 78 API calls 7397->7398 7399 bf7a57 CatchIt 7398->7399 7414 bf7b54 7399->7414 7401 bf7b3c 7401->7340 7403 bf7086 __FrameHandler3::FrameUnwindToState 7402->7403 7404 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7403->7404 7405 bf7101 CatchIt ___AdjustPointer 7403->7405 7406 bf71b7 __FrameHandler3::FrameUnwindToState 7404->7406 7405->7386 7407 bf707a CatchIt 68 API calls 7406->7407 7408 bf71ec CatchIt ___AdjustPointer 7407->7408 7408->7386 7410 bf6913 _unexpected 78 API calls 7409->7410 7411 bf6f4c 7410->7411 7412 bf6913 _unexpected 78 API calls 7411->7412 7413 bf6f57 7412->7413 7413->7392 7423 bf6f5f 7414->7423 7416 bf7b65 7417 bf6913 _unexpected 78 API calls 7416->7417 7418 bf7b6b 7417->7418 7419 bf6913 _unexpected 78 API calls 7418->7419 7420 bf7b76 7419->7420 7422 bf7bb7 __InternalCxxFrameHandler 7420->7422 7440 bf66a6 7420->7440 7422->7401 7424 bf6913 _unexpected 78 API calls 7423->7424 7425 bf6f68 7424->7425 7426 bf6f7e 7425->7426 7427 bf6f70 7425->7427 7429 bf6913 _unexpected 78 API calls 7426->7429 7428 bf6913 _unexpected 78 API calls 7427->7428 7430 bf6f78 7428->7430 7431 bf6f83 7429->7431 7430->7416 7431->7430 7432 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7431->7432 7433 bf6fa6 7432->7433 7434 bf5a25 CatchGuardHandler 5 API calls 7433->7434 7436 bf6fbb CatchGuardHandler 7434->7436 7435 bf6fc6 7435->7416 7436->7435 7437 bf7015 7436->7437 7443 bf6eb7 RtlUnwind 7436->7443 7444 bf6d91 7437->7444 7441 bf6913 _unexpected 78 API calls 7440->7441 7442 bf66ae 7441->7442 7442->7422 7443->7437 7445 bf6db3 __InternalCxxFrameHandler 7444->7445 7447 bf6da1 7444->7447 7446 bf6913 _unexpected 78 API calls 7445->7446 7446->7447 7447->7435 7449 bf6913 _unexpected 78 API calls 7448->7449 7450 bf7e82 7449->7450 7451 bf90eb _unexpected 68 API calls 7450->7451 7452 bf7e98 7451->7452 8077 bf52b5 8078 bf52be 8077->8078 8085 bf5845 IsProcessorFeaturePresent 8078->8085 8082 bf52cf 8083 bf52d3 8082->8083 8084 bf654d ___scrt_uninitialize_crt 7 API calls 8082->8084 8084->8083 8086 bf52ca 8085->8086 8087 bf652e 8086->8087 8095 bf6a01 8087->8095 8090 bf6537 8090->8082 8092 bf653f 8093 bf654a 8092->8093 8094 bf6a3d ___vcrt_uninitialize_locks DeleteCriticalSection 8092->8094 8093->8082 8094->8090 8096 bf6a0a 8095->8096 8098 bf6a33 8096->8098 8099 bf6533 8096->8099 8109 bf6c7d 8096->8109 8100 bf6a3d ___vcrt_uninitialize_locks DeleteCriticalSection 8098->8100 8099->8090 8101 bf69b3 8099->8101 8100->8099 8114 bf6b8e 8101->8114 8104 bf69c8 8104->8092 8105 bf6c3f ___vcrt_FlsSetValue 6 API calls 8106 bf69d6 8105->8106 8107 bf69e3 8106->8107 8108 bf69e6 ___vcrt_uninitialize_ptd 6 API calls 8106->8108 8107->8092 8108->8104 8110 bf6aa3 ___vcrt_FlsFree 5 API calls 8109->8110 8111 bf6c97 8110->8111 8112 bf6cb5 InitializeCriticalSectionAndSpinCount 8111->8112 8113 bf6ca0 8111->8113 8112->8113 8113->8096 8115 bf6aa3 ___vcrt_FlsFree 5 API calls 8114->8115 8116 bf6ba8 8115->8116 8117 bf6bc1 TlsAlloc 8116->8117 8118 bf69bd 8116->8118 8118->8104 8118->8105 8161 bf5235 8164 bf54dd 8161->8164 8163 bf523a 8163->8163 8165 bf54f3 8164->8165 8167 bf54fc 8165->8167 8168 bf5490 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 8165->8168 8167->8163 8168->8167 8404 bf8fb4 8407 bf901c 8404->8407 8408 bf8fc7 8407->8408 8409 bf9030 8407->8409 8409->8408 8410 bf9e01 ___free_lconv_mon 14 API calls 8409->8410 8410->8408 8516 bfc334 8517 bfc211 _unexpected 5 API calls 8516->8517 8518 bfc350 8517->8518 8519 bfc36b TlsFree 8518->8519 8520 bfc359 8518->8520 6725 c022cc 6737 c02277 GetPEB 6725->6737 6727 c022e5 6728 c02309 VirtualAlloc 6727->6728 6734 c023fa 6727->6734 6729 c02321 6728->6729 6728->6734 6739 c02098 VirtualAlloc 6729->6739 6732 c023eb VirtualFree 6732->6734 6733 c02359 VirtualAlloc 6733->6732 6735 c02370 6733->6735 6736 c023ae VirtualProtect 6735->6736 6736->6732 6738 c02295 6737->6738 6738->6727 6740 c02270 6739->6740 6741 c020d0 VirtualFree 6739->6741 6740->6732 6740->6733 6741->6740 7661 bf81b1 7662 bf81c8 7661->7662 7672 bf81c1 7661->7672 7663 bf81e9 7662->7663 7665 bf81d3 7662->7665 7691 bfae05 7663->7691 7667 bf9d91 __dosmaperr 14 API calls 7665->7667 7668 bf81d8 7667->7668 7670 bf9cb0 ___std_exception_copy 29 API calls 7668->7670 7670->7672 7677 bf824b 7679 bf9d91 __dosmaperr 14 API calls 7677->7679 7678 bf8257 7680 bf82ee 68 API calls 7678->7680 7681 bf8250 7679->7681 7682 bf826d 7680->7682 7684 bf9e01 ___free_lconv_mon 14 API calls 7681->7684 7682->7681 7683 bf8291 7682->7683 7685 bf82a8 7683->7685 7686 bf82b2 7683->7686 7684->7672 7687 bf9e01 ___free_lconv_mon 14 API calls 7685->7687 7688 bf9e01 ___free_lconv_mon 14 API calls 7686->7688 7689 bf82b0 7687->7689 7688->7689 7690 bf9e01 ___free_lconv_mon 14 API calls 7689->7690 7690->7672 7692 bfae0e 7691->7692 7696 bf81ef 7691->7696 7719 bf985b 7692->7719 7697 bfa7e8 GetModuleFileNameW 7696->7697 7698 bfa828 7697->7698 7699 bfa817 GetLastError 7697->7699 7939 bfa566 7698->7939 7934 bf9d37 7699->7934 7702 bfa823 7705 bf5a25 CatchGuardHandler 5 API calls 7702->7705 7706 bf8202 7705->7706 7707 bf82ee 7706->7707 7709 bf8314 7707->7709 7711 bf8372 7709->7711 7978 bfb136 7709->7978 7710 bf8235 7713 bf8462 7710->7713 7711->7710 7712 bfb136 68 API calls 7711->7712 7712->7711 7714 bf8473 7713->7714 7715 bf8242 7713->7715 7714->7715 7716 bf9da4 _unexpected 14 API calls 7714->7716 7715->7677 7715->7678 7717 bf849c 7716->7717 7718 bf9e01 ___free_lconv_mon 14 API calls 7717->7718 7718->7715 7720 bf986c 7719->7720 7721 bf9866 7719->7721 7723 bfc3b2 _unexpected 6 API calls 7720->7723 7739 bf9872 7720->7739 7722 bfc373 _unexpected 6 API calls 7721->7722 7722->7720 7724 bf9886 7723->7724 7726 bf9da4 _unexpected 14 API calls 7724->7726 7724->7739 7725 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7727 bf98f0 7725->7727 7728 bf9896 7726->7728 7729 bf989e 7728->7729 7730 bf98b3 7728->7730 7731 bfc3b2 _unexpected 6 API calls 7729->7731 7732 bfc3b2 _unexpected 6 API calls 7730->7732 7740 bf98aa 7731->7740 7733 bf98bf 7732->7733 7734 bf98c3 7733->7734 7735 bf98d2 7733->7735 7737 bfc3b2 _unexpected 6 API calls 7734->7737 7738 bf95ce _unexpected 14 API calls 7735->7738 7736 bf9e01 ___free_lconv_mon 14 API calls 7736->7739 7737->7740 7741 bf98dd 7738->7741 7739->7725 7743 bf9877 7739->7743 7740->7736 7742 bf9e01 ___free_lconv_mon 14 API calls 7741->7742 7742->7743 7744 bfac10 7743->7744 7767 bfad65 7744->7767 7749 bfac53 7749->7696 7750 bfbbef 15 API calls 7751 bfac64 7750->7751 7752 bfac6c 7751->7752 7753 bfac7a 7751->7753 7754 bf9e01 ___free_lconv_mon 14 API calls 7752->7754 7785 bfae60 7753->7785 7754->7749 7757 bfacb2 7758 bf9d91 __dosmaperr 14 API calls 7757->7758 7760 bfacb7 7758->7760 7759 bfacf9 7762 bfad42 7759->7762 7796 bfa889 7759->7796 7763 bf9e01 ___free_lconv_mon 14 API calls 7760->7763 7761 bfaccd 7761->7759 7764 bf9e01 ___free_lconv_mon 14 API calls 7761->7764 7766 bf9e01 ___free_lconv_mon 14 API calls 7762->7766 7763->7749 7764->7759 7766->7749 7768 bfad71 __FrameHandler3::FrameUnwindToState 7767->7768 7775 bfad8b 7768->7775 7804 bfb43d EnterCriticalSection 7768->7804 7770 bfad9b 7776 bf9e01 ___free_lconv_mon 14 API calls 7770->7776 7777 bfadc7 7770->7777 7771 bfac3a 7778 bfa997 7771->7778 7772 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7774 bfae04 7772->7774 7775->7771 7775->7772 7776->7777 7805 bfade4 7777->7805 7809 bfa49b 7778->7809 7780 bfa9a9 7781 bfa9ca 7780->7781 7782 bfa9b8 GetOEMCP 7780->7782 7783 bfa9e1 7781->7783 7784 bfa9cf GetACP 7781->7784 7782->7783 7783->7749 7783->7750 7784->7783 7786 bfa997 70 API calls 7785->7786 7787 bfae80 7786->7787 7789 bfaebd IsValidCodePage 7787->7789 7794 bfaf85 7787->7794 7795 bfaed8 _unexpected 7787->7795 7788 bf5a25 CatchGuardHandler 5 API calls 7790 bfaca7 7788->7790 7791 bfaecf 7789->7791 7789->7794 7790->7757 7790->7761 7792 bfaef8 GetCPInfo 7791->7792 7791->7795 7792->7794 7792->7795 7794->7788 7825 bfaa6b 7795->7825 7797 bfa895 __FrameHandler3::FrameUnwindToState 7796->7797 7908 bfb43d EnterCriticalSection 7797->7908 7799 bfa89f 7909 bfa8d6 7799->7909 7804->7770 7808 bfb485 LeaveCriticalSection 7805->7808 7807 bfadeb 7807->7775 7808->7807 7810 bfa4b9 7809->7810 7816 bfa4b2 7809->7816 7811 bf97a0 _unexpected 68 API calls 7810->7811 7810->7816 7812 bfa4da 7811->7812 7817 bfd205 7812->7817 7816->7780 7818 bfa4f0 7817->7818 7819 bfd218 7817->7819 7821 bfd263 7818->7821 7819->7818 7820 bfc027 _unexpected 68 API calls 7819->7820 7820->7818 7822 bfd28b 7821->7822 7823 bfd276 7821->7823 7822->7816 7823->7822 7824 bfae4d _unexpected 68 API calls 7823->7824 7824->7822 7826 bfaa93 GetCPInfo 7825->7826 7827 bfab5c 7825->7827 7826->7827 7832 bfaaab 7826->7832 7829 bf5a25 CatchGuardHandler 5 API calls 7827->7829 7831 bfac0e 7829->7831 7831->7794 7836 bfbc3d 7832->7836 7835 bfdca3 70 API calls 7835->7827 7837 bfa49b 68 API calls 7836->7837 7838 bfbc5d 7837->7838 7856 bfb1ff 7838->7856 7840 bfbd19 7843 bf5a25 CatchGuardHandler 5 API calls 7840->7843 7841 bfbd11 7859 bfbd3e 7841->7859 7842 bfbc8a 7842->7840 7842->7841 7845 bfbbef 15 API calls 7842->7845 7847 bfbcaf _unexpected 7842->7847 7846 bfab13 7843->7846 7845->7847 7851 bfdca3 7846->7851 7847->7841 7848 bfb1ff _unexpected MultiByteToWideChar 7847->7848 7849 bfbcf8 7848->7849 7849->7841 7850 bfbcff GetStringTypeW 7849->7850 7850->7841 7852 bfa49b 68 API calls 7851->7852 7853 bfdcb6 7852->7853 7865 bfdab4 7853->7865 7863 bfb167 7856->7863 7860 bfbd5b 7859->7860 7861 bfbd4a 7859->7861 7860->7840 7861->7860 7862 bf9e01 ___free_lconv_mon 14 API calls 7861->7862 7862->7860 7864 bfb178 MultiByteToWideChar 7863->7864 7864->7842 7866 bfdacf 7865->7866 7867 bfb1ff _unexpected MultiByteToWideChar 7866->7867 7871 bfdb13 7867->7871 7868 bfdc8e 7869 bf5a25 CatchGuardHandler 5 API calls 7868->7869 7870 bfab34 7869->7870 7870->7835 7871->7868 7872 bfbbef 15 API calls 7871->7872 7874 bfdb39 7871->7874 7885 bfdbe1 7871->7885 7872->7874 7873 bfbd3e __freea 14 API calls 7873->7868 7875 bfb1ff _unexpected MultiByteToWideChar 7874->7875 7874->7885 7876 bfdb82 7875->7876 7876->7885 7893 bfc43f 7876->7893 7879 bfdbb8 7884 bfc43f 6 API calls 7879->7884 7879->7885 7880 bfdbf0 7881 bfdc79 7880->7881 7882 bfbbef 15 API calls 7880->7882 7886 bfdc02 7880->7886 7883 bfbd3e __freea 14 API calls 7881->7883 7882->7886 7883->7885 7884->7885 7885->7873 7886->7881 7887 bfc43f 6 API calls 7886->7887 7888 bfdc45 7887->7888 7888->7881 7889 bfb2b9 _unexpected WideCharToMultiByte 7888->7889 7890 bfdc5f 7889->7890 7890->7881 7891 bfdc68 7890->7891 7892 bfbd3e __freea 14 API calls 7891->7892 7892->7885 7899 bfc112 7893->7899 7897 bfc490 LCMapStringW 7898 bfc450 7897->7898 7898->7879 7898->7880 7898->7885 7900 bfc211 _unexpected 5 API calls 7899->7900 7901 bfc128 7900->7901 7901->7898 7902 bfc49c 7901->7902 7905 bfc12c 7902->7905 7904 bfc4a7 7904->7897 7906 bfc211 _unexpected 5 API calls 7905->7906 7907 bfc142 7906->7907 7907->7904 7908->7799 7919 bfb065 7909->7919 7911 bfa8f8 7912 bfb065 29 API calls 7911->7912 7913 bfa917 7912->7913 7914 bfa8ac 7913->7914 7915 bf9e01 ___free_lconv_mon 14 API calls 7913->7915 7916 bfa8ca 7914->7916 7915->7914 7933 bfb485 LeaveCriticalSection 7916->7933 7918 bfa8b8 7918->7762 7920 bfb076 7919->7920 7924 bfb072 CatchIt 7919->7924 7921 bfb07d 7920->7921 7926 bfb090 _unexpected 7920->7926 7922 bf9d91 __dosmaperr 14 API calls 7921->7922 7923 bfb082 7922->7923 7925 bf9cb0 ___std_exception_copy 29 API calls 7923->7925 7924->7911 7925->7924 7926->7924 7927 bfb0be 7926->7927 7928 bfb0c7 7926->7928 7929 bf9d91 __dosmaperr 14 API calls 7927->7929 7928->7924 7930 bf9d91 __dosmaperr 14 API calls 7928->7930 7931 bfb0c3 7929->7931 7930->7931 7932 bf9cb0 ___std_exception_copy 29 API calls 7931->7932 7932->7924 7933->7918 7935 bf9d7e __dosmaperr 14 API calls 7934->7935 7936 bf9d42 __dosmaperr 7935->7936 7937 bf9d91 __dosmaperr 14 API calls 7936->7937 7938 bf9d55 7937->7938 7938->7702 7940 bfa49b 68 API calls 7939->7940 7941 bfa578 7940->7941 7942 bfa58a 7941->7942 7965 bfc2d6 7941->7965 7944 bfa6eb 7942->7944 7945 bfa6f8 7944->7945 7946 bfa707 7944->7946 7945->7702 7947 bfa70f 7946->7947 7948 bfa734 7946->7948 7947->7945 7971 bfa7ad 7947->7971 7949 bfb2b9 _unexpected WideCharToMultiByte 7948->7949 7950 bfa744 7949->7950 7952 bfa74b GetLastError 7950->7952 7953 bfa761 7950->7953 7954 bf9d37 __dosmaperr 14 API calls 7952->7954 7955 bfa772 7953->7955 7957 bfa7ad 14 API calls 7953->7957 7956 bfa757 7954->7956 7955->7945 7975 bfa542 7955->7975 7959 bf9d91 __dosmaperr 14 API calls 7956->7959 7957->7955 7959->7945 7961 bfa78c GetLastError 7962 bf9d37 __dosmaperr 14 API calls 7961->7962 7963 bfa798 7962->7963 7964 bf9d91 __dosmaperr 14 API calls 7963->7964 7964->7945 7968 bfc0f8 7965->7968 7969 bfc211 _unexpected 5 API calls 7968->7969 7970 bfc10e 7969->7970 7970->7942 7972 bfa7b8 7971->7972 7973 bf9d91 __dosmaperr 14 API calls 7972->7973 7974 bfa7c1 7973->7974 7974->7945 7976 bfb2b9 _unexpected WideCharToMultiByte 7975->7976 7977 bfa55f 7976->7977 7977->7945 7977->7961 7981 bfb0e6 7978->7981 7982 bfa49b 68 API calls 7981->7982 7983 bfb0f9 7982->7983 7983->7709 8169 bf8627 8170 bf8639 8169->8170 8172 bf863f 8169->8172 8171 bf85f8 14 API calls 8170->8171 8171->8172 7453 bf5426 7454 bf5432 7453->7454 7455 bf5448 7454->7455 7459 bf905c 7454->7459 7457 bf5440 7464 bf654d 7457->7464 7460 bf9067 7459->7460 7463 bf9079 ___scrt_uninitialize_crt 7459->7463 7461 bf9075 7460->7461 7470 bfcc7a 7460->7470 7461->7457 7463->7457 7465 bf6556 7464->7465 7466 bf6560 7464->7466 7473 bf69e6 7465->7473 7466->7455 7471 bfcb0b ___scrt_uninitialize_crt 68 API calls 7470->7471 7472 bfcc81 7471->7472 7472->7461 7474 bf69f0 7473->7474 7476 bf655b 7473->7476 7481 bf6bc9 7474->7481 7477 bf6a3d 7476->7477 7478 bf6a67 7477->7478 7479 bf6a48 7477->7479 7478->7466 7480 bf6a52 DeleteCriticalSection 7479->7480 7480->7478 7480->7480 7482 bf6aa3 ___vcrt_FlsFree 5 API calls 7481->7482 7483 bf6be3 7482->7483 7484 bf6bfb TlsFree 7483->7484 7485 bf6bef 7483->7485 7484->7485 7485->7476 7486 bfd420 7487 bfd45a 7486->7487 7488 bf9d91 __dosmaperr 14 API calls 7487->7488 7493 bfd46e 7487->7493 7489 bfd463 7488->7489 7490 bf9cb0 ___std_exception_copy 29 API calls 7489->7490 7490->7493 7491 bf5a25 CatchGuardHandler 5 API calls 7492 bfd47b 7491->7492 7493->7491 7493->7493 8173 c00260 8174 c00280 8173->8174 8177 c006f8 8174->8177 8179 c00737 __startOneArgErrorHandling 8177->8179 8178 c007bf __startOneArgErrorHandling 8181 c00eb2 __startOneArgErrorHandling 14 API calls 8178->8181 8182 c007f4 8178->8182 8179->8178 8185 c00b9e 8179->8185 8181->8182 8183 bf5a25 CatchGuardHandler 5 API calls 8182->8183 8184 c002a0 8183->8184 8186 c00bc1 __raise_exc RaiseException 8185->8186 8187 c00bbc 8186->8187 8187->8178 8016 bfa51d 8017 bfa527 8016->8017 8018 bfa537 8017->8018 8020 bf9e01 ___free_lconv_mon 14 API calls 8017->8020 8019 bf9e01 ___free_lconv_mon 14 API calls 8018->8019 8021 bfa53e 8019->8021 8020->8017 8022 bf8516 8023 bf852b 8022->8023 8024 bf9da4 _unexpected 14 API calls 8023->8024 8025 bf8552 8024->8025 8026 bf855a 8025->8026 8035 bf8564 8025->8035 8027 bf9e01 ___free_lconv_mon 14 API calls 8026->8027 8043 bf8560 8027->8043 8028 bf85c1 8029 bf9e01 ___free_lconv_mon 14 API calls 8028->8029 8029->8043 8030 bf9da4 _unexpected 14 API calls 8030->8035 8031 bf85d0 8053 bf85f8 8031->8053 8035->8028 8035->8030 8035->8031 8037 bf85eb 8035->8037 8040 bf9e01 ___free_lconv_mon 14 API calls 8035->8040 8044 bf914d 8035->8044 8036 bf9e01 ___free_lconv_mon 14 API calls 8039 bf85dd 8036->8039 8038 bf9cc0 ___std_exception_copy 11 API calls 8037->8038 8041 bf85f7 8038->8041 8042 bf9e01 ___free_lconv_mon 14 API calls 8039->8042 8040->8035 8042->8043 8045 bf9169 8044->8045 8046 bf915b 8044->8046 8047 bf9d91 __dosmaperr 14 API calls 8045->8047 8046->8045 8051 bf9181 8046->8051 8048 bf9171 8047->8048 8049 bf9cb0 ___std_exception_copy 29 API calls 8048->8049 8050 bf917b 8049->8050 8050->8035 8051->8050 8052 bf9d91 __dosmaperr 14 API calls 8051->8052 8052->8048 8057 bf8605 8053->8057 8058 bf85d6 8053->8058 8054 bf861c 8056 bf9e01 ___free_lconv_mon 14 API calls 8054->8056 8055 bf9e01 ___free_lconv_mon 14 API calls 8055->8057 8056->8058 8057->8054 8057->8055 8058->8036 8119 bf8a91 8120 bf8ac3 8119->8120 8121 bf8aa0 8119->8121 8121->8120 8122 bf9d91 __dosmaperr 14 API calls 8121->8122 8123 bf8ab3 8122->8123 8124 bf9cb0 ___std_exception_copy 29 API calls 8123->8124 8125 bf8abe 8124->8125 8188 bfda10 8191 bfda27 8188->8191 8190 bfda22 8192 bfda49 8191->8192 8193 bfda35 8191->8193 8194 bfda51 8192->8194 8197 bfda63 8192->8197 8195 bf9d91 __dosmaperr 14 API calls 8193->8195 8196 bf9d91 __dosmaperr 14 API calls 8194->8196 8198 bfda3a 8195->8198 8200 bfda56 8196->8200 8201 bfa49b 68 API calls 8197->8201 8204 bfda61 8197->8204 8199 bf9cb0 ___std_exception_copy 29 API calls 8198->8199 8202 bfda45 8199->8202 8203 bf9cb0 ___std_exception_copy 29 API calls 8200->8203 8201->8204 8202->8190 8203->8204 8204->8190 8411 bfb78d GetStartupInfoW 8412 bfb7aa 8411->8412 8413 bfb83e 8411->8413 8412->8413 8417 bfb598 8412->8417 8415 bfb7d2 8415->8413 8416 bfb802 GetFileType 8415->8416 8416->8415 8418 bfb5a4 __FrameHandler3::FrameUnwindToState 8417->8418 8419 bfb5ce 8418->8419 8420 bfb5ad 8418->8420 8430 bfb43d EnterCriticalSection 8419->8430 8421 bf9d91 __dosmaperr 14 API calls 8420->8421 8423 bfb5b2 8421->8423 8424 bf9cb0 ___std_exception_copy 29 API calls 8423->8424 8426 bfb5bc 8424->8426 8425 bfb606 8438 bfb62d 8425->8438 8426->8415 8427 bfb5da 8427->8425 8431 bfb4e8 8427->8431 8430->8427 8432 bf9da4 _unexpected 14 API calls 8431->8432 8435 bfb4fa 8432->8435 8433 bfb507 8434 bf9e01 ___free_lconv_mon 14 API calls 8433->8434 8436 bfb55c 8434->8436 8435->8433 8441 bfc3f4 8435->8441 8436->8427 8446 bfb485 LeaveCriticalSection 8438->8446 8440 bfb634 8440->8426 8442 bfc211 _unexpected 5 API calls 8441->8442 8443 bfc410 8442->8443 8444 bfc42e InitializeCriticalSectionAndSpinCount 8443->8444 8445 bfc419 8443->8445 8444->8445 8445->8435 8446->8440 6743 bf908c 6744 bf90aa 6743->6744 6748 bf90ca 6743->6748 6745 bf9d91 __dosmaperr 14 API calls 6744->6745 6746 bf90c0 6745->6746 6749 bf9cb0 6746->6749 6752 bf9bfc 6749->6752 6751 bf9cbc 6751->6748 6753 bf9c0e _unexpected 6752->6753 6756 bf9c33 6753->6756 6755 bf9c26 _unexpected 6755->6751 6757 bf9c4a 6756->6757 6758 bf9c43 6756->6758 6760 bf9c58 6757->6760 6771 bf9a8b 6757->6771 6767 bf92a0 GetLastError 6758->6767 6760->6755 6762 bf9c7f 6762->6760 6774 bf9cc0 IsProcessorFeaturePresent 6762->6774 6764 bf9caf 6765 bf9bfc ___std_exception_copy 29 API calls 6764->6765 6766 bf9cbc 6765->6766 6766->6755 6768 bf92b9 6767->6768 6778 bf99a2 6768->6778 6772 bf9aaf 6771->6772 6773 bf9a96 GetLastError SetLastError 6771->6773 6772->6762 6773->6762 6775 bf9ccc 6774->6775 6800 bf9ab4 6775->6800 6779 bf99bb 6778->6779 6780 bf99b5 6778->6780 6782 bfc3b2 _unexpected 6 API calls 6779->6782 6797 bf92d5 SetLastError 6779->6797 6781 bfc373 _unexpected 6 API calls 6780->6781 6781->6779 6783 bf99d5 6782->6783 6784 bf9da4 _unexpected 14 API calls 6783->6784 6783->6797 6785 bf99e5 6784->6785 6786 bf99ed 6785->6786 6787 bf9a02 6785->6787 6788 bfc3b2 _unexpected 6 API calls 6786->6788 6789 bfc3b2 _unexpected 6 API calls 6787->6789 6790 bf99f9 6788->6790 6791 bf9a0e 6789->6791 6794 bf9e01 ___free_lconv_mon 14 API calls 6790->6794 6792 bf9a12 6791->6792 6793 bf9a21 6791->6793 6795 bfc3b2 _unexpected 6 API calls 6792->6795 6796 bf95ce _unexpected 14 API calls 6793->6796 6794->6797 6795->6790 6798 bf9a2c 6796->6798 6797->6757 6799 bf9e01 ___free_lconv_mon 14 API calls 6798->6799 6799->6797 6801 bf9ad0 _unexpected 6800->6801 6802 bf9afc IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 6801->6802 6805 bf9bcd _unexpected 6802->6805 6804 bf9beb GetCurrentProcess TerminateProcess 6804->6764 6806 bf5a25 6805->6806 6807 bf5a2e IsProcessorFeaturePresent 6806->6807 6808 bf5a2d 6806->6808 6810 bf5a70 6807->6810 6808->6804 6813 bf5a33 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 6810->6813 6812 bf5b53 6812->6804 6813->6812 8521 bf6f0a 8522 bf5a25 CatchGuardHandler 5 API calls 8521->8522 8523 bf6f1c CatchGuardHandler 8522->8523 8205 c00277 8206 c00280 8205->8206 8207 c006f8 __startOneArgErrorHandling 20 API calls 8206->8207 8208 c002a0 8207->8208 8524 bf9f05 8525 bf9f2f 8524->8525 8526 bf9f13 8524->8526 8528 bf9f36 8525->8528 8529 bf9f52 8525->8529 8527 bfa5a5 14 API calls 8526->8527 8533 bf9f1d 8527->8533 8528->8533 8547 bfa5bf 8528->8547 8530 bfb2b9 _unexpected WideCharToMultiByte 8529->8530 8532 bf9f62 8530->8532 8534 bf9f7f 8532->8534 8535 bf9f69 GetLastError 8532->8535 8537 bf9f90 8534->8537 8539 bfa5bf 15 API calls 8534->8539 8536 bf9d37 __dosmaperr 14 API calls 8535->8536 8538 bf9f75 8536->8538 8537->8533 8540 bfa542 WideCharToMultiByte 8537->8540 8541 bf9d91 __dosmaperr 14 API calls 8538->8541 8539->8537 8542 bf9fa6 8540->8542 8541->8533 8542->8533 8543 bf9faa GetLastError 8542->8543 8544 bf9d37 __dosmaperr 14 API calls 8543->8544 8545 bf9fb6 8544->8545 8546 bf9d91 __dosmaperr 14 API calls 8545->8546 8546->8533 8548 bfa5a5 14 API calls 8547->8548 8549 bfa5cd 8548->8549 8550 bfa63a 15 API calls 8549->8550 8551 bfa5db 8550->8551 8551->8533 8447 bfb3fc 8449 bfb407 8447->8449 8448 bfc3f4 6 API calls 8448->8449 8449->8448 8450 bfb430 8449->8450 8451 bfb42c 8449->8451 8453 bfb454 8450->8453 8454 bfb480 8453->8454 8455 bfb461 8453->8455 8454->8451 8456 bfb46b DeleteCriticalSection 8455->8456 8456->8454 8456->8456 6569 bf8a7b 6572 bf88af 6569->6572 6573 bf88ee 6572->6573 6574 bf88dc 6572->6574 6584 bf875f 6573->6584 6599 bf56fa GetModuleHandleW 6574->6599 6579 bf892b 6582 bf8940 6585 bf876b __FrameHandler3::FrameUnwindToState 6584->6585 6607 bfb43d EnterCriticalSection 6585->6607 6587 bf8775 6608 bf87c7 6587->6608 6589 bf8782 6612 bf87a0 6589->6612 6592 bf8946 6691 bf8977 6592->6691 6594 bf8950 6595 bf8964 6594->6595 6596 bf8954 GetCurrentProcess TerminateProcess 6594->6596 6597 bf8990 _unexpected 3 API calls 6595->6597 6596->6595 6598 bf896c ExitProcess 6597->6598 6600 bf5706 6599->6600 6600->6573 6601 bf8990 GetModuleHandleExW 6600->6601 6602 bf89cf GetProcAddress 6601->6602 6603 bf89f0 6601->6603 6602->6603 6604 bf89e3 6602->6604 6605 bf88ed 6603->6605 6606 bf89f6 FreeLibrary 6603->6606 6604->6603 6605->6573 6606->6605 6607->6587 6610 bf87d3 __FrameHandler3::FrameUnwindToState _unexpected 6608->6610 6609 bf8837 _unexpected 6609->6589 6610->6609 6615 bf8eb4 6610->6615 6690 bfb485 LeaveCriticalSection 6612->6690 6614 bf878e 6614->6579 6614->6592 6616 bf8ec0 __EH_prolog3 6615->6616 6619 bf8c0c 6616->6619 6618 bf8ee7 _unexpected 6618->6609 6620 bf8c18 __FrameHandler3::FrameUnwindToState 6619->6620 6627 bfb43d EnterCriticalSection 6620->6627 6622 bf8c26 6628 bf8dc4 6622->6628 6627->6622 6629 bf8de3 6628->6629 6630 bf8c33 6628->6630 6629->6630 6635 bf9e01 6629->6635 6632 bf8c5b 6630->6632 6689 bfb485 LeaveCriticalSection 6632->6689 6634 bf8c44 6634->6618 6636 bf9e0c HeapFree 6635->6636 6637 bf9e36 6635->6637 6636->6637 6638 bf9e21 GetLastError 6636->6638 6637->6630 6639 bf9e2e __dosmaperr 6638->6639 6641 bf9d91 6639->6641 6644 bf98f1 GetLastError 6641->6644 6643 bf9d96 6643->6637 6645 bf9907 6644->6645 6646 bf990d 6644->6646 6667 bfc373 6645->6667 6665 bf9911 SetLastError 6646->6665 6672 bfc3b2 6646->6672 6653 bf9957 6656 bfc3b2 _unexpected 6 API calls 6653->6656 6654 bf9946 6655 bfc3b2 _unexpected 6 API calls 6654->6655 6664 bf9954 6655->6664 6657 bf9963 6656->6657 6658 bf997e 6657->6658 6659 bf9967 6657->6659 6684 bf95ce 6658->6684 6661 bfc3b2 _unexpected 6 API calls 6659->6661 6661->6664 6662 bf9e01 ___free_lconv_mon 12 API calls 6662->6665 6664->6662 6665->6643 6666 bf9e01 ___free_lconv_mon 12 API calls 6666->6665 6668 bfc211 _unexpected 5 API calls 6667->6668 6669 bfc38f 6668->6669 6670 bfc3aa TlsGetValue 6669->6670 6671 bfc398 6669->6671 6671->6646 6673 bfc211 _unexpected 5 API calls 6672->6673 6674 bfc3ce 6673->6674 6675 bfc3ec TlsSetValue 6674->6675 6676 bf9929 6674->6676 6676->6665 6677 bf9da4 6676->6677 6678 bf9db1 _unexpected 6677->6678 6679 bf9df1 6678->6679 6680 bf9ddc HeapAlloc 6678->6680 6683 bfc647 _unexpected EnterCriticalSection LeaveCriticalSection 6678->6683 6682 bf9d91 __dosmaperr 13 API calls 6679->6682 6680->6678 6681 bf993e 6680->6681 6681->6653 6681->6654 6682->6681 6683->6678 6685 bf9462 _unexpected EnterCriticalSection LeaveCriticalSection 6684->6685 6686 bf963c 6685->6686 6687 bf9574 _unexpected 14 API calls 6686->6687 6688 bf9665 6687->6688 6688->6666 6689->6634 6690->6614 6694 bfb4c1 6691->6694 6693 bf897c _unexpected 6693->6594 6695 bfb4d0 _unexpected 6694->6695 6696 bfb4dd 6695->6696 6698 bfc296 6695->6698 6696->6693 6701 bfc211 6698->6701 6702 bfc241 6701->6702 6706 bfc23d 6701->6706 6702->6706 6708 bfc146 6702->6708 6705 bfc25b GetProcAddress 6705->6706 6707 bfc26b _unexpected 6705->6707 6706->6696 6707->6706 6714 bfc157 ___vcrt_FlsFree 6708->6714 6709 bfc1ed 6709->6705 6709->6706 6710 bfc175 LoadLibraryExW 6711 bfc1f4 6710->6711 6712 bfc190 GetLastError 6710->6712 6711->6709 6713 bfc206 FreeLibrary 6711->6713 6712->6714 6713->6709 6714->6709 6714->6710 6715 bfc1c3 LoadLibraryExW 6714->6715 6715->6711 6715->6714 7494 bf547b 7497 bf544e 7494->7497 7498 bf545d 7497->7498 7499 bf5464 7497->7499 7503 bf8e9e 7498->7503 7506 bf8f1b 7499->7506 7502 bf5462 7504 bf8f1b 32 API calls 7503->7504 7505 bf8eb0 7504->7505 7505->7502 7509 bf8c67 7506->7509 7510 bf8c73 __FrameHandler3::FrameUnwindToState 7509->7510 7517 bfb43d EnterCriticalSection 7510->7517 7512 bf8c81 7518 bf8cc2 7512->7518 7514 bf8c8e 7528 bf8cb6 7514->7528 7517->7512 7519 bf8cdd 7518->7519 7520 bf8d50 _unexpected 7518->7520 7519->7520 7521 bf8d30 7519->7521 7531 bfc517 7519->7531 7520->7514 7521->7520 7523 bfc517 32 API calls 7521->7523 7524 bf8d46 7523->7524 7526 bf9e01 ___free_lconv_mon 14 API calls 7524->7526 7525 bf8d26 7527 bf9e01 ___free_lconv_mon 14 API calls 7525->7527 7526->7520 7527->7521 7580 bfb485 LeaveCriticalSection 7528->7580 7530 bf8c9f 7530->7502 7532 bfc53f 7531->7532 7533 bfc524 7531->7533 7535 bfc54e 7532->7535 7540 bfddc6 7532->7540 7533->7532 7534 bfc530 7533->7534 7536 bf9d91 __dosmaperr 14 API calls 7534->7536 7547 bfddf9 7535->7547 7539 bfc535 _unexpected 7536->7539 7539->7525 7541 bfdde6 HeapSize 7540->7541 7542 bfddd1 7540->7542 7541->7535 7543 bf9d91 __dosmaperr 14 API calls 7542->7543 7544 bfddd6 7543->7544 7545 bf9cb0 ___std_exception_copy 29 API calls 7544->7545 7546 bfdde1 7545->7546 7546->7535 7548 bfde06 7547->7548 7549 bfde11 7547->7549 7559 bfbbef 7548->7559 7550 bfde19 7549->7550 7557 bfde22 _unexpected 7549->7557 7552 bf9e01 ___free_lconv_mon 14 API calls 7550->7552 7555 bfde0e 7552->7555 7553 bfde4c HeapReAlloc 7553->7555 7553->7557 7554 bfde27 7556 bf9d91 __dosmaperr 14 API calls 7554->7556 7555->7539 7556->7555 7557->7553 7557->7554 7566 bfc647 7557->7566 7560 bfbc2d 7559->7560 7564 bfbbfd _unexpected 7559->7564 7562 bf9d91 __dosmaperr 14 API calls 7560->7562 7561 bfbc18 HeapAlloc 7563 bfbc2b 7561->7563 7561->7564 7562->7563 7563->7555 7564->7560 7564->7561 7565 bfc647 _unexpected 2 API calls 7564->7565 7565->7564 7569 bfc673 7566->7569 7570 bfc67f __FrameHandler3::FrameUnwindToState 7569->7570 7575 bfb43d EnterCriticalSection 7570->7575 7572 bfc68a _unexpected 7576 bfc6c1 7572->7576 7575->7572 7579 bfb485 LeaveCriticalSection 7576->7579 7578 bfc652 7578->7557 7579->7578 7580->7530 6814 bf68f7 6815 bf6901 6814->6815 6817 bf690e 6814->6817 6815->6817 6818 bf9127 6815->6818 6819 bf9e01 ___free_lconv_mon 14 API calls 6818->6819 6820 bf913f 6819->6820 6820->6817 8126 bfc2f5 8127 bfc211 _unexpected 5 API calls 8126->8127 8128 bfc311 8127->8128 8129 bfc329 TlsAlloc 8128->8129 8130 bfc31a 8128->8130 8129->8130 8131 bf66f1 8132 bf6715 8131->8132 8133 bf6703 8131->8133 8135 bf6913 _unexpected 78 API calls 8132->8135 8133->8132 8134 bf670b 8133->8134 8136 bf6713 8134->8136 8138 bf6913 _unexpected 78 API calls 8134->8138 8137 bf671a 8135->8137 8137->8136 8139 bf6913 _unexpected 78 API calls 8137->8139 8140 bf6733 8138->8140 8139->8136 8141 bf6913 _unexpected 78 API calls 8140->8141 8142 bf673e 8141->8142 8143 bf90eb _unexpected 68 API calls 8142->8143 8144 bf6746 8143->8144 8145 bf52ee 8146 bf52fe 8145->8146 8147 bf52fa 8145->8147 8148 bf530b ___scrt_release_startup_lock 8146->8148 8151 bf55a9 IsProcessorFeaturePresent 8146->8151 8150 bf5374 __FrameHandler3::FrameUnwindToState 8152 bf55bf _unexpected 8151->8152 8153 bf566a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 8152->8153 8154 bf56b5 _unexpected 8153->8154 8154->8150 8552 bf8b6e 8553 bf97a0 _unexpected 68 API calls 8552->8553 8554 bf8b79 8553->8554 8555 bf8bb1 8554->8555 8556 bf9d91 __dosmaperr 14 API calls 8554->8556 8557 bf8ba6 8556->8557 8558 bf9cb0 ___std_exception_copy 29 API calls 8557->8558 8558->8555 8209 bf9667 8210 bf9682 8209->8210 8211 bf9672 8209->8211 8215 bf9688 8211->8215 8214 bf9e01 ___free_lconv_mon 14 API calls 8214->8210 8216 bf969d 8215->8216 8217 bf96a3 8215->8217 8218 bf9e01 ___free_lconv_mon 14 API calls 8216->8218 8219 bf9e01 ___free_lconv_mon 14 API calls 8217->8219 8218->8217 8220 bf96af 8219->8220 8221 bf9e01 ___free_lconv_mon 14 API calls 8220->8221 8222 bf96ba 8221->8222 8223 bf9e01 ___free_lconv_mon 14 API calls 8222->8223 8224 bf96c5 8223->8224 8225 bf9e01 ___free_lconv_mon 14 API calls 8224->8225 8226 bf96d0 8225->8226 8227 bf9e01 ___free_lconv_mon 14 API calls 8226->8227 8228 bf96db 8227->8228 8229 bf9e01 ___free_lconv_mon 14 API calls 8228->8229 8230 bf96e6 8229->8230 8231 bf9e01 ___free_lconv_mon 14 API calls 8230->8231 8232 bf96f1 8231->8232 8233 bf9e01 ___free_lconv_mon 14 API calls 8232->8233 8234 bf96fc 8233->8234 8235 bf9e01 ___free_lconv_mon 14 API calls 8234->8235 8236 bf970a 8235->8236 8241 bf94b4 8236->8241 8242 bf94c0 __FrameHandler3::FrameUnwindToState 8241->8242 8257 bfb43d EnterCriticalSection 8242->8257 8244 bf94f4 8258 bf9513 8244->8258 8247 bf94ca 8247->8244 8248 bf9e01 ___free_lconv_mon 14 API calls 8247->8248 8248->8244 8249 bf951f 8250 bf952b __FrameHandler3::FrameUnwindToState 8249->8250 8262 bfb43d EnterCriticalSection 8250->8262 8252 bf9535 8263 bf9755 8252->8263 8254 bf9548 8267 bf9568 8254->8267 8257->8247 8261 bfb485 LeaveCriticalSection 8258->8261 8260 bf9501 8260->8249 8261->8260 8262->8252 8264 bf978b _unexpected 8263->8264 8265 bf9764 _unexpected 8263->8265 8264->8254 8265->8264 8270 bfbddb 8265->8270 8384 bfb485 LeaveCriticalSection 8267->8384 8269 bf9556 8269->8214 8271 bfbe5b 8270->8271 8274 bfbdf1 8270->8274 8272 bfbea9 8271->8272 8275 bf9e01 ___free_lconv_mon 14 API calls 8271->8275 8338 bfbf4c 8272->8338 8274->8271 8276 bfbe24 8274->8276 8281 bf9e01 ___free_lconv_mon 14 API calls 8274->8281 8277 bfbe7d 8275->8277 8278 bfbe46 8276->8278 8286 bf9e01 ___free_lconv_mon 14 API calls 8276->8286 8279 bf9e01 ___free_lconv_mon 14 API calls 8277->8279 8280 bf9e01 ___free_lconv_mon 14 API calls 8278->8280 8282 bfbe90 8279->8282 8283 bfbe50 8280->8283 8285 bfbe19 8281->8285 8287 bf9e01 ___free_lconv_mon 14 API calls 8282->8287 8288 bf9e01 ___free_lconv_mon 14 API calls 8283->8288 8284 bfbf17 8289 bf9e01 ___free_lconv_mon 14 API calls 8284->8289 8298 bfb97f 8285->8298 8291 bfbe3b 8286->8291 8292 bfbe9e 8287->8292 8288->8271 8293 bfbf1d 8289->8293 8326 bfba7d 8291->8326 8296 bf9e01 ___free_lconv_mon 14 API calls 8292->8296 8293->8264 8294 bfbeb7 8294->8284 8297 bf9e01 14 API calls ___free_lconv_mon 8294->8297 8296->8272 8297->8294 8299 bfb990 8298->8299 8325 bfba79 8298->8325 8300 bf9e01 ___free_lconv_mon 14 API calls 8299->8300 8302 bfb9a1 8299->8302 8300->8302 8301 bf9e01 ___free_lconv_mon 14 API calls 8303 bfb9b3 8301->8303 8302->8301 8302->8303 8304 bf9e01 ___free_lconv_mon 14 API calls 8303->8304 8306 bfb9c5 8303->8306 8304->8306 8305 bfb9d7 8308 bfb9e9 8305->8308 8310 bf9e01 ___free_lconv_mon 14 API calls 8305->8310 8306->8305 8307 bf9e01 ___free_lconv_mon 14 API calls 8306->8307 8307->8305 8309 bfb9fb 8308->8309 8311 bf9e01 ___free_lconv_mon 14 API calls 8308->8311 8312 bfba0d 8309->8312 8313 bf9e01 ___free_lconv_mon 14 API calls 8309->8313 8310->8308 8311->8309 8314 bfba1f 8312->8314 8315 bf9e01 ___free_lconv_mon 14 API calls 8312->8315 8313->8312 8316 bfba31 8314->8316 8318 bf9e01 ___free_lconv_mon 14 API calls 8314->8318 8315->8314 8317 bfba43 8316->8317 8319 bf9e01 ___free_lconv_mon 14 API calls 8316->8319 8320 bfba55 8317->8320 8321 bf9e01 ___free_lconv_mon 14 API calls 8317->8321 8318->8316 8319->8317 8322 bfba67 8320->8322 8323 bf9e01 ___free_lconv_mon 14 API calls 8320->8323 8321->8320 8324 bf9e01 ___free_lconv_mon 14 API calls 8322->8324 8322->8325 8323->8322 8324->8325 8325->8276 8327 bfba8a 8326->8327 8337 bfbae2 8326->8337 8328 bfba9a 8327->8328 8329 bf9e01 ___free_lconv_mon 14 API calls 8327->8329 8330 bf9e01 ___free_lconv_mon 14 API calls 8328->8330 8331 bfbaac 8328->8331 8329->8328 8330->8331 8332 bf9e01 ___free_lconv_mon 14 API calls 8331->8332 8333 bfbabe 8331->8333 8332->8333 8334 bfbad0 8333->8334 8335 bf9e01 ___free_lconv_mon 14 API calls 8333->8335 8336 bf9e01 ___free_lconv_mon 14 API calls 8334->8336 8334->8337 8335->8334 8336->8337 8337->8278 8339 bfbf78 8338->8339 8340 bfbf59 8338->8340 8339->8294 8340->8339 8344 bfbb0b 8340->8344 8343 bf9e01 ___free_lconv_mon 14 API calls 8343->8339 8345 bfbbe9 8344->8345 8346 bfbb1c 8344->8346 8345->8343 8380 bfbae6 8346->8380 8349 bfbae6 _unexpected 14 API calls 8350 bfbb2f 8349->8350 8351 bfbae6 _unexpected 14 API calls 8350->8351 8352 bfbb3a 8351->8352 8353 bfbae6 _unexpected 14 API calls 8352->8353 8354 bfbb45 8353->8354 8355 bfbae6 _unexpected 14 API calls 8354->8355 8356 bfbb53 8355->8356 8357 bf9e01 ___free_lconv_mon 14 API calls 8356->8357 8358 bfbb5e 8357->8358 8359 bf9e01 ___free_lconv_mon 14 API calls 8358->8359 8360 bfbb69 8359->8360 8361 bf9e01 ___free_lconv_mon 14 API calls 8360->8361 8362 bfbb74 8361->8362 8363 bfbae6 _unexpected 14 API calls 8362->8363 8364 bfbb82 8363->8364 8365 bfbae6 _unexpected 14 API calls 8364->8365 8366 bfbb90 8365->8366 8367 bfbae6 _unexpected 14 API calls 8366->8367 8368 bfbba1 8367->8368 8369 bfbae6 _unexpected 14 API calls 8368->8369 8370 bfbbaf 8369->8370 8371 bfbae6 _unexpected 14 API calls 8370->8371 8372 bfbbbd 8371->8372 8373 bf9e01 ___free_lconv_mon 14 API calls 8372->8373 8374 bfbbc8 8373->8374 8375 bf9e01 ___free_lconv_mon 14 API calls 8374->8375 8376 bfbbd3 8375->8376 8377 bf9e01 ___free_lconv_mon 14 API calls 8376->8377 8378 bfbbde 8377->8378 8379 bf9e01 ___free_lconv_mon 14 API calls 8378->8379 8379->8345 8383 bfbaf8 8380->8383 8381 bfbb07 8381->8349 8382 bf9e01 ___free_lconv_mon 14 API calls 8382->8383 8383->8381 8383->8382 8384->8269 8059 bfb563 8060 bfb592 8059->8060 8061 bfb570 8059->8061 8062 bfb57e DeleteCriticalSection 8061->8062 8063 bfb58c 8061->8063 8062->8062 8062->8063 8064 bf9e01 ___free_lconv_mon 14 API calls 8063->8064 8064->8060 6821 bfc4e1 6822 bfc512 6821->6822 6824 bfc4ec 6821->6824 6823 bfc4fc FreeLibrary 6823->6824 6824->6822 6824->6823 8559 bfb35c GetEnvironmentStringsW 8560 bfb374 8559->8560 8573 bfb3f7 8559->8573 8561 bfb2b9 _unexpected WideCharToMultiByte 8560->8561 8562 bfb391 8561->8562 8563 bfb39b FreeEnvironmentStringsW 8562->8563 8564 bfb3a6 8562->8564 8563->8573 8565 bfbbef 15 API calls 8564->8565 8566 bfb3ad 8565->8566 8567 bfb3c6 8566->8567 8568 bfb3b5 8566->8568 8570 bfb2b9 _unexpected WideCharToMultiByte 8567->8570 8569 bf9e01 ___free_lconv_mon 14 API calls 8568->8569 8571 bfb3ba FreeEnvironmentStringsW 8569->8571 8572 bfb3d6 8570->8572 8571->8573 8574 bfb3dd 8572->8574 8575 bfb3e5 8572->8575 8577 bf9e01 ___free_lconv_mon 14 API calls 8574->8577 8576 bf9e01 ___free_lconv_mon 14 API calls 8575->8576 8578 bfb3e3 FreeEnvironmentStringsW 8576->8578 8577->8578 8578->8573 6716 bf4e5a GetProcessHeap RtlAllocateHeap 6717 bf4e84 _unexpected 6716->6717 6718 bf4f3b 6716->6718 6719 bf4e94 GetModuleFileNameW 6717->6719 6720 bf4f11 GetProcessHeap RtlFreeHeap 6719->6720 6723 bf4eaf _wcsrchr 6719->6723 6720->6718 6721 bf4f27 MulDiv 6720->6721 6721->6718 6722 bf4edb lstrlenW 6724 bf4eea 6722->6724 6723->6720 6723->6722 6724->6720 6825 c004a7 6826 c004c0 __startOneArgErrorHandling 6825->6826 6827 c00511 __startOneArgErrorHandling 6826->6827 6829 c00850 6826->6829 6830 c00889 __startOneArgErrorHandling 6829->6830 6832 c008b0 __startOneArgErrorHandling 6830->6832 6840 c00bc1 6830->6840 6833 c008f3 6832->6833 6834 c008ce 6832->6834 6852 c00eb2 6833->6852 6844 c00ee3 6834->6844 6837 c008ee __startOneArgErrorHandling 6838 bf5a25 CatchGuardHandler 5 API calls 6837->6838 6839 c00917 6838->6839 6839->6827 6841 c00bec __raise_exc 6840->6841 6842 c00de5 RaiseException 6841->6842 6843 c00dfd 6842->6843 6843->6832 6845 c00ef0 6844->6845 6846 c00eff __startOneArgErrorHandling 6845->6846 6848 c00f2e __startOneArgErrorHandling 6845->6848 6847 c00eb2 __startOneArgErrorHandling 14 API calls 6846->6847 6849 c00f18 6847->6849 6850 c00f7c 6848->6850 6851 c00eb2 __startOneArgErrorHandling 14 API calls 6848->6851 6849->6837 6850->6837 6851->6850 6853 c00ed6 6852->6853 6855 c00ebf 6852->6855 6854 bf9d91 __dosmaperr 14 API calls 6853->6854 6856 c00edb 6854->6856 6855->6856 6857 bf9d91 __dosmaperr 14 API calls 6855->6857 6856->6837 6858 c00ece 6857->6858 6858->6837 8385 bf8a55 8386 bf8a6b __FrameHandler3::FrameUnwindToState _unexpected 8385->8386 8387 bf97a0 _unexpected 68 API calls 8386->8387 8390 bf90fc 8387->8390 8388 bf91a7 __FrameHandler3::FrameUnwindToState 68 API calls 8389 bf9126 8388->8389 8390->8388 7984 bf79d4 7987 bf7f27 7984->7987 7986 bf79e9 7988 bf7f3b 7987->7988 7989 bf7f34 7987->7989 7988->7986 7990 bf9127 ___vcrt_freefls@4 14 API calls 7989->7990 7990->7988 7991 bff9d0 7994 bff9ee 7991->7994 7993 bff9e6 7998 bff9f3 7994->7998 7995 bffa88 7995->7993 7998->7995 7999 c002b3 7998->7999 8000 c002c6 DecodePointer 7999->8000 8001 c002d6 7999->8001 8000->8001 8002 c0031a 8001->8002 8003 c00305 8001->8003 8004 bffc1f 8001->8004 8002->8004 8006 bf9d91 __dosmaperr 14 API calls 8002->8006 8003->8004 8005 bf9d91 __dosmaperr 14 API calls 8003->8005 8004->7993 8005->8004 8006->8004 8464 bf63d0 8465 bf63ee __InternalCxxFrameHandler 8464->8465 8476 bf6390 8465->8476 8477 bf63af 8476->8477 8478 bf63a2 8476->8478 8479 bf5a25 CatchGuardHandler 5 API calls 8478->8479 8479->8477 8391 bf664e 8392 bf6687 8391->8392 8393 bf6657 8391->8393 8393->8392 8394 bf6913 _unexpected 78 API calls 8393->8394 8395 bf6692 8394->8395 8396 bf6913 _unexpected 78 API calls 8395->8396 8397 bf669d 8396->8397 8398 bf90eb _unexpected 68 API calls 8397->8398 8399 bf66a5 8398->8399 7581 bff04d 7582 bff060 _unexpected 7581->7582 7585 bfef28 7582->7585 7584 bff06c _unexpected 7586 bfef34 __FrameHandler3::FrameUnwindToState 7585->7586 7587 bfef3e 7586->7587 7588 bfef61 7586->7588 7589 bf9c33 ___std_exception_copy 29 API calls 7587->7589 7590 bfef59 7588->7590 7596 bfcd97 EnterCriticalSection 7588->7596 7589->7590 7590->7584 7592 bfef7f 7597 bfefbf 7592->7597 7594 bfef8c 7611 bfefb7 7594->7611 7596->7592 7598 bfefef 7597->7598 7599 bfefcc 7597->7599 7601 bfefe7 7598->7601 7602 bfcbac _unexpected 68 API calls 7598->7602 7600 bf9c33 ___std_exception_copy 29 API calls 7599->7600 7600->7601 7601->7594 7603 bff007 7602->7603 7614 bfeafb 7603->7614 7606 bfd3f4 _unexpected 29 API calls 7607 bff01b 7606->7607 7618 bff83c 7607->7618 7610 bf9e01 ___free_lconv_mon 14 API calls 7610->7601 7660 bfcdab LeaveCriticalSection 7611->7660 7613 bfefbd 7613->7590 7615 bfeb24 7614->7615 7616 bfeb12 7614->7616 7615->7606 7616->7615 7617 bf9e01 ___free_lconv_mon 14 API calls 7616->7617 7617->7615 7619 bff865 7618->7619 7622 bff022 7618->7622 7620 bff8b4 7619->7620 7623 bff88c 7619->7623 7621 bf9c33 ___std_exception_copy 29 API calls 7620->7621 7621->7622 7622->7601 7622->7610 7625 bff7ab 7623->7625 7626 bff7b7 __FrameHandler3::FrameUnwindToState 7625->7626 7633 bfb636 EnterCriticalSection 7626->7633 7628 bff7c5 7629 bff7f6 7628->7629 7634 bff8df 7628->7634 7647 bff830 7629->7647 7633->7628 7635 bfb70d _unexpected 29 API calls 7634->7635 7638 bff8ef 7635->7638 7636 bff8f5 7650 bfb67c 7636->7650 7638->7636 7640 bfb70d _unexpected 29 API calls 7638->7640 7646 bff927 7638->7646 7639 bfb70d _unexpected 29 API calls 7641 bff933 CloseHandle 7639->7641 7642 bff91e 7640->7642 7641->7636 7644 bff93f GetLastError 7641->7644 7643 bfb70d _unexpected 29 API calls 7642->7643 7643->7646 7644->7636 7645 bff94d _unexpected 7645->7629 7646->7636 7646->7639 7659 bfb659 LeaveCriticalSection 7647->7659 7649 bff819 7649->7622 7651 bfb68b 7650->7651 7652 bfb6f2 7650->7652 7651->7652 7658 bfb6b5 7651->7658 7653 bf9d91 __dosmaperr 14 API calls 7652->7653 7654 bfb6f7 7653->7654 7655 bf9d7e __dosmaperr 14 API calls 7654->7655 7656 bfb6e2 7655->7656 7656->7645 7657 bfb6dc SetStdHandle 7657->7656 7658->7656 7658->7657 7659->7649 7660->7613 8480 bf9fcb 8483 bf9e53 8480->8483 8484 bf9e7b 8483->8484 8485 bf9e61 8483->8485 8487 bf9e82 8484->8487 8488 bf9ea1 8484->8488 8501 bfa5a5 8485->8501 8492 bf9e6b 8487->8492 8505 bfa5fb 8487->8505 8489 bfb1ff _unexpected MultiByteToWideChar 8488->8489 8491 bf9eb0 8489->8491 8493 bf9eb7 GetLastError 8491->8493 8494 bf9edd 8491->8494 8496 bfa5fb 15 API calls 8491->8496 8495 bf9d37 __dosmaperr 14 API calls 8493->8495 8494->8492 8497 bfb1ff _unexpected MultiByteToWideChar 8494->8497 8498 bf9ec3 8495->8498 8496->8494 8499 bf9ef4 8497->8499 8500 bf9d91 __dosmaperr 14 API calls 8498->8500 8499->8492 8499->8493 8500->8492 8502 bfa5b0 8501->8502 8504 bfa5b8 8501->8504 8503 bf9e01 ___free_lconv_mon 14 API calls 8502->8503 8503->8504 8504->8492 8506 bfa5a5 14 API calls 8505->8506 8507 bfa609 8506->8507 8510 bfa63a 8507->8510 8511 bfbbef 15 API calls 8510->8511 8512 bfa61a 8511->8512 8512->8492 8580 bf5748 8581 bf577f 8580->8581 8583 bf575a 8580->8583 8583->8581 8589 bf6747 8583->8589 8587 bf90eb _unexpected 68 API calls 8588 bf579d 8587->8588 8590 bf6913 _unexpected 78 API calls 8589->8590 8591 bf578c 8590->8591 8592 bf6750 8591->8592 8593 bf6913 _unexpected 78 API calls 8592->8593 8594 bf5796 8593->8594 8594->8587 8595 bf8b47 8598 bf8ace 8595->8598 8599 bf8ada __FrameHandler3::FrameUnwindToState 8598->8599 8606 bfb43d EnterCriticalSection 8599->8606 8601 bf8b12 8611 bf8b30 8601->8611 8603 bf8ae4 8603->8601 8607 bfc0a8 8603->8607 8606->8603 8608 bfc0b6 _unexpected 8607->8608 8609 bfc0c3 8607->8609 8608->8609 8610 bfbddb _unexpected 14 API calls 8608->8610 8609->8603 8610->8609 8614 bfb485 LeaveCriticalSection 8611->8614 8613 bf8b1e 8614->8613 8007 bfd9c5 8008 bfd90e 8007->8008 8009 bfd928 8008->8009 8010 bfd93c 8008->8010 8014 bfd961 8008->8014 8009->8010 8011 bf9d91 __dosmaperr 14 API calls 8009->8011 8012 bfd932 8011->8012 8013 bf9cb0 ___std_exception_copy 29 API calls 8012->8013 8013->8010 8014->8010 8015 bf9d91 __dosmaperr 14 API calls 8014->8015 8015->8012 8065 bf7945 8068 bf7978 8065->8068 8071 bf7ec4 8068->8071 8073 bf7ed1 ___std_exception_copy 8071->8073 8076 bf7953 8071->8076 8072 bf7efe 8075 bf9127 ___vcrt_freefls@4 14 API calls 8072->8075 8073->8072 8074 bf914d ___std_exception_copy 29 API calls 8073->8074 8073->8076 8074->8072 8075->8076 8155 bf56c4 8159 bf60e0 8155->8159 8158 bf56ea 8160 bf56d7 GetStartupInfoW 8159->8160 8160->8158 8513 bf7fc0 8514 bf98f1 __dosmaperr 14 API calls 8513->8514 8515 bf7fcd 8514->8515

                                                        Control-flow Graph

                                                        APIs
                                                        • GetProcessHeap.KERNEL32(00000000,3B9ACA00), ref: 00BF4E6D
                                                        • RtlAllocateHeap.NTDLL(00000000), ref: 00BF4E74
                                                        • GetModuleFileNameW.KERNEL32(00000000,?,00000104), ref: 00BF4EA5
                                                        • _wcsrchr.LIBVCRUNTIME ref: 00BF4EB8
                                                        • lstrlenW.KERNEL32(-00000002), ref: 00BF4EDD
                                                        • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00BF4F14
                                                        • RtlFreeHeap.NTDLL(00000000), ref: 00BF4F1B
                                                        • MulDiv.KERNEL32(00000001,80000000,80000000), ref: 00BF4F30
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: Heap$Process$AllocateFileFreeModuleName_wcsrchrlstrlen
                                                        • String ID: $($@
                                                        • API String ID: 443335681-2581157662
                                                        • Opcode ID: a58d88590377653aa617e7038d5911271eaf0dcdc21ead73f8a4e5a9e38095fb
                                                        • Instruction ID: bc45e270ef626542a26029bdc4a36a2e52f873360ceb36883193c9d165a0363e
                                                        • Opcode Fuzzy Hash: a58d88590377653aa617e7038d5911271eaf0dcdc21ead73f8a4e5a9e38095fb
                                                        • Instruction Fuzzy Hash: EE21C2769003096AE7345364AC8EBBF26E8EB4A361F214595FB0DD71D1EB648C48C561

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 26 bfc146-bfc152 27 bfc1e4-bfc1e7 26->27 28 bfc1ed 27->28 29 bfc157-bfc168 27->29 30 bfc1ef-bfc1f3 28->30 31 bfc16a-bfc16d 29->31 32 bfc175-bfc18e LoadLibraryExW 29->32 33 bfc20d-bfc20f 31->33 34 bfc173 31->34 35 bfc1f4-bfc204 32->35 36 bfc190-bfc199 GetLastError 32->36 33->30 38 bfc1e1 34->38 35->33 37 bfc206-bfc207 FreeLibrary 35->37 39 bfc19b-bfc1ad call bf9428 36->39 40 bfc1d2-bfc1df 36->40 37->33 38->27 39->40 43 bfc1af-bfc1c1 call bf9428 39->43 40->38 43->40 46 bfc1c3-bfc1d0 LoadLibraryExW 43->46 46->35 46->40
                                                        APIs
                                                        • FreeLibrary.KERNEL32(00000000,?,00BFC255,00BFCAD9,?,00000000,00000000,00000000,?,00BFC3CE,00000022,FlsSetValue,00C14078,00C14080,00000000), ref: 00BFC207
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: FreeLibrary
                                                        • String ID: api-ms-$ext-ms-
                                                        • API String ID: 3664257935-537541572
                                                        • Opcode ID: e9f440b67762e6ee740e36e9c07d9d46f473af497040aa9ba4ea4eee333ee502
                                                        • Instruction ID: 11cb78a43f41c74d66a365943b62a3ec64591f2575e2b5d923fca70d93ebcb35
                                                        • Opcode Fuzzy Hash: e9f440b67762e6ee740e36e9c07d9d46f473af497040aa9ba4ea4eee333ee502
                                                        • Instruction Fuzzy Hash: 1E210835A4111DABC7318B649D40BBE7BA9EB42360F204190EE15F7281D730EF64C6E0

                                                        Control-flow Graph

                                                        APIs
                                                        • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 00C02314
                                                          • Part of subcall function 00C02098: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C020C1
                                                          • Part of subcall function 00C02098: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C0226D
                                                        • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 00C02366
                                                        • VirtualProtect.KERNELBASE(0000002C,?,00000040,0000002C), ref: 00C023C0
                                                        • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C023F3
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: Virtual$Alloc$Free$Protect
                                                        • String ID: ,
                                                        • API String ID: 1004437363-3772416878
                                                        • Opcode ID: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                                        • Instruction ID: ba8363b6dc526faf5b2d633715e9e7ea9bd2cf7151a60412e9afea31d1211011
                                                        • Opcode Fuzzy Hash: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                                        • Instruction Fuzzy Hash: F051FC75900719AFCB10DFA9C885B9EBBF8FF08354F10851AF959A7280D370EA54CB94
                                                        APIs
                                                        • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 00C02314
                                                          • Part of subcall function 00C02098: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C020C1
                                                          • Part of subcall function 00C02098: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C0226D
                                                        • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 00C02366
                                                        • VirtualProtect.KERNELBASE(0000002C,?,00000040,0000002C), ref: 00C023C0
                                                        • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C023F3
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000003.1699532870.0000000000C02000.00000040.00000001.01000000.00000003.sdmp, Offset: 00C02000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_3_c02000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: Virtual$Alloc$Free$Protect
                                                        • String ID: ,
                                                        • API String ID: 1004437363-3772416878
                                                        • Opcode ID: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                                        • Instruction ID: ba8363b6dc526faf5b2d633715e9e7ea9bd2cf7151a60412e9afea31d1211011
                                                        • Opcode Fuzzy Hash: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                                                        • Instruction Fuzzy Hash: F051FC75900719AFCB10DFA9C885B9EBBF8FF08354F10851AF959A7280D370EA54CB94

                                                        Control-flow Graph

                                                        APIs
                                                        • GetCurrentProcess.KERNEL32(00BF8A50,?,00BF8940,00000000,?,?,00BF8A50,10008967,?,00BF8A50), ref: 00BF8957
                                                        • TerminateProcess.KERNEL32(00000000,?,00BF8940,00000000,?,?,00BF8A50,10008967,?,00BF8A50), ref: 00BF895E
                                                        • ExitProcess.KERNEL32 ref: 00BF8970
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: Process$CurrentExitTerminate
                                                        • String ID:
                                                        • API String ID: 1703294689-0
                                                        • Opcode ID: 12c1b877d6f5180eb95620a0112bfadeeedddc8d93afc5c187cde2e4b882c3e2
                                                        • Instruction ID: efb11d76537ed196c10b58f1f739b6dd4551cb5f8a60eef94772ed52ce5dd8d1
                                                        • Opcode Fuzzy Hash: 12c1b877d6f5180eb95620a0112bfadeeedddc8d93afc5c187cde2e4b882c3e2
                                                        • Instruction Fuzzy Hash: 87D06C35400208ABCF016FA0DC09BBE3F6AFA49385B549154BA099A022CFB199A6DA81

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 79 c02098-c020ca VirtualAlloc 80 c02270-c02274 79->80 81 c020d0-c020d4 79->81 82 c020dd-c020e4 81->82 83 c020f1-c020f8 82->83 84 c020e6-c020ef 82->84 86 c020fc-c0210e 83->86 84->82 87 c02110-c02116 86->87 88 c02133-c0213b 86->88 91 c02118 87->91 92 c0211d-c02130 87->92 89 c0219c-c021a2 88->89 90 c0213d-c02143 88->90 95 c021a4 89->95 96 c021a9-c021b0 89->96 93 c02145 90->93 94 c0214a-c02167 90->94 97 c02260-c0226d VirtualFree 91->97 92->88 93->97 98 c02169 94->98 99 c0216e-c02197 94->99 95->97 100 c021b2 96->100 101 c021b7-c021fa 96->101 97->80 98->97 102 c0225b 99->102 100->97 103 c02203-c02209 101->103 102->86 103->102 104 c0220b-c02238 103->104 105 c0223a 104->105 106 c0223c-c02259 104->106 105->102 106->103
                                                        APIs
                                                        • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C020C1
                                                        • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C0226D
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: Virtual$AllocFree
                                                        • String ID:
                                                        • API String ID: 2087232378-0
                                                        • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                                        • Instruction ID: 39f5a65c487c15d1ef884feb9f46b7cd3f14da3c98caf3fa0d4f6a7bac689b14
                                                        • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                                        • Instruction Fuzzy Hash: B1718A71E0424ADFDB41CF98C985BEEBBF0AF09324F244095E565FB281C234AA91DF64
                                                        APIs
                                                        • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 00C020C1
                                                        • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 00C0226D
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000003.1699532870.0000000000C02000.00000040.00000001.01000000.00000003.sdmp, Offset: 00C02000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_3_c02000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: Virtual$AllocFree
                                                        • String ID:
                                                        • API String ID: 2087232378-0
                                                        • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                                        • Instruction ID: 39f5a65c487c15d1ef884feb9f46b7cd3f14da3c98caf3fa0d4f6a7bac689b14
                                                        • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                                        • Instruction Fuzzy Hash: B1718A71E0424ADFDB41CF98C985BEEBBF0AF09324F244095E565FB281C234AA91DF64

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 108 bfc211-bfc23b 109 bfc23d-bfc23f 108->109 110 bfc241-bfc243 108->110 111 bfc292-bfc295 109->111 112 bfc249-bfc250 call bfc146 110->112 113 bfc245-bfc247 110->113 115 bfc255-bfc259 112->115 113->111 116 bfc25b-bfc269 GetProcAddress 115->116 117 bfc278-bfc28f 115->117 116->117 118 bfc26b-bfc276 call bf811b 116->118 119 bfc291 117->119 118->119 119->111
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID:
                                                        • API String ID:
                                                        • Opcode ID: 107e8cb87553c10f913c4d92b1f209a08dd915a92949b73b7541cd080c35e54f
                                                        • Instruction ID: e3eeefdba2be0afb56b3f3c94dc07bb64c915386bc973b8942adf2d67fdcb10b
                                                        • Opcode Fuzzy Hash: 107e8cb87553c10f913c4d92b1f209a08dd915a92949b73b7541cd080c35e54f
                                                        • Instruction Fuzzy Hash: C501FE3320021C5F9F168BE8ED80BBA3BE5FBCB3207208164FA0597154DA31D9899781
                                                        APIs
                                                        • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00BF55B5
                                                        • IsDebuggerPresent.KERNEL32 ref: 00BF5681
                                                        • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00BF56A1
                                                        • UnhandledExceptionFilter.KERNEL32(?), ref: 00BF56AB
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                        • String ID:
                                                        • API String ID: 254469556-0
                                                        • Opcode ID: 5e7a6f763c95f1301b82cc5229c4d304f1894ae510807ca736fa4426d46db95f
                                                        • Instruction ID: 604810c8c33888fa0473f68bff67cc1230e86a8c6d8574ca3cd0fe978d21c7a2
                                                        • Opcode Fuzzy Hash: 5e7a6f763c95f1301b82cc5229c4d304f1894ae510807ca736fa4426d46db95f
                                                        • Instruction Fuzzy Hash: E9310675D0521C9BDB20DFA4D989BCCBBF8BF08304F1041EAE509AB250EB719A89CF44
                                                        APIs
                                                        • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 00BF9BAC
                                                        • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 00BF9BB6
                                                        • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 00BF9BC3
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                        • String ID:
                                                        • API String ID: 3906539128-0
                                                        • Opcode ID: 91f37ba4390c2b904c41be6e31ca176993e6355394bdafca1f415d1b6984c81d
                                                        • Instruction ID: 92c577c18e17ec0881d99b7afb823da1486b3fefad645ccd18cc7818452dd6bf
                                                        • Opcode Fuzzy Hash: 91f37ba4390c2b904c41be6e31ca176993e6355394bdafca1f415d1b6984c81d
                                                        • Instruction Fuzzy Hash: FE31B27490122C9BCB21DF64D989BDCBBF8BF08310F5042EAE90CA7251E7709B858F54
                                                        APIs
                                                        • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00C00BBC,?,?,00000008,?,?,00C007BF,00000000), ref: 00C00DEE
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: ExceptionRaise
                                                        • String ID:
                                                        • API String ID: 3997070919-0
                                                        • Opcode ID: 15756a9b55189aabd8854b2dd2a111da937e970c684afa185eb67a452a53dfb3
                                                        • Instruction ID: bba21b783f504eb3d60dbbf8c1ee95706f18db1c9977da109b70f4ac39f63aa2
                                                        • Opcode Fuzzy Hash: 15756a9b55189aabd8854b2dd2a111da937e970c684afa185eb67a452a53dfb3
                                                        • Instruction Fuzzy Hash: B3B129316106089FD715CF28C48AB657BE0FF45365F2A8658E9EACF2E1C335EA91CB40
                                                        APIs
                                                        • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 00BF585B
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: FeaturePresentProcessor
                                                        • String ID:
                                                        • API String ID: 2325560087-0
                                                        • Opcode ID: 1bf9ad1123ca89b33f55aee0da921508b120460bb99cea9f3cea0245347b4b3b
                                                        • Instruction ID: 953cb461558c94f2edaa319d5d57dfda61fa8ba9480c365139e4fc909d285058
                                                        • Opcode Fuzzy Hash: 1bf9ad1123ca89b33f55aee0da921508b120460bb99cea9f3cea0245347b4b3b
                                                        • Instruction Fuzzy Hash: 35518B71A11A098BEB28CF59D8917BEBBF0FB49320F14C56AD645EB250D3B4D904CF50
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID:
                                                        • API String ID:
                                                        • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                                        • Instruction ID: 9833d8cff144a3ebb9fc2afb608cc995ed016f0630624c842418124262c83a66
                                                        • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                                        • Instruction Fuzzy Hash: 90F06D79A00200CFCB24CF8AC64CC95B7FAFB85730B6545A5E414DB2A1D3B0EE44DBA1
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000003.1699532870.0000000000C02000.00000040.00000001.01000000.00000003.sdmp, Offset: 00C02000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_3_c02000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID:
                                                        • API String ID:
                                                        • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                                        • Instruction ID: 9833d8cff144a3ebb9fc2afb608cc995ed016f0630624c842418124262c83a66
                                                        • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                                        • Instruction Fuzzy Hash: 90F06D79A00200CFCB24CF8AC64CC95B7FAFB85730B6545A5E414DB2A1D3B0EE44DBA1

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 160 bf72d1-bf72fc call bf7e99 163 bf7302-bf7305 160->163 164 bf7670-bf7675 call bf91a7 160->164 163->164 166 bf730b-bf7314 163->166 167 bf731a-bf731e 166->167 168 bf7411-bf7417 166->168 167->168 170 bf7324-bf732b 167->170 171 bf741f-bf742d 168->171 172 bf732d-bf7334 170->172 173 bf7343-bf7348 170->173 174 bf75d9-bf75dc 171->174 175 bf7433-bf7437 171->175 172->173 176 bf7336-bf733d 172->176 173->168 177 bf734e-bf7356 call bf6913 173->177 178 bf75ff-bf7608 call bf6913 174->178 179 bf75de-bf75e1 174->179 175->174 180 bf743d-bf7444 175->180 176->168 176->173 194 bf735c-bf7375 call bf6913 * 2 177->194 195 bf760a-bf760e 177->195 178->164 178->195 179->164 182 bf75e7-bf75fc call bf7676 179->182 183 bf745c-bf7462 180->183 184 bf7446-bf744d 180->184 182->178 189 bf7579-bf757d 183->189 190 bf7468-bf748f call bf6cc4 183->190 184->183 188 bf744f-bf7456 184->188 188->174 188->183 192 bf757f-bf7588 call bf65a0 189->192 193 bf7589-bf7595 189->193 190->189 206 bf7495-bf7498 190->206 192->193 193->178 199 bf7597-bf75a1 193->199 194->164 222 bf737b-bf7381 194->222 203 bf75af-bf75b1 199->203 204 bf75a3-bf75a5 199->204 208 bf75c8-bf75d5 call bf7d59 203->208 209 bf75b3-bf75c6 call bf6913 * 2 203->209 204->178 207 bf75a7-bf75ab 204->207 211 bf749b-bf74b0 206->211 207->178 215 bf75ad 207->215 224 bf75d7 208->224 225 bf7634-bf7649 call bf6913 * 2 208->225 234 bf760f call bf90eb 209->234 212 bf755a-bf756d 211->212 213 bf74b6-bf74b9 211->213 212->211 218 bf7573-bf7576 212->218 213->212 219 bf74bf-bf74c7 213->219 215->209 218->189 219->212 223 bf74cd-bf74e1 219->223 227 bf73ad-bf73b5 call bf6913 222->227 228 bf7383-bf7387 222->228 229 bf74e4-bf74f5 223->229 224->178 257 bf764e-bf766b call bf6eb7 call bf7c59 call bf7e16 call bf7bd0 225->257 258 bf764b 225->258 243 bf7419-bf741c 227->243 244 bf73b7-bf73d7 call bf6913 * 2 call bf7d59 227->244 228->227 233 bf7389-bf7390 228->233 237 bf751b-bf7528 229->237 238 bf74f7-bf7508 call bf77ac 229->238 235 bf73a4-bf73a7 233->235 236 bf7392-bf7399 233->236 252 bf7614-bf762f call bf65a0 call bf7960 call bf7f46 234->252 235->164 235->227 236->235 241 bf739b-bf73a2 236->241 237->229 246 bf752a 237->246 254 bf752c-bf7554 call bf7251 238->254 255 bf750a-bf7513 238->255 241->227 241->235 243->171 244->243 275 bf73d9-bf73de 244->275 251 bf7557 246->251 251->212 252->225 254->251 255->238 260 bf7515-bf7518 255->260 257->164 258->257 260->237 275->234 277 bf73e4-bf73f7 call bf79b5 275->277 277->252 281 bf73fd-bf7409 277->281 281->234 282 bf740f 281->282 282->277
                                                        APIs
                                                        • type_info::operator==.LIBVCRUNTIME ref: 00BF73F0
                                                        • ___TypeMatch.LIBVCRUNTIME ref: 00BF74FE
                                                        • CatchIt.LIBVCRUNTIME ref: 00BF754F
                                                        • _UnwindNestedFrames.LIBCMT ref: 00BF7650
                                                        • CallUnexpected.LIBVCRUNTIME ref: 00BF766B
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: CallCatchFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                        • String ID: csm$csm$csm
                                                        • API String ID: 4119006552-393685449
                                                        • Opcode ID: 596957527878c3668af5806d5f0ddcc3401df35dd7f47fb2b2bd3bab4ca589af
                                                        • Instruction ID: 05c815ad6089eb3bcc41975e90c264f88fb6acad465c8e4d1ef1ae9d91df4142
                                                        • Opcode Fuzzy Hash: 596957527878c3668af5806d5f0ddcc3401df35dd7f47fb2b2bd3bab4ca589af
                                                        • Instruction Fuzzy Hash: 48B15B7184820DEFCF25DFA8C8819BEBBF5EF14310B1445DAEA106B212DB71DA59CB91

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 283 bf63d0-bf6421 call c01400 call bf6390 call bf68c7 290 bf647d-bf6480 283->290 291 bf6423-bf6435 283->291 293 bf64a0-bf64a9 290->293 294 bf6482-bf648f call bf68b0 290->294 292 bf6437-bf644e 291->292 291->293 295 bf6464 292->295 296 bf6450-bf645e call bf6850 292->296 300 bf6494-bf649d call bf6390 294->300 299 bf6467-bf646c 295->299 305 bf6474-bf647b 296->305 306 bf6460 296->306 299->292 302 bf646e-bf6470 299->302 300->293 302->293 307 bf6472 302->307 305->300 308 bf64aa-bf64b3 306->308 309 bf6462 306->309 307->300 310 bf64ed-bf64fd call bf6890 308->310 311 bf64b5-bf64bc 308->311 309->299 316 bf64ff-bf650e call bf68b0 310->316 317 bf6511-bf652d call bf6390 call bf6870 310->317 311->310 312 bf64be-bf64cd call c011e0 311->312 321 bf64cf-bf64e7 312->321 322 bf64ea 312->322 316->317 321->322 322->310
                                                        APIs
                                                        • _ValidateLocalCookies.LIBCMT ref: 00BF6407
                                                        • ___except_validate_context_record.LIBVCRUNTIME ref: 00BF640F
                                                        • _ValidateLocalCookies.LIBCMT ref: 00BF6498
                                                        • __IsNonwritableInCurrentImage.LIBCMT ref: 00BF64C3
                                                        • _ValidateLocalCookies.LIBCMT ref: 00BF6518
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                        • String ID: csm
                                                        • API String ID: 1170836740-1018135373
                                                        • Opcode ID: d7d278ac92f848d559e7a28bab751b114390d63af01df46074e9655a7b3f37a6
                                                        • Instruction ID: 01fce61a104e62782c72f5725d46951112b2094fff88a3c1f2a2fa181934f86e
                                                        • Opcode Fuzzy Hash: d7d278ac92f848d559e7a28bab751b114390d63af01df46074e9655a7b3f37a6
                                                        • Instruction Fuzzy Hash: F8418734A0020D9BCF10EF68C885AAEBBF5FF45324F148199EE159B352D731EA59CB91

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 329 bf6921-bf6928 330 bf692d-bf6948 GetLastError call bf6c04 329->330 331 bf692a-bf692c 329->331 334 bf694a-bf694c 330->334 335 bf6961-bf6963 330->335 336 bf69a7-bf69b2 SetLastError 334->336 337 bf694e-bf695f call bf6c3f 334->337 335->336 337->335 340 bf6965-bf6975 call bf91eb 337->340 343 bf6989-bf6999 call bf6c3f 340->343 344 bf6977-bf6987 call bf6c3f 340->344 350 bf699f-bf69a6 call bf9127 343->350 344->343 349 bf699b-bf699d 344->349 349->350 350->336
                                                        APIs
                                                        • GetLastError.KERNEL32(?,?,00BF6918,00BF674C,00BF578C), ref: 00BF692F
                                                        • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 00BF693D
                                                        • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 00BF6956
                                                        • SetLastError.KERNEL32(00000000,00BF6918,00BF674C,00BF578C), ref: 00BF69A8
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: ErrorLastValue___vcrt_
                                                        • String ID:
                                                        • API String ID: 3852720340-0
                                                        • Opcode ID: 92c7e09074301d4b18fc7c5b8994e6dc2268ed5ef8c94d17356e2e6d55b92dee
                                                        • Instruction ID: a67ccecc08487247e2bac680649586ed260307a81db8af00dbf2b065fa56d08a
                                                        • Opcode Fuzzy Hash: 92c7e09074301d4b18fc7c5b8994e6dc2268ed5ef8c94d17356e2e6d55b92dee
                                                        • Instruction Fuzzy Hash: 9B01D83750C31E6D9A142B74AC9677B27E5EB0E77472083A9FB60970E0EFB14C18D151

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 353 bfa6eb-bfa6f6 354 bfa6f8-bfa702 call bfa7d4 353->354 355 bfa707-bfa70d 353->355 364 bfa7aa-bfa7ac 354->364 357 bfa70f-bfa715 355->357 358 bfa734-bfa749 call bfb2b9 355->358 361 bfa728-bfa732 357->361 362 bfa717-bfa722 call bfa7ad 357->362 367 bfa74b-bfa75f GetLastError call bf9d37 call bf9d91 358->367 368 bfa761-bfa768 358->368 366 bfa7a9 361->366 362->361 362->366 366->364 367->366 371 bfa76a-bfa774 call bfa7ad 368->371 372 bfa776-bfa78a call bfa542 368->372 371->372 380 bfa7a8 371->380 381 bfa78c-bfa7a0 GetLastError call bf9d37 call bf9d91 372->381 382 bfa7a2-bfa7a6 372->382 380->366 381->380 382->380
                                                        Strings
                                                        • C:\Users\user\Desktop\cXjy5Y6dXX.exe, xrefs: 00BFA707
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID: C:\Users\user\Desktop\cXjy5Y6dXX.exe
                                                        • API String ID: 0-2847042741
                                                        • Opcode ID: ddc99e26277d951d907234c79ffffb1fdd4ad9d2fe498ff782e99db680b44da7
                                                        • Instruction ID: 8ad334af2066925ea6bf1471752790912e357d02b389fcad0497270853e7ff25
                                                        • Opcode Fuzzy Hash: ddc99e26277d951d907234c79ffffb1fdd4ad9d2fe498ff782e99db680b44da7
                                                        • Instruction Fuzzy Hash: 09217CB560020DBF9B28BF61C880E7AB7F8EF0036571085A4FA19D7161DB30EC1887A2
                                                        APIs
                                                        • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,10008967,?,?,00000000,00C014CF,000000FF,?,00BF896C,00BF8A50,?,00BF8940,00000000), ref: 00BF89C5
                                                        • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00BF89D7
                                                        • FreeLibrary.KERNEL32(00000000,?,?,00000000,00C014CF,000000FF,?,00BF896C,00BF8A50,?,00BF8940,00000000), ref: 00BF89F9
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: AddressFreeHandleLibraryModuleProc
                                                        • String ID: CorExitProcess$mscoree.dll
                                                        • API String ID: 4061214504-1276376045
                                                        • Opcode ID: 825500d4012296e9e25aec762ac7bf267845c3627440a7d7632ecb304c68e9d4
                                                        • Instruction ID: d54d42d1df2377323e893e304385aa032f7a70b44f0de715189006aa9188015e
                                                        • Opcode Fuzzy Hash: 825500d4012296e9e25aec762ac7bf267845c3627440a7d7632ecb304c68e9d4
                                                        • Instruction Fuzzy Hash: 2701A236940619AFCB159B80DC05BFEBBF9FB09B10F008625E911A22E0DFB49944CB81
                                                        APIs
                                                        • EncodePointer.KERNEL32(00000000,?), ref: 00BF769B
                                                        • CatchIt.LIBVCRUNTIME ref: 00BF7781
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: CatchEncodePointer
                                                        • String ID: MOC$RCC
                                                        • API String ID: 1435073870-2084237596
                                                        • Opcode ID: 3ccf520597fb60358c175aa828f40cb1eca4e1e512841694a6a34bbe22385eee
                                                        • Instruction ID: 3cc952d41f6dc4855f4ae032ccf14170cadf274b90e2d735f22653fb3cfaa36c
                                                        • Opcode Fuzzy Hash: 3ccf520597fb60358c175aa828f40cb1eca4e1e512841694a6a34bbe22385eee
                                                        • Instruction Fuzzy Hash: BC41257290020DAFDF16DF98CD81AAEBBB5EF48304F2880D9FA14A7261D6359E54DB50
                                                        APIs
                                                        • LoadLibraryExW.KERNEL32(00000000,00000000,00000800,?,00BF6AF4,00000000,?,00C19C78,?,?,?,00BF6C97,00000004,InitializeCriticalSectionEx,00C12CC0,InitializeCriticalSectionEx), ref: 00BF6B50
                                                        • GetLastError.KERNEL32(?,00BF6AF4,00000000,?,00C19C78,?,?,?,00BF6C97,00000004,InitializeCriticalSectionEx,00C12CC0,InitializeCriticalSectionEx,00000000,?,00BF6A17), ref: 00BF6B5A
                                                        • LoadLibraryExW.KERNEL32(00000000,00000000,00000000), ref: 00BF6B82
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: LibraryLoad$ErrorLast
                                                        • String ID: api-ms-
                                                        • API String ID: 3177248105-2084034818
                                                        • Opcode ID: 84a955012f41d11e50dbeeb6cb9647336f25b1f911e58f689050fb9eb8c24b0c
                                                        • Instruction ID: 4d1edb3dddaa767baecf278bc0126c9854ddbf5834e788f2622b676886a0a2ed
                                                        • Opcode Fuzzy Hash: 84a955012f41d11e50dbeeb6cb9647336f25b1f911e58f689050fb9eb8c24b0c
                                                        • Instruction Fuzzy Hash: DCE01234640208BBEB201B61DC06FAD3BA5FB15B55F108160FA0DE61E1D7629865DA55
                                                        APIs
                                                        • GetConsoleOutputCP.KERNEL32(10008967,00000000,00000000,?), ref: 00BFDFE4
                                                          • Part of subcall function 00BFB2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00BFDC5F,?,00000000,-00000008), ref: 00BFB31A
                                                        • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 00BFE236
                                                        • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00BFE27C
                                                        • GetLastError.KERNEL32 ref: 00BFE31F
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: FileWrite$ByteCharConsoleErrorLastMultiOutputWide
                                                        • String ID:
                                                        • API String ID: 2112829910-0
                                                        • Opcode ID: d4925624cc51fc6d82bab414649bf404923260df43b68ba3ef3aa3776835262b
                                                        • Instruction ID: e700a8f6cdf6345ad7359a49d0511b52ffcd57c239f7ec68c1fa537d1e067925
                                                        • Opcode Fuzzy Hash: d4925624cc51fc6d82bab414649bf404923260df43b68ba3ef3aa3776835262b
                                                        • Instruction Fuzzy Hash: 7BD15A75D002589FCB15CFA8D884AFDBBF9FF09310F1481AAE666EB261D630E945CB50
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: AdjustPointer
                                                        • String ID:
                                                        • API String ID: 1740715915-0
                                                        • Opcode ID: 76ac8b24e43240e22ced2b74caa03edfe27c2686eac7feacd8b5d5ed0370721b
                                                        • Instruction ID: 741aa1b6136cabc485593e33be70b7d7da77830b7b44c2a30ae600aa80f23e64
                                                        • Opcode Fuzzy Hash: 76ac8b24e43240e22ced2b74caa03edfe27c2686eac7feacd8b5d5ed0370721b
                                                        • Instruction Fuzzy Hash: 5051A27164860AAFEB298F14D841BBAB7E5EF41711F1441E9EA01671A1EF319D8CC790
                                                        APIs
                                                          • Part of subcall function 00BFB2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00BFDC5F,?,00000000,-00000008), ref: 00BFB31A
                                                        • GetLastError.KERNEL32 ref: 00BF9F69
                                                        • __dosmaperr.LIBCMT ref: 00BF9F70
                                                        • GetLastError.KERNEL32(?,?,?,?), ref: 00BF9FAA
                                                        • __dosmaperr.LIBCMT ref: 00BF9FB1
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: ErrorLast__dosmaperr$ByteCharMultiWide
                                                        • String ID:
                                                        • API String ID: 1913693674-0
                                                        • Opcode ID: 35a78e76dd467280dde0ed599009c45b792c6dfc3976bdb66f6f459cc3aee8f2
                                                        • Instruction ID: 9ff77a06a928c676b3915e81ff9c19504b3f1bc87b04cf56767a2fb8897de255
                                                        • Opcode Fuzzy Hash: 35a78e76dd467280dde0ed599009c45b792c6dfc3976bdb66f6f459cc3aee8f2
                                                        • Instruction Fuzzy Hash: 9621B07160420DAFDB20AF61C880A7BB7EDFF44364B1085A8FA29C7140D730FD188B61
                                                        APIs
                                                        • GetEnvironmentStringsW.KERNEL32 ref: 00BFB364
                                                          • Part of subcall function 00BFB2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00BFDC5F,?,00000000,-00000008), ref: 00BFB31A
                                                        • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00BFB39C
                                                        • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00BFB3BC
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: EnvironmentStrings$Free$ByteCharMultiWide
                                                        • String ID:
                                                        • API String ID: 158306478-0
                                                        • Opcode ID: 4eeb7fa851c09e56f915d2ed99d4e552b3616fccf35b4066c1b70c2402ac5415
                                                        • Instruction ID: 4c03f8ff89d19eb4b3c2c98ef64d31f8d6f3a0ce37eed4f9ad102c23c3449fe0
                                                        • Opcode Fuzzy Hash: 4eeb7fa851c09e56f915d2ed99d4e552b3616fccf35b4066c1b70c2402ac5415
                                                        • Instruction Fuzzy Hash: CC11C4B550551D7F66256776DCC9DBF69ECDE453A432100A4FB01D3101EF60DD0892B8
                                                        APIs
                                                        • WriteConsoleW.KERNEL32(00000000,?,00000000,00000000,00000000,?,00BFEF14,00000000,00000001,00000000,?,?,00BFE373,?,00000000,00000000), ref: 00BFF76D
                                                        • GetLastError.KERNEL32(?,00BFEF14,00000000,00000001,00000000,?,?,00BFE373,?,00000000,00000000,?,?,?,00BFE916,00000000), ref: 00BFF779
                                                          • Part of subcall function 00BFF73F: CloseHandle.KERNEL32(FFFFFFFE,00BFF789,?,00BFEF14,00000000,00000001,00000000,?,?,00BFE373,?,00000000,00000000,?,?), ref: 00BFF74F
                                                        • ___initconout.LIBCMT ref: 00BFF789
                                                          • Part of subcall function 00BFF701: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,00BFF730,00BFEF01,?,?,00BFE373,?,00000000,00000000,?), ref: 00BFF714
                                                        • WriteConsoleW.KERNEL32(00000000,?,00000000,00000000,?,00BFEF14,00000000,00000001,00000000,?,?,00BFE373,?,00000000,00000000,?), ref: 00BFF79E
                                                        Memory Dump Source
                                                        • Source File: 00000000.00000002.1702761670.0000000000BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BA0000, based on PE: true
                                                        • Associated: 00000000.00000002.1702748194.0000000000BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702795825.0000000000C02000.00000040.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702812014.0000000000C12000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702825422.0000000000C19000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                        • Associated: 00000000.00000002.1702838956.0000000000C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_0_2_ba0000_cXjy5Y6dXX.jbxd
                                                        Similarity
                                                        • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                        • String ID:
                                                        • API String ID: 2744216297-0
                                                        • Opcode ID: e84151400a2afd16f5d2c5417ff0ecd3561928edb542e2366e6e83367cf0729e
                                                        • Instruction ID: 11e45baf6a30d2c7c60bbc2c932ef81eb5caf6d2f3cc7808aad10b419d2be31b
                                                        • Opcode Fuzzy Hash: e84151400a2afd16f5d2c5417ff0ecd3561928edb542e2366e6e83367cf0729e
                                                        • Instruction Fuzzy Hash: 10F0983651115DBBCF226F969C44BEE7EA6FF0A7A1B158160FA1896130C6328C21DB90
                                                        APIs
                                                        • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 030C0326
                                                          • Part of subcall function 030C00A4: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 030C00CD
                                                          • Part of subcall function 030C00A4: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 030C0279
                                                        • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 030C0378
                                                        • VirtualProtect.KERNELBASE(0000002C,?,00000040,?), ref: 030C03E7
                                                        • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 030C0407
                                                        • MapViewOfFile.KERNELBASE(?,00000004,00000000,00000000,00000000), ref: 030C042E
                                                        • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 030C0456
                                                        • CloseHandle.KERNELBASE(?), ref: 030C0471
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000001.00000003.1702598354.00000000030C0000.00000040.00000001.00020000.00000000.sdmp, Offset: 030C0000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_1_3_30c0000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: Virtual$Alloc$Free$CloseFileHandleProtectView
                                                        • String ID: ,
                                                        • API String ID: 3867569247-3772416878
                                                        • Opcode ID: 34919759cab89c45596a3336aca0d90db3a2564f30e7825e5c793611e7351f71
                                                        • Instruction ID: 38a9b31bca7e3b3a54144f5010c3be8904a88dd2ba9bfd0a98a4a13d90fe4fcd
                                                        • Opcode Fuzzy Hash: 34919759cab89c45596a3336aca0d90db3a2564f30e7825e5c793611e7351f71
                                                        • Instruction Fuzzy Hash: BC611BB5911249EFDB20DFA5C884ADEBBF8FF48354F148519FA59A7640D730E940CB60
                                                        APIs
                                                        • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 030C00CD
                                                        • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 030C0279
                                                        Memory Dump Source
                                                        • Source File: 00000001.00000003.1702598354.00000000030C0000.00000040.00000001.00020000.00000000.sdmp, Offset: 030C0000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_1_3_30c0000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: Virtual$AllocFree
                                                        • String ID:
                                                        • API String ID: 2087232378-0
                                                        • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                                        • Instruction ID: 87d399e8ac7582e240f1516162e7592a3006c1ba7ddb12e1e840b941ace21a47
                                                        • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                                        • Instruction Fuzzy Hash: 24719D71E15289DFDB41CF98C981BEDBBF0AF09314F284499E4A5FB241C234AA91CF64

                                                        Execution Graph

                                                        Execution Coverage:34.5%
                                                        Dynamic/Decrypted Code Coverage:100%
                                                        Signature Coverage:71.4%
                                                        Total number of Nodes:28
                                                        Total number of Limit Nodes:0
                                                        execution_graph 412 1d97cc419a0 413 1d97cc419b3 412->413 414 1d97cc419e7 413->414 415 1d97cc419d2 VirtualFree 413->415 415->414 416 1d97cc41cd0 418 1d97cc41cf5 416->418 417 1d97cc41f7d 418->417 427 1d97cc415ac 418->427 420 1d97cc41f74 CloseHandle 420->417 421 1d97cc41f64 NtAcceptConnectPort 421->420 422 1d97cc41e16 422->420 422->421 425 1d97cc41ea9 422->425 430 1d97cc40ac8 422->430 425->425 436 1d97cc41a90 NtAcceptConnectPort 425->436 429 1d97cc415e0 NtAcceptConnectPort 427->429 429->422 431 1d97cc40c4b 430->431 432 1d97cc40ae8 430->432 431->425 432->431 433 1d97cc40bd1 NtAcceptConnectPort 432->433 433->431 434 1d97cc40c04 433->434 434->431 435 1d97cc40c1c NtAcceptConnectPort 434->435 435->431 437 1d97cc41bf0 436->437 438 1d97cc41ae3 436->438 437->421 442 1d97cc4185c 438->442 440 1d97cc41afc 441 1d97cc41ba2 NtAcceptConnectPort 440->441 441->437 444 1d97cc41875 442->444 443 1d97cc41935 443->440 444->443 445 1d97cc4191c GetProcessMitigationPolicy 444->445 445->443

                                                        Callgraph

                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort$DuplicateHandlecalloc
                                                        • String ID: ,$H$H
                                                        • API String ID: 2577638757-438696205
                                                        • Opcode ID: 9fb62eb4d8959293fc2d40b19de36242d3d29fe68d1ba52932dcd9bec1ad6912
                                                        • Instruction ID: b852a42ab04c5d6f04dfd1c28fd0d16927887e8e7d578977c595c673363e5ada
                                                        • Opcode Fuzzy Hash: 9fb62eb4d8959293fc2d40b19de36242d3d29fe68d1ba52932dcd9bec1ad6912
                                                        • Instruction Fuzzy Hash: D202B73161CE8C8BD768DF58D885AABB3E0FB98305F10453ED58FC3691DA34E9518B92
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort$free
                                                        • String ID: $0$@
                                                        • API String ID: 2328307678-2347541974
                                                        • Opcode ID: d8fdb236a247b9205c502de8d0d979f89367b2180e7993cbf521bb03780d7e1e
                                                        • Instruction ID: b42c626f0639fdb1a4a7322d790dbece3eb2bf9cd603bc36d55eafcf00174e04
                                                        • Opcode Fuzzy Hash: d8fdb236a247b9205c502de8d0d979f89367b2180e7993cbf521bb03780d7e1e
                                                        • Instruction Fuzzy Hash: 5C51973152CB884FD768DF18D885BAAB7E0FB89704F20452ED68EC2641DB74D495CB93
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.1847921366.000001D97E640000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97E640000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_1d97e640000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort$FreeHeap
                                                        • String ID:
                                                        • API String ID: 2519882481-0
                                                        • Opcode ID: 06103e6240192ff0ea4d22a768af3a34bd3b5889dbd62609acb6a2f682bb8b02
                                                        • Instruction ID: 711cc337573c06ca14ea06b3cfa410bca5e3488e4fd1761d9f3180747238ea97
                                                        • Opcode Fuzzy Hash: 06103e6240192ff0ea4d22a768af3a34bd3b5889dbd62609acb6a2f682bb8b02
                                                        • Instruction Fuzzy Hash: 1DC1A93025CB098FDB58EF18D485BAAB7E1FB99350F10452EE48EC7256DB34E985CB81
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID: $0$@
                                                        • API String ID: 1658770261-2347541974
                                                        • Opcode ID: e038bc6975502a75aa15522c9d2aad796b46013016ac9629b0cf3dc02c1d6b17
                                                        • Instruction ID: b934c1021cce45bb7e91e73d85ea31f824e89cbca59a78ccb4ab3f342880e7c5
                                                        • Opcode Fuzzy Hash: e038bc6975502a75aa15522c9d2aad796b46013016ac9629b0cf3dc02c1d6b17
                                                        • Instruction Fuzzy Hash: 4A51293160CB898FE764DF68D894BABB7E4FB98301F20462EE58AC3250DB75D444CB52
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: NamedPipe$BindCallbackCompletionConnectCreate
                                                        • String ID:
                                                        • API String ID: 2502124517-0
                                                        • Opcode ID: 584620923d8bee05c4cd2b55fbc688861300e251001a2660cae9de72a1f183dd
                                                        • Instruction ID: b5b52dad34f81fa48850018ff2d2a9074edb19ab2f4b4b125fa974be41ee2691
                                                        • Opcode Fuzzy Hash: 584620923d8bee05c4cd2b55fbc688861300e251001a2660cae9de72a1f183dd
                                                        • Instruction Fuzzy Hash: 4A319270608A888FD794EF68D8D879A77F1FB94310F50462AE09BC61D0DF78D885CB91
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID: 0
                                                        • API String ID: 0-4108050209
                                                        • Opcode ID: d4dd2c9ec2e40b847152b417cb6d645fdeafd31ca8a11a7a04321dd5438b40c0
                                                        • Instruction ID: ba839216a02eb790d3a11087b0ea00db4360c3cdc988ead63421637bd6c602cc
                                                        • Opcode Fuzzy Hash: d4dd2c9ec2e40b847152b417cb6d645fdeafd31ca8a11a7a04321dd5438b40c0
                                                        • Instruction Fuzzy Hash: 8921A732A0CF8C4FD754DF58AD84BAA72E1FB88355F60053FE64AC3190D73898958756
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID: 0
                                                        • API String ID: 0-4108050209
                                                        • Opcode ID: 47ebd45c6b9b16ee77b28bcb10b07460bf5cba96d3288197dd2caf634787b8b3
                                                        • Instruction ID: 858c32be8dd6b0f0bc8713be715844257c7ac4bbdb1f4457a81fd636b8acf0ce
                                                        • Opcode Fuzzy Hash: 47ebd45c6b9b16ee77b28bcb10b07460bf5cba96d3288197dd2caf634787b8b3
                                                        • Instruction Fuzzy Hash: E121A832B0CE8C4FD7509E9899C4BAB76F0EB98742F60053FE64EC3250D7689D948752
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: CloseHandleSuspendThread
                                                        • String ID:
                                                        • API String ID: 1038686644-0
                                                        • Opcode ID: ee8ed1484b309d5b480d9ed41d064abcb8b4e034361352156597246fbc6f772d
                                                        • Instruction ID: 67075e019ff4a5cdab157d9921ddfed646d69a6277fcca27f60fee4705c5e25a
                                                        • Opcode Fuzzy Hash: ee8ed1484b309d5b480d9ed41d064abcb8b4e034361352156597246fbc6f772d
                                                        • Instruction Fuzzy Hash: 0591B330F0CA598FEB68DB18DD955BA73E1FF46310B24416AD14FD6685CA3CE842CBA1

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptCloseConnectHandlePort
                                                        • String ID:
                                                        • API String ID: 3811980168-0
                                                        • Opcode ID: 2998f17752da19f3229414bc30af807452c20e21bc577cde4fa90f5802e493a5
                                                        • Instruction ID: e0282231ef61c27a4200b464b5571743e0d61f4d7d07b6d5b599e7e3650dfa48
                                                        • Opcode Fuzzy Hash: 2998f17752da19f3229414bc30af807452c20e21bc577cde4fa90f5802e493a5
                                                        • Instruction Fuzzy Hash: 2D91E930518E489FEB65EF18C4817E577E0FBC4310F248A5FD4DBC3196DA34A9428B81

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 82f3aeb1d2454658223fb6d5b21d23051085e6a8eeabdc877af9343281df37cc
                                                        • Instruction ID: 91c99f2ce0e03d4109c381d4361ccc8e45d74e3badea25b487936d1b9b379e6d
                                                        • Opcode Fuzzy Hash: 82f3aeb1d2454658223fb6d5b21d23051085e6a8eeabdc877af9343281df37cc
                                                        • Instruction Fuzzy Hash: 3A415F30968A944AF328F62C8C866B97BD1F7C5309F34895FE4D6C2192D539C6438B46

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort$MitigationPolicyProcess
                                                        • String ID:
                                                        • API String ID: 2923266908-0
                                                        • Opcode ID: d10bc7eecf76d0dca438e32bd9e6ca23ea1b11bfffb6ce02bc94d4770511dc9b
                                                        • Instruction ID: 28119604503b4164533bfd719a2d240acdc2d0e7a62eb9dffee7149d65855560
                                                        • Opcode Fuzzy Hash: d10bc7eecf76d0dca438e32bd9e6ca23ea1b11bfffb6ce02bc94d4770511dc9b
                                                        • Instruction Fuzzy Hash: BD41D430218B888FDB44EF2C98897D57BD1FB99320F14839EE89ACB2D7DA34D5058795
                                                        APIs
                                                        • socket.WS2_32(?,?,?,?,?,?,?,?,0000006B,0000006A,-00000002,00007DF41C3341A9), ref: 00007DF41C3340B5
                                                          • Part of subcall function 00007DF41C333C98: ioctlsocket.WS2_32 ref: 00007DF41C333CC4
                                                        • bind.WS2_32(?,?,?,?,?,?,?,?,0000006B,0000006A,-00000002,00007DF41C3341A9), ref: 00007DF41C33413A
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: bindioctlsocketsocket
                                                        • String ID:
                                                        • API String ID: 3555158474-0
                                                        • Opcode ID: 1cbeedcb49cdd83f56073e3a9aa9cf65c2d138516cd5c7d59cce1983b39e0131
                                                        • Instruction ID: d8ea16ac49ce16f38b480787601bb335f63020a0b40387bbc11445dfba1aeba9
                                                        • Opcode Fuzzy Hash: 1cbeedcb49cdd83f56073e3a9aa9cf65c2d138516cd5c7d59cce1983b39e0131
                                                        • Instruction Fuzzy Hash: 93210A30B08D484FE748AF38DD8DAA637E1EB55325F20567AD92FC72D1DE289C0187A1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 9166209b5f367574360b80d64ced2ea26e8fa752ef609ccd6263efb912702e76
                                                        • Instruction ID: 030c03fb4b55bcd0221d499438c907a585d18cabf5794c33fc97a4cfdddc7ea4
                                                        • Opcode Fuzzy Hash: 9166209b5f367574360b80d64ced2ea26e8fa752ef609ccd6263efb912702e76
                                                        • Instruction Fuzzy Hash: E121623150CE488FDB54EF18D848BAA73F1FBA9341F10052EE54AC36A0DBB4E884CB42
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 98531d878e0ad7d3d6690ce9736b63ba0a61470b6d8d195234036ffb9fe9491b
                                                        • Instruction ID: 6f6ea6776d05727a35c96e6ce358fe07c10a48b4518faaa69b3d98a1aff7d110
                                                        • Opcode Fuzzy Hash: 98531d878e0ad7d3d6690ce9736b63ba0a61470b6d8d195234036ffb9fe9491b
                                                        • Instruction Fuzzy Hash: 9A21543151CE488FDB49EB58D948BA673F1FBAC341F00456EE54AC32A0DBB4E984CB42
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 1a40425d81a0dda3cd82788b19327da5a379df3b5c3bd351d49e58af76a5eeec
                                                        • Instruction ID: bfefc68b246321d1be35b819e0496de3c11b353fa56900f6f9e385cfec79a2dd
                                                        • Opcode Fuzzy Hash: 1a40425d81a0dda3cd82788b19327da5a379df3b5c3bd351d49e58af76a5eeec
                                                        • Instruction Fuzzy Hash: FD81C83690CF8D8BE7659B49AD54EEBB7E0FF94300F64462BE54FC3180DA68E8508653
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: Recv
                                                        • String ID:
                                                        • API String ID: 4192927123-0
                                                        • Opcode ID: 7916fdf4d3e942b440d7f5c412e90116e139ebed5d60f444feec34680a904e5a
                                                        • Instruction ID: 6fbae9e30217706f01afd190c45b84f88c7c786750a47331366312e2a74844f4
                                                        • Opcode Fuzzy Hash: 7916fdf4d3e942b440d7f5c412e90116e139ebed5d60f444feec34680a904e5a
                                                        • Instruction Fuzzy Hash: 45516D74608E898FEBA4EF18CA84B967BF0FF54314F60056AD54BC3561DB39E440CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 5c97c20283281d0f686864c64b2abe35391f7ab31688f0fa8af160c1736108da
                                                        • Instruction ID: 297b19de97cdd100d0fcf670ebbc70522f65d1d525894aca02be4219ee94811b
                                                        • Opcode Fuzzy Hash: 5c97c20283281d0f686864c64b2abe35391f7ab31688f0fa8af160c1736108da
                                                        • Instruction Fuzzy Hash: 8231C83270CE485FE71C5E18AD859BA73E0EB49315F20463EEA4FC3292D918B81246D2
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: CryptDataUnprotect
                                                        • String ID:
                                                        • API String ID: 834300711-0
                                                        • Opcode ID: a07a12428c7964199d363ccabf4b149c9f1c56c6408fd6f078d364f4c66a6574
                                                        • Instruction ID: 9b50d389d0f86d27c34a6866d0a9d074f13cf82d3ebfbf23e8a41ab6c8f54fb4
                                                        • Opcode Fuzzy Hash: a07a12428c7964199d363ccabf4b149c9f1c56c6408fd6f078d364f4c66a6574
                                                        • Instruction Fuzzy Hash: 8231C53171CA884FD748DB58D88966FB7E1FBC8301F50456DE18BC3251DA78D8018B52

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 115 1d97cc415ac-1d97cc415de 116 1d97cc415e0-1d97cc415e3 115->116 117 1d97cc415e5-1d97cc415e7 115->117 118 1d97cc4160b-1d97cc41659 NtAcceptConnectPort 116->118 119 1d97cc415e9-1d97cc415f5 117->119 120 1d97cc415f7-1d97cc415f9 117->120 119->118 121 1d97cc41609 120->121 122 1d97cc415fb-1d97cc41607 120->122 121->118 122->118
                                                        APIs
                                                        • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,00000000,000001D97CC41E16), ref: 000001D97CC41640
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 835a411c94ef729b3118f684f14c42465dca72cdcacd8c0bc7bbe2bb8e6fff18
                                                        • Instruction ID: 4bfa317a522e319bf79ed90ba31ab08725e0f1e41916cd01250f6aafd1ae4bef
                                                        • Opcode Fuzzy Hash: 835a411c94ef729b3118f684f14c42465dca72cdcacd8c0bc7bbe2bb8e6fff18
                                                        • Instruction Fuzzy Hash: 22218E71918B488FDB58DF58C4C96AABBE5FBA8305F184A2FE48AC7260D730D584CB41
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: d99824a7b56689602d55d9b975c23b4966fb1dfc1a28fa016acf5b8b83f0fdf8
                                                        • Instruction ID: 3d5914d6fc5ebfa87cc46ed332551ac92355763503a0909f56c0a2a83654246b
                                                        • Opcode Fuzzy Hash: d99824a7b56689602d55d9b975c23b4966fb1dfc1a28fa016acf5b8b83f0fdf8
                                                        • Instruction Fuzzy Hash: 0CF0B67450C7C88FD7A0EB688441B9ABBF0BB9A350F544A1DE4CCC3211D73494858B13
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: af3340e2b301fb20eba4bd36f70d30fdbe005acca17dd1e0c445e9428843075b
                                                        • Instruction ID: cd10e90f343388b95434dc194e1711decc91f55ca5b99713884e4ab2cde87525
                                                        • Opcode Fuzzy Hash: af3340e2b301fb20eba4bd36f70d30fdbe005acca17dd1e0c445e9428843075b
                                                        • Instruction Fuzzy Hash: B2F0D030A1CB848FDBA4EF2CD4C5B9977E1FB98300F504519E44CC3245DB3498808B46
                                                        APIs
                                                        • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,00000000,?,?,00000000,00007DF41C2F341C), ref: 00007DF41C30AF8A
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 1d9a6f3c19fc3a1664a9a6811ff4ba6c27299ee4e4794d390710366357d59dbc
                                                        • Instruction ID: b1558f9fc7425ef8d2ced680bea61a69b937514eb9d943a8d84aabff74f83c13
                                                        • Opcode Fuzzy Hash: 1d9a6f3c19fc3a1664a9a6811ff4ba6c27299ee4e4794d390710366357d59dbc
                                                        • Instruction Fuzzy Hash: 6BE09B7161CA488FDB04DF94DCC18AAB3F0FBD9300F104E3AE94AC7164D264D559C692
                                                        APIs
                                                        • GetSystemInfo.KERNELBASE(?,00007DF41C37B7C7,?,?,?,?,00000000,00000000), ref: 00007DF41C369F21
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: InfoSystem
                                                        • String ID:
                                                        • API String ID: 31276548-0
                                                        • Opcode ID: d72fac8d1d1b7f96bb5fe0759d88f2d5c6e0343dfc4f10e03c2c9322f33a3d86
                                                        • Instruction ID: 100c5ff4a774e2ff239980bdd2fc828efd3fec72f54c7126c04890dd6c9ce95b
                                                        • Opcode Fuzzy Hash: d72fac8d1d1b7f96bb5fe0759d88f2d5c6e0343dfc4f10e03c2c9322f33a3d86
                                                        • Instruction Fuzzy Hash: 77E04F31918C5D4BF74DF770DCA6CE73371EB64300FA14632D907C10A2ED2C664A8691
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: a9327488733b823840a3f29582a089392b2a1446868cb63a967a810240f58cb8
                                                        • Instruction ID: 523be9110305773fafbf3347b667df5e502e680c91734e04e11f49e0d1202802
                                                        • Opcode Fuzzy Hash: a9327488733b823840a3f29582a089392b2a1446868cb63a967a810240f58cb8
                                                        • Instruction Fuzzy Hash: D1D05E30968E8D4BD610A7289901A5637E1FBD4304FA44714D849C2240D23CE452D286
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 4927af5c10e17f27f2edd3b7dd4d43612d79bd47543f67f71f12626d98bff908
                                                        • Instruction ID: 8bbf3554b2f35e6805968648c694219343c367373f6bddbbc39429175de397a7
                                                        • Opcode Fuzzy Hash: 4927af5c10e17f27f2edd3b7dd4d43612d79bd47543f67f71f12626d98bff908
                                                        • Instruction Fuzzy Hash: 21D05E31E68ECD4BD610A7289A0164A36E2FB95308FA04614E849C2250D23CE4128386
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: eb8f498348e5c7f372421b27a3827434041340d731fc3728b954386bc4ea4cc4
                                                        • Instruction ID: 61261a211f3cc1f68201bdb42fd1a482c895477efe29c2cc00854bfc4966a001
                                                        • Opcode Fuzzy Hash: eb8f498348e5c7f372421b27a3827434041340d731fc3728b954386bc4ea4cc4
                                                        • Instruction Fuzzy Hash: 74D05E20A28A8D4BD650A7289A4164A37E2FB95304FA14614E44EC2200D22CE41282C2
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 333093483b5b65ac6ab85e83ccc52a142bbc301cae1d85d61a22b47e66de8b6c
                                                        • Instruction ID: cf714263896845c57d7da2e3712db3f927382fe7d3fbb462e33968fa46717236
                                                        • Opcode Fuzzy Hash: 333093483b5b65ac6ab85e83ccc52a142bbc301cae1d85d61a22b47e66de8b6c
                                                        • Instruction Fuzzy Hash: B2C08C20A2CC0F0BE914F2B96E82B8520A0AB4C704F970220E80AC2180E41CE4F1D3A2
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 953671860da08bf31fab518e05a010f803d920f951da2702e38e3d0cf3acdea6
                                                        • Instruction ID: c163a87e0d5c1243e4262c041222a141e6a14085546cef5d6c4e98ee11676f7c
                                                        • Opcode Fuzzy Hash: 953671860da08bf31fab518e05a010f803d920f951da2702e38e3d0cf3acdea6
                                                        • Instruction Fuzzy Hash: 00C08C01A69C0F8AE90862BA7E82B9922A0AB48300F900111E60EC2180E40CE4E643B2
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID: rE\
                                                        • API String ID: 544645111-988334199
                                                        • Opcode ID: dc7abe3753608a406b2e8c4677f2e3e348cb1d8b9abc271147da51083885c1c3
                                                        • Instruction ID: 7fff61709b84e58e05833720297d27ae6586e13b19d339c4472dfe71263ed5f4
                                                        • Opcode Fuzzy Hash: dc7abe3753608a406b2e8c4677f2e3e348cb1d8b9abc271147da51083885c1c3
                                                        • Instruction Fuzzy Hash: 4F214131B18D484BDB54E758A891AAA73E6FBD8700F100439E54BD3286DE7CED4587C2
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID:
                                                        • API String ID: 544645111-3916222277
                                                        • Opcode ID: 45ee73fde44b844a7982fd6fa2bb9a274e67d6e904138dbe31d6ae3e461be495
                                                        • Instruction ID: e4ac4e881b77e313334767cfb8fa534a758d23acda193994ec5fa1d429a22fe5
                                                        • Opcode Fuzzy Hash: 45ee73fde44b844a7982fd6fa2bb9a274e67d6e904138dbe31d6ae3e461be495
                                                        • Instruction Fuzzy Hash: 9B11E431A08C9A0BE715A718ED646F673E1FB84710FA44136E54BC32A1DA1CE952C691
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: Completion$CreateFileModesNotificationPortioctlsocket
                                                        • String ID:
                                                        • API String ID: 1455841399-0
                                                        • Opcode ID: b0ef64daf23010be4df91d754ff29401ba7eeb6e21b37df906d22bfb74ec9eab
                                                        • Instruction ID: 92fecb7cbe4143c98a8dcb65789f9dc52053c124ea2e02f5084d12c8fed10a30
                                                        • Opcode Fuzzy Hash: b0ef64daf23010be4df91d754ff29401ba7eeb6e21b37df906d22bfb74ec9eab
                                                        • Instruction Fuzzy Hash: 3731BA3060CD9C4BFBA5AA189E84AB732E5FF54715F60507AD50FC2292DA29EC4246E1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: InitializeUninitializefree
                                                        • String ID:
                                                        • API String ID: 1169324116-0
                                                        • Opcode ID: 300bfe15e1352cda4c3c9a5eb26de8ea91f06f6889c64728d4398b9a5c111e42
                                                        • Instruction ID: 25e5b40e02011b56e59e6a6a4fe930afabded92b05db6c1b38886f2b9b493b43
                                                        • Opcode Fuzzy Hash: 300bfe15e1352cda4c3c9a5eb26de8ea91f06f6889c64728d4398b9a5c111e42
                                                        • Instruction Fuzzy Hash: D2214C30609A0D8FDF84EF68D849AAA77E0FF94315F10462AE94ED3251CB38E941CB90
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free$callocmalloc
                                                        • String ID:
                                                        • API String ID: 1437353635-0
                                                        • Opcode ID: 6cebd9367394abf21773eb1584d65681aa51e4210b0eb886ea29ebe4f46530e1
                                                        • Instruction ID: b2f911816795c8954472526ac6e9b041551ffdc422f6ec985179a8d6d67940a5
                                                        • Opcode Fuzzy Hash: 6cebd9367394abf21773eb1584d65681aa51e4210b0eb886ea29ebe4f46530e1
                                                        • Instruction Fuzzy Hash: C3422030A18E4C8FDB55EF28D889AEAB7E1FB58700F20462AD15FC7251DF38A545CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc$free
                                                        • String ID:
                                                        • API String ID: 1480856625-0
                                                        • Opcode ID: f833b09acc7dcda6218a08ced81fc052c99920b07a41f041528abf3627ace0e1
                                                        • Instruction ID: 93b6f39daa22673716137ac4aea319e9d2ae52918e4a9b75c52bb84f6aeff018
                                                        • Opcode Fuzzy Hash: f833b09acc7dcda6218a08ced81fc052c99920b07a41f041528abf3627ace0e1
                                                        • Instruction Fuzzy Hash: 3A317131B08E099BAB58AEA4DC458FAB3E0FF54310720422AD51BD7691EF68F951C7D1
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.1847921366.000001D97E640000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97E640000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_1d97e640000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: FreeHeap
                                                        • String ID: l
                                                        • API String ID: 3298025750-2517025534
                                                        • Opcode ID: 945787e355e9cefb289f3126088299a2a592093c218b6f331fdd883cb8990c47
                                                        • Instruction ID: a5d1d592cbf0677f30c8227060ee8ef75d25ff8621ef9a24919fa7af4c07aa7e
                                                        • Opcode Fuzzy Hash: 945787e355e9cefb289f3126088299a2a592093c218b6f331fdd883cb8990c47
                                                        • Instruction Fuzzy Hash: 74A1263152865A4BE729AB2C88926FA77D1FB96340F10066FE4DBC3187DD34DA46CAC1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: CreateFile$AcceptConnectMappingPortcalloc
                                                        • String ID:
                                                        • API String ID: 2835849967-0
                                                        • Opcode ID: d1b445dc56701135788b0dc920e68535db059dd4faca11d9a453a424e093dfee
                                                        • Instruction ID: da698b92f8a7fda437b9858dac35418f2724289fd3b4f77223c7a984173dab9d
                                                        • Opcode Fuzzy Hash: d1b445dc56701135788b0dc920e68535db059dd4faca11d9a453a424e093dfee
                                                        • Instruction Fuzzy Hash: 52D15071A1CB888BD765EF18D9856EBB7E0FB94300F14452EE58FC2251DF38A505CB92
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: File$CreateReadmalloc
                                                        • String ID:
                                                        • API String ID: 3950102678-0
                                                        • Opcode ID: b879bc7b5dc6143657be184a8553957d82cf9a437ba6bdf4bbb2c4680e42a6eb
                                                        • Instruction ID: 35ee810bcf5b0e1a6896418664cfec1013050a2e85118ee3eacc847a0a4a7b12
                                                        • Opcode Fuzzy Hash: b879bc7b5dc6143657be184a8553957d82cf9a437ba6bdf4bbb2c4680e42a6eb
                                                        • Instruction Fuzzy Hash: 6A719531618E484FD7589F1998C5BEEB3E1FB98300F60053EE6CFC3292DA389845C652
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AllocInfoSystemVirtual
                                                        • String ID:
                                                        • API String ID: 3440192736-0
                                                        • Opcode ID: 10974d638571623cb466fc5259723849182c6a649d453933aa228a33d07da908
                                                        • Instruction ID: 7c1570d632166677437825fb472f8a86ad3a1501affffa56a5f0bafa7f7f4089
                                                        • Opcode Fuzzy Hash: 10974d638571623cb466fc5259723849182c6a649d453933aa228a33d07da908
                                                        • Instruction Fuzzy Hash: A651F730B1CE4D8FE759AA5899483AA33E1FB99300F24013AD54FD3295DAACD8818791
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: File$CreateRead
                                                        • String ID:
                                                        • API String ID: 3388366904-0
                                                        • Opcode ID: 73db5555d885fd7ea61d85234132b183eb459049274d5711c35081ec0b7aef7a
                                                        • Instruction ID: 50858a8315cb490d68abe7e0e8bc7fc4bc2f98044629bd0a3918d6373587bd59
                                                        • Opcode Fuzzy Hash: 73db5555d885fd7ea61d85234132b183eb459049274d5711c35081ec0b7aef7a
                                                        • Instruction Fuzzy Hash: 7D41B47070CA884FEB59EF289C8566B77E5FB99701F10452EE98FC3251EE38D8018792
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: File$CreateRead
                                                        • String ID:
                                                        • API String ID: 3388366904-0
                                                        • Opcode ID: 6dcf9cfff2eacf5cd94369649f002897bcffdea66228e64647734ab7a70026dd
                                                        • Instruction ID: 9ccfd6b59233826c31f258b11a9a973463b62628b615cf6bf624a1e28b96f205
                                                        • Opcode Fuzzy Hash: 6dcf9cfff2eacf5cd94369649f002897bcffdea66228e64647734ab7a70026dd
                                                        • Instruction Fuzzy Hash: 4821F77170CB484FE3549E59AC8667B73D4EB89710F20013FE98FC2242DA74A8164697
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID:
                                                        • API String ID: 544645111-0
                                                        • Opcode ID: e54d32ce24f4b710544f648fa16c64d8d7f0589b34fc61474f65512f49413183
                                                        • Instruction ID: 15f4cc8a3c8032586d2960d564ec37bbb1e8ca974c2a2d6ad67dced4b954534d
                                                        • Opcode Fuzzy Hash: e54d32ce24f4b710544f648fa16c64d8d7f0589b34fc61474f65512f49413183
                                                        • Instruction Fuzzy Hash: 1A31F92070CA858FD7149B6CDC947A63BD1EB5A310F2512A5E98FD73C5CB6CD842C351
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: callocfree
                                                        • String ID:
                                                        • API String ID: 306872129-0
                                                        • Opcode ID: 2b200ceb4e4cc9f035faf7b6c1b247c7413155f6bad845cc72cf0ce4a6dd00dc
                                                        • Instruction ID: 9222dca6dcaa3f7d8680a99fad7e64229d8420a94885e1125991da33380c69e1
                                                        • Opcode Fuzzy Hash: 2b200ceb4e4cc9f035faf7b6c1b247c7413155f6bad845cc72cf0ce4a6dd00dc
                                                        • Instruction Fuzzy Hash: 48D17131A1CF8C4BEB65EB14C995AEBB3E1FF94300F50052FD54FC3192DA38A9558692
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc$free
                                                        • String ID:
                                                        • API String ID: 1480856625-0
                                                        • Opcode ID: 352f2f2cecbb3e27f866ef48949e4e4dcfd5ee98b9eced5f0af6e5ea8a5601e0
                                                        • Instruction ID: d81561d748d76e7680c109316c5257a2692afcdaedf2e010c9fe58ca6156c08d
                                                        • Opcode Fuzzy Hash: 352f2f2cecbb3e27f866ef48949e4e4dcfd5ee98b9eced5f0af6e5ea8a5601e0
                                                        • Instruction Fuzzy Hash: B171E731A1CD984BE729A7589D95AFFB3E1FB85300F20067FE18FC2183DD38A9458695
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc$AcceptConnectPortfree
                                                        • String ID:
                                                        • API String ID: 342249184-0
                                                        • Opcode ID: 694a03a6a0a341675988201f7685504af8169e7f1b53cb1e5f9007a100a90dea
                                                        • Instruction ID: 88bb94b9805f1a8c7b0ff1b1dea91b96f7f66f44d38dd588532141b921dd31c8
                                                        • Opcode Fuzzy Hash: 694a03a6a0a341675988201f7685504af8169e7f1b53cb1e5f9007a100a90dea
                                                        • Instruction Fuzzy Hash: BF416071508B4C8FDB68EF18D885AEA77E5FB58701F10016AD84EC7251DB34E985CB92
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: 31b51a1252b2397096177e19cb7010b666d546ef653b70412147a1dab026b8b6
                                                        • Instruction ID: 660e21bbcc5c1944fdf1378adb4029e2c1960eab4d6a70c0201ac75dbba5379b
                                                        • Opcode Fuzzy Hash: 31b51a1252b2397096177e19cb7010b666d546ef653b70412147a1dab026b8b6
                                                        • Instruction Fuzzy Hash: C4418131608D0E8FDB94EF2CD898AA677F1FB68311724466BD41AC3660DB75E8948BC0
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 472e16019ba601094a4c2923f039f601fa415deb3ae2891c44a4e6fa2e872d25
                                                        • Instruction ID: 2d256730005a5cf851fb968e815712fe56dc4f43db7c1e3738426dd3df4879bf
                                                        • Opcode Fuzzy Hash: 472e16019ba601094a4c2923f039f601fa415deb3ae2891c44a4e6fa2e872d25
                                                        • Instruction Fuzzy Hash: 93215030A08C0C4FDEA4FB1CD6C5DA577E3EB887207B502A1D91BC7199C625EC818790
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: callocfree
                                                        • String ID:
                                                        • API String ID: 306872129-0
                                                        • Opcode ID: 14d07331c19738ae6f5dcbbc3446d40274566deaf3c6ba6d90dddde88c6f0ea8
                                                        • Instruction ID: 482d1cb9b7d0690ade57eb1671d913a85dc6044cad53cce37f838b1641c6cc83
                                                        • Opcode Fuzzy Hash: 14d07331c19738ae6f5dcbbc3446d40274566deaf3c6ba6d90dddde88c6f0ea8
                                                        • Instruction Fuzzy Hash: AF21D530A18E0C4FD748AF5898855E577E4FB58311F10426ED44EC3261EA74E841CBD2
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPortcallocfree
                                                        • String ID:
                                                        • API String ID: 1866692179-0
                                                        • Opcode ID: 1c81860f17a6367f43a2a94f10a5d32e0a9fa92ddff0a1d18b0803ced88c0a31
                                                        • Instruction ID: 934535627934f1cf03fc033ff95bd6b6a1a8c59525559b882870dd56b696897d
                                                        • Opcode Fuzzy Hash: 1c81860f17a6367f43a2a94f10a5d32e0a9fa92ddff0a1d18b0803ced88c0a31
                                                        • Instruction Fuzzy Hash: 5EF02831214D0C4FD758BB1C9C88AB637E5EB94726714462AE00BC3360DD78DD408790
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: calloc
                                                        • String ID:
                                                        • API String ID: 2635317215-0
                                                        • Opcode ID: 4c67779dd63165b43659fab8fd510d9b574d13d676e16a29e3859926c8de3004
                                                        • Instruction ID: 05aceb686aff939609d193801bdd9a30f2f7b573d964385aad901c337c63d290
                                                        • Opcode Fuzzy Hash: 4c67779dd63165b43659fab8fd510d9b574d13d676e16a29e3859926c8de3004
                                                        • Instruction Fuzzy Hash: 6C72643151CA888BDB69EB18C981EDEB3F1FF94300F60462EE58F83296DE34E5458756
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: CreateFileMapping
                                                        • String ID:
                                                        • API String ID: 524692379-0
                                                        • Opcode ID: 090a60165b6d81dbbef6ccd1718067ffa9bcceaffdfa6db13320491a5d5642c1
                                                        • Instruction ID: fe1a2959e346aa2c42d4750f3a47f271a0aa4a3eeb667c72fdd2faf121b6ccda
                                                        • Opcode Fuzzy Hash: 090a60165b6d81dbbef6ccd1718067ffa9bcceaffdfa6db13320491a5d5642c1
                                                        • Instruction Fuzzy Hash: 97A13F31A0CA8C8FDB55EF18C8859EAB7F1FB94310F50462EE14FD7291DA38A945CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: Open
                                                        • String ID:
                                                        • API String ID: 71445658-0
                                                        • Opcode ID: e8d5d7329d2320a05d82013e26ca3d8c66ee9948d03da3e8e50157f1609a8dd5
                                                        • Instruction ID: 8513af1b848e8130446bdedf62d43e56de2af643b6c03471e6c41d5c7755ad6a
                                                        • Opcode Fuzzy Hash: e8d5d7329d2320a05d82013e26ca3d8c66ee9948d03da3e8e50157f1609a8dd5
                                                        • Instruction Fuzzy Hash: FD919C3161DB888FE765EF24C889B9BB7E5FB98301F10492EE58AC3261DB34D544CB52
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: Send
                                                        • String ID:
                                                        • API String ID: 121738739-0
                                                        • Opcode ID: d8e018eafecf73722f3cfd2108c578dd3fd3213e6426fbbfe5b50f999653df9c
                                                        • Instruction ID: 38ba58457555d0f480c150deaee4181b9733717900babc8b435a47af982b0efc
                                                        • Opcode Fuzzy Hash: d8e018eafecf73722f3cfd2108c578dd3fd3213e6426fbbfe5b50f999653df9c
                                                        • Instruction Fuzzy Hash: 31818070508E499FEB98EF28C584BA6BBE0FF54315F10426AD44FC7691DB35E850CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: InformationVolume
                                                        • String ID:
                                                        • API String ID: 2039140958-0
                                                        • Opcode ID: 458a1419ed12d8a3c2e86420f2914f8409b820493848f008ec8053e1bf8f0b77
                                                        • Instruction ID: 87c453d4c6a1ffb3860f441c67511e21151391666418eac9c8ca1d7b3d4931ea
                                                        • Opcode Fuzzy Hash: 458a1419ed12d8a3c2e86420f2914f8409b820493848f008ec8053e1bf8f0b77
                                                        • Instruction Fuzzy Hash: AA616E7190CB8C8BE755EF54D8856DBB7E1FB94300F100A2EE18BC3151DE39A645CB52
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: CreateProcess
                                                        • String ID:
                                                        • API String ID: 963392458-0
                                                        • Opcode ID: e9169745a3f5c8f3addee9eb58fc29d082d9d243fdbbd28d7b824531286ef21a
                                                        • Instruction ID: 9a855d2b629c691bf66c7688baa6b572ad978779061061fe12faed259a2d85c2
                                                        • Opcode Fuzzy Hash: e9169745a3f5c8f3addee9eb58fc29d082d9d243fdbbd28d7b824531286ef21a
                                                        • Instruction Fuzzy Hash: CC51303161CB888BE768DF58D849BABB7E5FF94311F10052EE58BC3191DB78E8118B52
                                                        APIs
                                                          • Part of subcall function 00007DF41C2F65E0: VirtualProtect.KERNELBASE ref: 00007DF41C2F6640
                                                          • Part of subcall function 00007DF41C2F65E0: VirtualProtect.KERNELBASE ref: 00007DF41C2F6669
                                                          • Part of subcall function 00007DF41C2F65E0: VirtualProtect.KERNELBASE ref: 00007DF41C2F6685
                                                          • Part of subcall function 00007DF41C2F65E0: VirtualProtect.KERNELBASE ref: 00007DF41C2F66B0
                                                        • TlsFree.KERNELBASE(?,?,?,?,?,?,?,00000000,?,?,00000000,00007DF41C2F341C), ref: 00007DF41C2F7CB7
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual$Free
                                                        • String ID:
                                                        • API String ID: 3841229516-0
                                                        • Opcode ID: 9454607179550a56fcb25c77309fc397396c8818e949c4bf6b88fbdfb1fa50f0
                                                        • Instruction ID: 4fa7cd053bdce3d4798ded652c5012e574f2f66fbd94f4dd30c4f74f4ac69502
                                                        • Opcode Fuzzy Hash: 9454607179550a56fcb25c77309fc397396c8818e949c4bf6b88fbdfb1fa50f0
                                                        • Instruction Fuzzy Hash: 8341D230F08E4C8BEB54EB6899945EE73A1EF48B00B214577E51FD7386DA2CF84087A1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: ErrorFunctionModeTable
                                                        • String ID:
                                                        • API String ID: 928017140-0
                                                        • Opcode ID: d9c23544fbb2a9f569b4c70e99ee3ada11af114710c16124923c5dd5b1b488fd
                                                        • Instruction ID: a25941fb223eef7f80252a6adb5b208bcb16f96639d94763cc3fcb2594cc6ce5
                                                        • Opcode Fuzzy Hash: d9c23544fbb2a9f569b4c70e99ee3ada11af114710c16124923c5dd5b1b488fd
                                                        • Instruction Fuzzy Hash: A2318121F18C8D4BEA54FB689D825EA73E1EB44710B60057AD24FC33D2D95CAD8543A1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: setsockopt
                                                        • String ID:
                                                        • API String ID: 3981526788-0
                                                        • Opcode ID: 5ecb9aca37cfa74a852660f22e24977ddf5ffe3d9d8c212dab6545ea967c75f3
                                                        • Instruction ID: 78bef9522397f1a9f6ba6408492e0b1ff6ce6144cb3f96324841a45d9946fff7
                                                        • Opcode Fuzzy Hash: 5ecb9aca37cfa74a852660f22e24977ddf5ffe3d9d8c212dab6545ea967c75f3
                                                        • Instruction Fuzzy Hash: 0A313071504A498FEB98DF18C5C8BA177E1FF14325F2012AAD95ECF2E6D7789881CB90

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 92 1d97cc4185c-1d97cc4188c call 1d97cc408a4 * 2 97 1d97cc41940-1d97cc41947 92->97 98 1d97cc41892-1d97cc41895 92->98 98->97 99 1d97cc4189b-1d97cc418a5 98->99 99->97 100 1d97cc418ab-1d97cc418b0 99->100 100->97 101 1d97cc418b6-1d97cc418c3 100->101 101->97 102 1d97cc418c5-1d97cc418cd 101->102 102->97 103 1d97cc418cf-1d97cc418da 102->103 103->97 104 1d97cc418dc-1d97cc418e3 103->104 104->97 105 1d97cc418e5-1d97cc418e8 104->105 105->97 106 1d97cc418ea-1d97cc418f2 105->106 106->97 107 1d97cc418f4-1d97cc418f7 106->107 107->97 108 1d97cc418f9-1d97cc41902 107->108 108->97 109 1d97cc41904-1d97cc41908 108->109 109->97 110 1d97cc4190a-1d97cc4191a 109->110 110->97 112 1d97cc4191c-1d97cc41933 GetProcessMitigationPolicy 110->112 112->97 113 1d97cc41935-1d97cc4193a 112->113 113->97 114 1d97cc4193c-1d97cc4193d 113->114 114->97
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: MitigationPolicyProcess
                                                        • String ID:
                                                        • API String ID: 1088084561-0
                                                        • Opcode ID: 04359cd7b97b11c476e8c0617afcaa098c35e265ec660168a6fbd24c0647ca60
                                                        • Instruction ID: caad6b25f9e325ef01d1ead65d29c2fdb1c1677196f408e1d067fc154b71304e
                                                        • Opcode Fuzzy Hash: 04359cd7b97b11c476e8c0617afcaa098c35e265ec660168a6fbd24c0647ca60
                                                        • Instruction Fuzzy Hash: 23310730128A467AFB65F76A88847E177D1EBE43A0F2C89BBC481C61D2DE71CA41CF40
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 3a75ac4bc0ef9b92f46b283ccd4d50aa8e5ba4e277f879feac89481dd4401175
                                                        • Instruction ID: 20e86b4ade0e5ab3c89aaa679cb4181effec387a2304a5e197d849dd658ed8c9
                                                        • Opcode Fuzzy Hash: 3a75ac4bc0ef9b92f46b283ccd4d50aa8e5ba4e277f879feac89481dd4401175
                                                        • Instruction Fuzzy Hash: 7BC17030918A888FDB95DF2888C4BD677F0FF54300F6445BAD98ECB19BC624D895C761
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: ResumeThread
                                                        • String ID:
                                                        • API String ID: 947044025-0
                                                        • Opcode ID: a1e79bfd5fdfa4d599be838d72d64bf9e685b5698f2b0b05ab8498b458f49234
                                                        • Instruction ID: 1530464547348a5d463ff2800a5ef1d981865d6b68adb1be6b8ab2e25102814b
                                                        • Opcode Fuzzy Hash: a1e79bfd5fdfa4d599be838d72d64bf9e685b5698f2b0b05ab8498b458f49234
                                                        • Instruction Fuzzy Hash: E701D631B149198FEB94EB69DC8867633E5FF893517240476E80FD7254DA3DAC42C790
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: DestroyHeap
                                                        • String ID:
                                                        • API String ID: 2435110975-0
                                                        • Opcode ID: e8b38785987ebe4bf97a71b2e294a612045f12fa57e0274daf3e7e500e703184
                                                        • Instruction ID: a955fbecdf812f32147cbb06bf747ef9223102b0e933020d2715ab6519874f37
                                                        • Opcode Fuzzy Hash: e8b38785987ebe4bf97a71b2e294a612045f12fa57e0274daf3e7e500e703184
                                                        • Instruction Fuzzy Hash: C8011D70E09B55CFEB54AF69FD8616637B1EB98311754413FE10EC7A60CA3C5880C761
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: CreateHeap
                                                        • String ID:
                                                        • API String ID: 10892065-0
                                                        • Opcode ID: f6a5c260a6ff26826b95901847e0f94daf167b208f970919ab6999429e88efbf
                                                        • Instruction ID: cce22606589f7affb5ca1d8cb25db89b96e82de5f19e573d075cf6a6e0e8e112
                                                        • Opcode Fuzzy Hash: f6a5c260a6ff26826b95901847e0f94daf167b208f970919ab6999429e88efbf
                                                        • Instruction Fuzzy Hash: C0F0A761F18A468FE7207F755D812A763629B84311F34493FEA0FDA285DC3D94818660
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: setsockopt
                                                        • String ID:
                                                        • API String ID: 3981526788-0
                                                        • Opcode ID: ddedd6023ad442b8d2b2fe3290ed3783bcd232237776f9c3a295af58d00cf6c3
                                                        • Instruction ID: 9296305bd7148812721086f50b5c9920ef41fd92fed031c36ad4861ef50d0d14
                                                        • Opcode Fuzzy Hash: ddedd6023ad442b8d2b2fe3290ed3783bcd232237776f9c3a295af58d00cf6c3
                                                        • Instruction Fuzzy Hash: B8F08274104A084FEB48EF5CC48876677E2FFA8315F100169E90DC72E4D7359949C751
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: AddressCallerProc
                                                        • String ID:
                                                        • API String ID: 2663294120-0
                                                        • Opcode ID: c2543c20c0a7d110227d86949c13dfaa5e54e54e664fb098b1aa0bdcf88303a9
                                                        • Instruction ID: 98d3df35fb548cbf2bb3d44476b4dd4f20dc1a10d0b67bcb0e436da733f369d4
                                                        • Opcode Fuzzy Hash: c2543c20c0a7d110227d86949c13dfaa5e54e54e664fb098b1aa0bdcf88303a9
                                                        • Instruction Fuzzy Hash: 32E0C211F18C0D0B6B6862AE288CAB752D6CBDC13331402BBE51EC3395EC18CC850390
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: FilePointer
                                                        • String ID:
                                                        • API String ID: 973152223-0
                                                        • Opcode ID: 23f3765db31a0df280e37a6bc4f8137308a1fee0486dc2818908f898aea27d2f
                                                        • Instruction ID: c076b59af0e72806b2472201f695b54bc63e28b6ed3703abb36710452691a838
                                                        • Opcode Fuzzy Hash: 23f3765db31a0df280e37a6bc4f8137308a1fee0486dc2818908f898aea27d2f
                                                        • Instruction Fuzzy Hash: ADE0C232B150240BF72C6ABD2C8917A36DAC7CC572705423BF80AC3284ED7C8C4602D1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: FunctionTable
                                                        • String ID:
                                                        • API String ID: 1252446317-0
                                                        • Opcode ID: 3b09555bf32cd7a482aca5e21dc4f37ab037edd0c1b9afc7390cc3b8e22e33b4
                                                        • Instruction ID: 2d4877ada3e81689adf89f8be6c0467802656cbd0fc9e0bc89a9032522b822f8
                                                        • Opcode Fuzzy Hash: 3b09555bf32cd7a482aca5e21dc4f37ab037edd0c1b9afc7390cc3b8e22e33b4
                                                        • Instruction Fuzzy Hash: DAE04F306509058BEBA8E61DC9493903BE0FB58306F64426DDA05C9291CB3DD89BCF81
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: LibraryLoad
                                                        • String ID:
                                                        • API String ID: 1029625771-0
                                                        • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                                        • Instruction ID: 67300f96fb859b42ebe22121225dcd4423ea9f510f2aaf203e6f296c38a948ea
                                                        • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                                        • Instruction Fuzzy Hash: 05D05E20B24D0D1BEA48622D1C94B661295EBC8621B64013BE50AC2281DD5CCC550211
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: calloc
                                                        • String ID:
                                                        • API String ID: 2635317215-0
                                                        • Opcode ID: 2479110834a0a50aa720895a2966e0087a87a39eabe9dff41225e0602a7593e9
                                                        • Instruction ID: a25b6a5f893d165ac258e399cfb4bb3329b4780f5ab694505e69845ebce3c47d
                                                        • Opcode Fuzzy Hash: 2479110834a0a50aa720895a2966e0087a87a39eabe9dff41225e0602a7593e9
                                                        • Instruction Fuzzy Hash: CB818330A1CE488FDB54EF18D9859A673E1FF98700B61427AD54FC7296DA38E841CBD1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 903acddc3c2cbd21899d181af60d2020bd4c0d22b9f6ec9809e98e44769c02c6
                                                        • Instruction ID: cd8d9009139aac14d6bc047bda0f2311fa6b0222748f5bec1dcd055d7063c806
                                                        • Opcode Fuzzy Hash: 903acddc3c2cbd21899d181af60d2020bd4c0d22b9f6ec9809e98e44769c02c6
                                                        • Instruction Fuzzy Hash: 56413031618E488FEB94EB18C585EE6B3E1FF98310F644266D54EC7296DA38F841CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: c3b5330ba83a094f7bad87bbcfda8b7898b28b22e9f53235a9dbd9f71cfcc7c9
                                                        • Instruction ID: 4f2b265f0e30bb6005095ee776ad191192dd821ca5938c956c88d3aa0dc56bb6
                                                        • Opcode Fuzzy Hash: c3b5330ba83a094f7bad87bbcfda8b7898b28b22e9f53235a9dbd9f71cfcc7c9
                                                        • Instruction Fuzzy Hash: 6441EB30F048588BEB68DE698DD40BB37E1EF85305724417BD96BCB646DA2CE946C7E0
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: db34f96bb32c5808d121ed52c15c20ade07964c9e34a55c401bc0086a79692f1
                                                        • Instruction ID: 7c1a18aababa8536e152663fc9781b3249afea0eede703105f8629968c51209f
                                                        • Opcode Fuzzy Hash: db34f96bb32c5808d121ed52c15c20ade07964c9e34a55c401bc0086a79692f1
                                                        • Instruction Fuzzy Hash: EC310720A18E8D4BFB989B2C89157E677F0FF85350F24417AD95FC7186DA18E8568360
                                                        APIs
                                                        • malloc.MSVCRT(?,?,?,?,?,FFFFFFFF,-00000001,-00000002,-00000001,00007DF41C322CFA), ref: 00007DF41C303867
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: aa4f1f029a65678ad9f3ad1f83a567308f2cd0838b93955c777e9bc3ae762b5b
                                                        • Instruction ID: ab6513cb10dabe08119f92def1dbada214cc41b23db1922a13de78d60d3cc4cc
                                                        • Opcode Fuzzy Hash: aa4f1f029a65678ad9f3ad1f83a567308f2cd0838b93955c777e9bc3ae762b5b
                                                        • Instruction Fuzzy Hash: F5219031614D1C8FDB59EF1CDC8CBA277E1FB6831271442ABD80ACB265DA35E888C791
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: lstrcmpi
                                                        • String ID:
                                                        • API String ID: 1586166983-0
                                                        • Opcode ID: dd3043cd4fdbf6ce1bec2523c8a3e90b76413ae5d3024df9cc9149889a1f6f13
                                                        • Instruction ID: 9b0c08e7306d4d054a69a868f89156ba111b97dd10cd4ca64d199160b2d6ec15
                                                        • Opcode Fuzzy Hash: dd3043cd4fdbf6ce1bec2523c8a3e90b76413ae5d3024df9cc9149889a1f6f13
                                                        • Instruction Fuzzy Hash: D211B931F14D8D5BFB5CAB389D592F736E2FF94700B640236D90FC62A9EE2CA9448650
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 75680fa04e19e4440b4640af9aa4d4391f4b0436c9268b337d289e293cb6ea92
                                                        • Instruction ID: 18024cc85a5391f16117ed0f158a49426b5d3c3b94133c6651f8fc904562fd29
                                                        • Opcode Fuzzy Hash: 75680fa04e19e4440b4640af9aa4d4391f4b0436c9268b337d289e293cb6ea92
                                                        • Instruction Fuzzy Hash: 1101FB30604D4C8FDF84EB1CD4D4E5573E5EB68310B2405A6D40ECB255CA79EC828B50
                                                        APIs
                                                        • malloc.MSVCRT(?,?,?,?,-00000001,?,-00000001,00007DF41C2E65CE), ref: 00007DF41C2E6585
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: 051b47b6163c57a56397831363f2f208832c5eccc5cbea97d62df897e1ee0233
                                                        • Instruction ID: 0938f985a43c6a063b6e35951023ef370bd67973ae9559d71369da019bee4256
                                                        • Opcode Fuzzy Hash: 051b47b6163c57a56397831363f2f208832c5eccc5cbea97d62df897e1ee0233
                                                        • Instruction Fuzzy Hash: 2C01D630B04E0A9BE3689B29D888362B3E1FB98311F14413AD419C3384DB38E890C7D0
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: FreeVirtual
                                                        • String ID:
                                                        • API String ID: 1263568516-0
                                                        • Opcode ID: 85f62002f11eda201487085593c698b0135f5f3e41b5990a1ae8dfcda2a01f33
                                                        • Instruction ID: 70c3b426b54cda9c9b263dc55a83bcad9f55dff75b84f88f3c7ff55680029aaf
                                                        • Opcode Fuzzy Hash: 85f62002f11eda201487085593c698b0135f5f3e41b5990a1ae8dfcda2a01f33
                                                        • Instruction Fuzzy Hash: 61016230F18E498FEB5CDB2C8E6426133E1FB59315764816AD00FD63E4EA2DE842C711
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: e005b8aad8ae59e5c4306d33e7cf4f806ca0153c9240256dc9db618efce1777c
                                                        • Instruction ID: f81d1e304a4d39a6b75fcb9274b69e28f7640ee925cb9630b0fe7fe1c541ea1f
                                                        • Opcode Fuzzy Hash: e005b8aad8ae59e5c4306d33e7cf4f806ca0153c9240256dc9db618efce1777c
                                                        • Instruction Fuzzy Hash: A8F0FF3061BE0E8BFF5CABA5DD98A6A3BB1EF14306B14103FD90BD15A0CB6D98549721

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 123 1d97cc419a0-1d97cc419bd 125 1d97cc419bf-1d97cc419c6 123->125 126 1d97cc419c9-1d97cc419d0 123->126 125->126 127 1d97cc419e7-1d97cc419f5 126->127 128 1d97cc419d2-1d97cc419e5 VirtualFree 126->128 128->127
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: FreeVirtual
                                                        • String ID:
                                                        • API String ID: 1263568516-0
                                                        • Opcode ID: 68a2bebb63dec11ebeb4fbf40c1c95563ebbd08489d40e2effbc7ec76ba53b27
                                                        • Instruction ID: 12ef11a1d81ebb7826645c81f01546ce42001ab4dd5adb2926444a1cad0beebb
                                                        • Opcode Fuzzy Hash: 68a2bebb63dec11ebeb4fbf40c1c95563ebbd08489d40e2effbc7ec76ba53b27
                                                        • Instruction Fuzzy Hash: F4F03031214A098FDF9CEF95C4D5EE137A4EB28301F14457ACC4ACB156DA21D985CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: 4c39f900df3972edeb9c523e4745635d2babc99cae264e1317ea5b764d4d565e
                                                        • Instruction ID: 77a33029f327320db183e26d3168276c119541292ee3bc548cf45d0e64eddaaa
                                                        • Opcode Fuzzy Hash: 4c39f900df3972edeb9c523e4745635d2babc99cae264e1317ea5b764d4d565e
                                                        • Instruction Fuzzy Hash: 83D05E11B15E0D0FAB58A27E1D9E56A22D6D7D81227940537B90AC2250ED29CC558261
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 38b5563491cec97da23afbec1dbe8fd433f77e7ca0be4d4ad2848afd0e677fff
                                                        • Instruction ID: 77f63dd550acc1a27a3a9be0f7c74893b2d3810658c508574a6198593bf1ca58
                                                        • Opcode Fuzzy Hash: 38b5563491cec97da23afbec1dbe8fd433f77e7ca0be4d4ad2848afd0e677fff
                                                        • Instruction Fuzzy Hash: 62E08C30525D0D8EEF88AB388E49B9332E0FB08B01FA40869D00AC31D0D72CD490C711
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: f40fb4788220d337bb008d16cea7b0a0ee6a5daf6a138a5e0a6bf71422f7da42
                                                        • Instruction ID: f69f651ce9fb2a63429de5c95c094f42236e8473c236e3801bac4d9e86bea528
                                                        • Opcode Fuzzy Hash: f40fb4788220d337bb008d16cea7b0a0ee6a5daf6a138a5e0a6bf71422f7da42
                                                        • Instruction Fuzzy Hash: 0ED05E34B06E4E8BFF9CA6BA89AC57623A1EF58203718107DD50BD1AA0CA5DD8409311
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: 7aac0fcb7c972547ff5d390886f6270a0f974cec2218a33fb889b5e6a18d3d37
                                                        • Instruction ID: c5f0b511ffcdd0db2e1d1ba270ca8cbb8b5f1f71ed0dfb5a94b4bc751638d85b
                                                        • Opcode Fuzzy Hash: 7aac0fcb7c972547ff5d390886f6270a0f974cec2218a33fb889b5e6a18d3d37
                                                        • Instruction Fuzzy Hash: A1D01260B05D094B7B5076FB1DCD1792A94D7282027100022E919C0660E908C894D351
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: b7031c71d370f0c4b9d1add862bc0dfec61c612abdfff09cb5e9d61695c69b58
                                                        • Instruction ID: 91a6cae47af2a3ac07ba65e0eb943f02086a93d5951ef76d460a3e0e3adffdc9
                                                        • Opcode Fuzzy Hash: b7031c71d370f0c4b9d1add862bc0dfec61c612abdfff09cb5e9d61695c69b58
                                                        • Instruction Fuzzy Hash: B7B0922489AD4A42ED0832764E991992A60AB14201FC500259806C0154E50E809A42A6
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 551c0ffc82b28a3876ee79cfc9de3840c8837f1e4274ad0e5daf9a8a7b3ff23c
                                                        • Instruction ID: 404f7b5f25c7a1682fd6117a52f51a728b550125061c2cbeabb6e3099024c092
                                                        • Opcode Fuzzy Hash: 551c0ffc82b28a3876ee79cfc9de3840c8837f1e4274ad0e5daf9a8a7b3ff23c
                                                        • Instruction Fuzzy Hash: 27B01224E27C4F43ED4C37B70F690693760AF18212FD40015EC0AD0A54E55CC494A35A
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000003.2576205493.00007DF41C2E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF41C2E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_3_7df41c2e1000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID:
                                                        • API String ID:
                                                        • Opcode ID: 46f5df41ea43a57528ce76f95f617c5d60ae02f95908509022172248d9e28bd8
                                                        • Instruction ID: 317b8491c6c81d94af8fc2b3a06f72133790875556e8c436f9feff669d1d81d5
                                                        • Opcode Fuzzy Hash: 46f5df41ea43a57528ce76f95f617c5d60ae02f95908509022172248d9e28bd8
                                                        • Instruction Fuzzy Hash: FFB01130E28808C2C2280E0AF802330F2B0C30B300F00303A2000F3A20C8BACC82008F
                                                        Memory Dump Source
                                                        • Source File: 00000002.00000002.2576552726.000001D97CC40000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001D97CC40000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_2_2_1d97cc40000_OpenWith.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID:
                                                        • API String ID:
                                                        • Opcode ID: d522c07823fb8778296108337a3d1ec347010d1dae431256f70b68abef76ec51
                                                        • Instruction ID: 9c6f723353de5f7bfac1b68b00d860ec9f8fa9508ac40f659eae0282c9a534f1
                                                        • Opcode Fuzzy Hash: d522c07823fb8778296108337a3d1ec347010d1dae431256f70b68abef76ec51
                                                        • Instruction Fuzzy Hash: 26B01132E28A0082E3880E0AB8023B0F2B0C30B300F00B0322008F3220C828CC08028F

                                                        Execution Graph

                                                        Execution Coverage:5.2%
                                                        Dynamic/Decrypted Code Coverage:14.9%
                                                        Signature Coverage:0%
                                                        Total number of Nodes:282
                                                        Total number of Limit Nodes:28
                                                        execution_graph 22451 195528e2904 22452 195528e2957 22451->22452 22453 195528e2916 22451->22453 22453->22452 22454 195528e2939 ResumeThread 22453->22454 22454->22453 22468 195528e697c 22469 195528e6998 22468->22469 22470 195528e699d GetProcAddressForCaller 22469->22470 22471 195528e69a6 22469->22471 22470->22471 22489 195528ebe7c 22490 195528ebea5 22489->22490 22491 195528ebeb5 22490->22491 22492 195528ebed3 LoadLibraryA 22490->22492 22492->22491 22785 195528ecd54 CreateNamedPipeW BindIoCompletionCallback ConnectNamedPipe NtAcceptConnectPort 22653 7df4c3613018 22654 7df4c361304b 22653->22654 22662 7df4c3613213 22654->22662 22663 7df4c3611708 22654->22663 22658 7df4c3613130 calloc 22660 7df4c3613085 22658->22660 22659 7df4c361318a 22661 7df4c36131e7 SendMessageA 22659->22661 22660->22658 22660->22659 22660->22662 22661->22662 22664 7df4c3611715 22663->22664 22665 7df4c361173b 22663->22665 22664->22665 22666 7df4c361171b RtlAddFunctionTable 22664->22666 22667 7df4c3611740 22665->22667 22666->22665 22668 7df4c3611760 VirtualProtect 22667->22668 22670 7df4c361176f 22667->22670 22668->22670 22669 7df4c361180d 22669->22660 22670->22669 22671 7df4c36117e9 VirtualProtect 22670->22671 22671->22670 22787 195528f12d0 16 API calls 22672 195528e5110 22685 195528f252c 22672->22685 22674 195528e5328 22675 195528e5169 22675->22674 22676 195528e531b 22675->22676 22688 195528f28b8 22675->22688 22697 195528f2418 22676->22697 22683 195528f28b8 NtAcceptConnectPort 22684 195528e52a6 22683->22684 22694 195528f28e8 22684->22694 22686 195528f2551 22685->22686 22687 195528f253c NtAcceptConnectPort 22685->22687 22686->22675 22687->22686 22689 195528e51f8 22688->22689 22690 195528f28c8 NtAcceptConnectPort 22688->22690 22689->22676 22691 195528f27b8 22689->22691 22690->22689 22692 195528e5244 22691->22692 22693 195528f27cb NtAcceptConnectPort 22691->22693 22692->22683 22692->22684 22693->22692 22695 195528f28fc 22694->22695 22696 195528f28f8 NtAcceptConnectPort 22694->22696 22695->22676 22696->22695 22698 195528f2428 NtAcceptConnectPort 22697->22698 22699 195528f242c 22697->22699 22698->22699 22699->22674 22700 195528e6950 22701 195528e696a 22700->22701 22702 195528e6974 22701->22702 22703 195528e696f LoadLibraryA 22701->22703 22703->22702 22704 195528eccd0 22705 195528ecce3 22704->22705 22709 195528ecd39 22704->22709 22710 195528ea76c 22705->22710 22707 195528eccf5 22708 195528ecd18 ReadFile 22707->22708 22708->22709 22711 195528ea78c 22710->22711 22713 195528ea7d3 22710->22713 22712 195528ea7f7 malloc 22711->22712 22711->22713 22712->22713 22713->22707 22800 195528e58d0 30 API calls 22714 195528f288c 22715 195528f289c NtAcceptConnectPort 22714->22715 22716 195528f28ab 22714->22716 22715->22716 22717 195528eca8c 22718 195528ecaaa 22717->22718 22731 195528ecb24 22717->22731 22719 195528ecc4f 22718->22719 22720 195528ecad0 22718->22720 22718->22731 22722 195528ea76c malloc 22719->22722 22721 195528ecc1e 22720->22721 22725 195528ecae7 22720->22725 22723 195528ea76c malloc 22721->22723 22724 195528ecc32 22722->22724 22723->22724 22728 195528ecc83 ReadFile 22724->22728 22726 195528ecbdd 22725->22726 22727 195528ecb1b 22725->22727 22725->22731 22744 195528ebbf0 22726->22744 22727->22731 22732 195528ec784 22727->22732 22728->22731 22733 195528eca56 22732->22733 22737 195528ec7be 22732->22737 22733->22731 22734 195528eca3f 22735 195528ea960 2 API calls 22734->22735 22735->22733 22736 195528ec9ba free 22738 195528ec9c5 22736->22738 22737->22733 22737->22736 22737->22738 22740 195528ec9b2 22737->22740 22751 195528fe0c8 free free 22737->22751 22752 195528fd4ac 22737->22752 22738->22734 22758 195528ec25c 22738->22758 22762 195528fdc78 free free 22740->22762 22745 195528ebc1e 22744->22745 22746 195528ebcec 22744->22746 22745->22746 22747 195528ebc41 OpenFileMappingW 22745->22747 22746->22731 22747->22746 22748 195528ebc5e MapViewOfFile 22747->22748 22749 195528ebce3 CloseHandle 22748->22749 22750 195528ebc7c 22748->22750 22749->22746 22750->22749 22751->22737 22753 195528fd4c5 22752->22753 22756 195528fd4be 22752->22756 22754 195528fd4fe free 22753->22754 22755 195528fd504 22753->22755 22753->22756 22754->22755 22755->22756 22763 19552924468 22755->22763 22756->22737 22759 195528ec2a1 22758->22759 22761 195528ec66e 22758->22761 22760 195528ec5ba VirtualAlloc 22759->22760 22759->22761 22760->22761 22761->22734 22762->22736 22764 195529244af 22763->22764 22765 19552924476 22763->22765 22764->22756 22765->22764 22766 19552924498 free 22765->22766 22766->22764 22767 7df4c3612f60 22768 7df4c3612f6d 22767->22768 22770 7df4c3612fdc 22767->22770 22769 7df4c3612fa3 SetWinEventHook 22768->22769 22768->22770 22769->22770 22780 195528edde4 GetSystemInfo VirtualAlloc 22455 195528f7da0 SetErrorMode 22456 195528f7db4 22455->22456 22457 195528fb216 socket 22456->22457 22458 195528fb25a getsockopt 22457->22458 22459 195528fb2a3 socket 22457->22459 22458->22459 22461 195528fb2c3 22459->22461 22781 195528e6ddf free free 22462 195528e74a0 22466 195528e74d8 22462->22466 22464 195528e7732 22465 195528e7573 VirtualFree 22465->22466 22466->22464 22466->22465 22467 195528e73c4 free free 22466->22467 22467->22466 22472 7df4c36222cc 22474 7df4c36222ee 22472->22474 22473 7df4c362276d 22474->22473 22480 7df4c3621290 22474->22480 22478 7df4c3622329 22478->22473 22479 7df4c3622754 SetTimer 22478->22479 22479->22473 22481 7df4c362129d 22480->22481 22482 7df4c36212c3 22480->22482 22481->22482 22483 7df4c36212a3 RtlAddFunctionTable 22481->22483 22484 7df4c36212c8 22482->22484 22483->22482 22485 7df4c36212e8 VirtualProtect 22484->22485 22487 7df4c36212f7 22484->22487 22485->22487 22486 7df4c3621395 22486->22478 22487->22486 22488 7df4c3621371 VirtualProtect 22487->22488 22488->22487 22782 195528e2ddc 6 API calls 22493 7df4c3612ed0 22494 7df4c3612ee6 22493->22494 22496 7df4c3612f16 22494->22496 22497 7df4c3612704 NtQuerySystemInformation 22494->22497 22498 7df4c3612727 22497->22498 22499 7df4c361272d malloc 22497->22499 22498->22499 22500 7df4c361275f 22499->22500 22501 7df4c3612743 NtQuerySystemInformation 22499->22501 22500->22496 22501->22500 22502 195528e58d8 22505 195528e6c10 22502->22505 22504 195528e58ea 22506 195528e6c19 22505->22506 22513 195528e6cfc 22505->22513 22506->22513 22516 195528f2d24 22506->22516 22508 195528e6cae 22508->22513 22524 195528e3c84 22508->22524 22510 195528e6cba 22511 195528e6cd1 SetErrorMode 22510->22511 22512 195528e6cea 22511->22512 22515 195528e6d14 22511->22515 22512->22513 22528 195528e69b0 22512->22528 22513->22504 22515->22504 22521 195528f2d71 22516->22521 22517 195528f3db2 22517->22508 22518 195528f3866 RtlFormatCurrentUserKeyPath 22519 195528f3872 22518->22519 22519->22517 22520 195528f39b7 calloc 22519->22520 22520->22517 22522 195528f39dd 22520->22522 22521->22517 22521->22518 22521->22519 22522->22517 22544 195528e55f0 6 API calls 22522->22544 22525 195528e3c91 22524->22525 22526 195528e3cb7 22524->22526 22525->22526 22527 195528e3c97 RtlAddFunctionTable 22525->22527 22526->22510 22527->22526 22529 195528e69b9 22528->22529 22532 195528e6a18 22528->22532 22530 195528e6a75 22529->22530 22533 195528e69e5 22529->22533 22568 195528f0bd0 16 API calls 22530->22568 22532->22513 22533->22532 22534 195528e6a41 22533->22534 22535 195528e69f9 22533->22535 22567 195528f11e8 13 API calls 22534->22567 22537 195528e6a34 22535->22537 22538 195528e69fe 22535->22538 22566 195528f0cf0 16 API calls 22537->22566 22539 195528e6a03 22538->22539 22540 195528e6a27 22538->22540 22539->22532 22545 195528ed594 22539->22545 22565 195528f0e18 18 API calls 22540->22565 22544->22517 22546 195528ed5aa 22545->22546 22547 195528ed629 CloseHandle 22546->22547 22548 195528ed5c5 MapViewOfFile 22546->22548 22549 195528ed6db 22547->22549 22550 195528ed63b 22547->22550 22555 195528ed5ef 22548->22555 22590 195528ea960 22549->22590 22550->22549 22569 195528e2b50 22550->22569 22554 195528ed64b 22554->22549 22573 195528edfc4 22554->22573 22555->22547 22559 195528ed65d 22582 195528ed188 6 API calls 22559->22582 22561 195528ed662 22583 195528e7950 22561->22583 22563 195528ed697 22589 195528e2ba4 6 API calls 22563->22589 22565->22532 22566->22532 22567->22532 22568->22532 22570 195528e2b60 22569->22570 22571 195528e2b69 HeapCreate 22570->22571 22572 195528e2b82 22570->22572 22571->22572 22572->22554 22574 195528edfdc 22573->22574 22575 195528ee026 22574->22575 22595 195528e2c20 22574->22595 22576 195528ee033 VirtualProtect 22575->22576 22577 195528ed658 22575->22577 22599 195528e1000 22576->22599 22581 195528edef8 GetSystemInfo VirtualAlloc 22577->22581 22580 195528ee060 VirtualProtect 22580->22577 22581->22559 22582->22561 22587 195528e797b 22583->22587 22584 195528e7bd3 22584->22563 22585 195528e7b21 22586 195528ea960 2 API calls 22585->22586 22586->22584 22587->22584 22587->22585 22608 195528e778c 22587->22608 22589->22549 22591 195528ea973 free 22590->22591 22592 195528ea984 22590->22592 22591->22591 22591->22592 22593 195528ea9a3 22592->22593 22594 195528ea98e free 22592->22594 22593->22532 22594->22593 22594->22594 22596 195528e2c4e 22595->22596 22598 195528e2cb8 22596->22598 22601 195528e24c0 22596->22601 22598->22575 22600 195528e100c 22599->22600 22600->22580 22604 195528e22d0 GetSystemInfo 22601->22604 22605 195528e2301 22604->22605 22606 195528e23a0 VirtualAlloc 22605->22606 22607 195528e23cb 22605->22607 22606->22605 22606->22607 22607->22598 22609 195528e77b4 22608->22609 22616 195528f2c64 22609->22616 22611 195528e77dd 22613 195528e7829 22611->22613 22620 195528f29d4 22611->22620 22614 195528e786b GetVolumeInformationW 22613->22614 22615 195528e78bc 22613->22615 22614->22615 22615->22585 22617 195528f2c87 22616->22617 22619 195528f2c7f 22616->22619 22618 195528f2ce8 NtAcceptConnectPort 22617->22618 22617->22619 22618->22619 22619->22611 22621 195528f2a1d 22620->22621 22622 195528f2a73 NtAcceptConnectPort 22621->22622 22623 195528f2a27 22621->22623 22622->22623 22623->22613 22793 195528e6bd8 NtAcceptConnectPort 22624 195528ecdf4 22625 195528ece47 22624->22625 22632 195528eae7c 22625->22632 22627 195528ece6f CreateNamedPipeW 22628 195528eceb7 22627->22628 22631 195528ecef9 22627->22631 22629 195528eced0 BindIoCompletionCallback 22628->22629 22630 195528ecee8 ConnectNamedPipe 22629->22630 22629->22631 22630->22631 22633 195528eaeb8 22632->22633 22636 195528f2990 22633->22636 22635 195528eaec0 22635->22627 22637 195528f29a4 NtAcceptConnectPort 22636->22637 22638 195528f29be 22636->22638 22637->22638 22638->22635 22639 195528e2974 22640 195528e29a2 VirtualProtect 22639->22640 22641 195528e299a 22639->22641 22643 195528e29c7 22640->22643 22644 195528e29bd 22640->22644 22641->22640 22642 195528e2a09 VirtualProtect 22642->22644 22643->22642 22645 195528ebbb4 22646 195528ebbe2 22645->22646 22647 195528ebbb9 22645->22647 22649 195528eb9d8 22647->22649 22650 195528eb9f9 22649->22650 22651 195528ebad0 CreateWindowExW 22650->22651 22652 195528ebb2d 22650->22652 22651->22652 22652->22646 22789 195528ed6f0 malloc 22771 195528e2628 22773 195528e265b 22771->22773 22772 195528e288a 22774 195528e267c Thread32First 22773->22774 22778 195528e2734 22773->22778 22777 195528e2681 22774->22777 22775 195528e276d SuspendThread 22775->22778 22776 195528e272b CloseHandle 22776->22778 22777->22776 22778->22772 22778->22775
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2514012192.00007DF4C3601000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3601000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_7df4c3601000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: MemoryVirtual$Read$Protect$Write$AllocateInformationProcessQuerycalloc
                                                        • String ID: H$H
                                                        • API String ID: 874015164-136785262
                                                        • Opcode ID: 8b723a4ddad616be20f9dda8abf44bc9042e1d61a48c0cd72079f3722cd3507a
                                                        • Instruction ID: d10527c9833c5f3ae680327788c2bb8f175cf386ad3324c19b86457ee10e84b9
                                                        • Opcode Fuzzy Hash: 8b723a4ddad616be20f9dda8abf44bc9042e1d61a48c0cd72079f3722cd3507a
                                                        • Instruction Fuzzy Hash: BFB1437060CB888FD764DF18D895AAAB7E5FBD5304F001A2EE5CBC3251DB38E5458B86

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 0 195528f2d24-195528f2d80 call 195528e4998 3 195528f3dc7-195528f3ded call 195528f4500 0->3 4 195528f2d86-195528f2de7 call 195528e6da4 * 3 call 195528e32f8 call 195528e6da4 0->4 18 195528f3db4-195528f3db5 4->18 19 195528f2ded-195528f3700 4->19 22 195528f3db9-195528f3dc2 call 195528e49f4 18->22 20 195528f3706-195528f3711 19->20 21 195528f3855-195528f385d 19->21 20->21 25 195528f3717-195528f3725 20->25 23 195528f38d0-195528f38e1 21->23 24 195528f385f-195528f3864 21->24 22->3 27 195528f38e3-195528f38fb 23->27 28 195528f393a-195528f3940 23->28 24->23 29 195528f3866-195528f3870 RtlFormatCurrentUserKeyPath 24->29 30 195528f3850-195528f3851 25->30 31 195528f372b-195528f3733 25->31 27->28 44 195528f38fd-195528f3905 27->44 34 195528f3942-195528f3943 28->34 35 195528f396b-195528f397e 28->35 29->23 33 195528f3872-195528f3883 29->33 30->21 31->30 36 195528f3739-195528f3751 31->36 38 195528f389e-195528f38a6 33->38 39 195528f3885-195528f3891 33->39 40 195528f3945-195528f3964 34->40 35->18 54 195528f3984-195528f398f 35->54 41 195528f3844-195528f3848 36->41 42 195528f3757-195528f3758 36->42 45 195528f38a8-195528f38c4 call 195528e1000 38->45 57 195528f3893-195528f389c 39->57 58 195528f38c7-195528f38c8 39->58 40->40 46 195528f3966-195528f3967 40->46 43 195528f384a-195528f384b 41->43 47 195528f375b-195528f376b 42->47 43->30 49 195528f3917 44->49 50 195528f3907-195528f3915 44->50 45->58 46->35 53 195528f377d-195528f377f 47->53 49->28 56 195528f3919-195528f3934 49->56 50->28 60 195528f3781-195528f3786 53->60 61 195528f376d-195528f377b 53->61 54->18 55 195528f3995-195528f39a3 54->55 55->18 62 195528f39a9-195528f39b1 55->62 56->28 57->45 58->23 63 195528f3811-195528f3814 60->63 64 195528f378c 60->64 61->53 62->18 66 195528f39b7-195528f39d7 calloc 62->66 67 195528f3821-195528f3830 63->67 68 195528f3816-195528f381a 63->68 65 195528f378e-195528f3795 64->65 69 195528f37af-195528f37db 65->69 70 195528f3797-195528f37ab 65->70 66->18 71 195528f39dd-195528f3a01 66->71 67->47 73 195528f3836-195528f3842 67->73 68->67 72 195528f381c-195528f381d 68->72 75 195528f3803-195528f3804 69->75 76 195528f37dd-195528f37f1 call 195528f452c 69->76 70->65 74 195528f37ad 70->74 77 195528f3b20-195528f3b5b 71->77 78 195528f3a07-195528f3a1a 71->78 72->67 73->43 74->63 81 195528f3809-195528f380a 75->81 76->75 86 195528f37f3-195528f3801 76->86 89 195528f3bb3-195528f3bc3 77->89 90 195528f3b5d-195528f3b5e 77->90 80 195528f3a1c-195528f3a26 78->80 83 195528f3af1-195528f3b03 80->83 84 195528f3a2c-195528f3a30 80->84 81->63 83->80 87 195528f3b09-195528f3b1e 83->87 84->83 88 195528f3a36-195528f3a80 call 195528f4540 84->88 86->81 87->77 99 195528f3a94-195528f3a96 88->99 89->18 98 195528f3bc9-195528f3bdf 89->98 92 195528f3b60-195528f3b68 90->92 95 195528f3b6a-195528f3b6f 92->95 96 195528f3b95-195528f3ba9 92->96 95->96 100 195528f3b71-195528f3b7a 95->100 96->92 97 195528f3bab-195528f3bac 96->97 97->89 101 195528f3be1-195528f3be2 98->101 102 195528f3c55-195528f3c5b 98->102 103 195528f3a82-195528f3a92 99->103 104 195528f3a98-195528f3aae 99->104 105 195528f3b7d-195528f3b80 100->105 110 195528f3be4-195528f3bef 101->110 108 195528f3cae-195528f3cb5 102->108 109 195528f3c5d-195528f3c61 102->109 103->99 111 195528f3ab0-195528f3ab8 104->111 112 195528f3aed 104->112 106 195528f3b82 105->106 107 195528f3b89-195528f3b93 105->107 106->107 107->96 107->105 116 195528f3d62-195528f3d64 108->116 117 195528f3cbb-195528f3cdb call 195528e32f8 108->117 113 195528f3c68-195528f3c73 109->113 114 195528f3bf1-195528f3bfe 110->114 115 195528f3c00-195528f3c14 110->115 111->112 118 195528f3aba 111->118 112->83 121 195528f3c95-195528f3cac 113->121 122 195528f3c75-195528f3c81 113->122 114->115 137 195528f3c18-195528f3c27 114->137 115->102 123 195528f3c16 115->123 119 195528f3d90-195528f3d99 116->119 120 195528f3d66-195528f3d70 116->120 132 195528f3cf0-195528f3d04 call 195528e32f8 117->132 133 195528f3cdd-195528f3cee call 195528e35b4 117->133 125 195528f3abc-195528f3ad5 call 195528f452c 118->125 119->22 128 195528f3d9b-195528f3db2 call 195528e6db4 call 195528e55f0 119->128 120->119 127 195528f3d72-195528f3d8c 120->127 121->108 121->113 122->121 129 195528f3c83-195528f3c8a 122->129 123->110 141 195528f3ae1-195528f3ae7 125->141 142 195528f3ad7-195528f3add 125->142 127->119 128->22 129->121 136 195528f3c8c-195528f3c93 129->136 132->116 152 195528f3d06-195528f3d17 call 195528e35b4 132->152 133->132 151 195528f3d19-195528f3d2f call 195528f2310 133->151 136->121 138 195528f3c29-195528f3c46 137->138 139 195528f3c48 137->139 147 195528f3c4d-195528f3c4f 138->147 139->147 141->112 142->125 146 195528f3adf 142->146 146->112 147->102 147->119 151->116 158 195528f3d31-195528f3d41 151->158 152->116 152->151 158->116 160 195528f3d43-195528f3d5c 158->160 160->116
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: CurrentFormatPathUsercalloc
                                                        • String ID: ;$dW$;$dW$MZ$MZ$N$t$;Ln
                                                        • API String ID: 4207655178-84560671
                                                        • Opcode ID: 1512b8534d4c685afcc9061355cc33150ae67fa718ee72ec55426bd84ba67b64
                                                        • Instruction ID: 8c1e7b5e5efc8d8932d48fd7074002bde08f3250173ff88466565776253d9f46
                                                        • Opcode Fuzzy Hash: 1512b8534d4c685afcc9061355cc33150ae67fa718ee72ec55426bd84ba67b64
                                                        • Instruction Fuzzy Hash: BCA28FB051CF888FE376DF1898947EAB7E5FB99701F500A2EE489C3252DB749541CB82
                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2514012192.00007DF4C3601000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3601000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_7df4c3601000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: Close$CreateFunctionHandleInformationOpenProcessProtectQueryResumeTableThreadValueVirtualVolumecallocfree
                                                        • String ID: -
                                                        • API String ID: 167522227-2547889144
                                                        • Opcode ID: 105c85825427e7c8ed203293b96c467a96f9bba36c05be2648f83f100e5bc7da
                                                        • Instruction ID: 842103727d5696f808f948fab5c39abcea95dc89abbe9753dec5e5dc2597f217
                                                        • Opcode Fuzzy Hash: 105c85825427e7c8ed203293b96c467a96f9bba36c05be2648f83f100e5bc7da
                                                        • Instruction Fuzzy Hash: 6D919334708A494BFB64EF64D8A66BB73E1FF94301F00552AE58BC3291DF78E9818785

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: NamedPipe$BindCallbackCompletionConnectCreate
                                                        • String ID:
                                                        • API String ID: 2502124517-0
                                                        • Opcode ID: 1f39a579d535edce93b33f8ad890ac1eeea552d42be0d6d7d28d92d913c1a808
                                                        • Instruction ID: 4c26072f2831011921e36235b5fb014664db2ab25e44c07e1d2faf9e0e123397
                                                        • Opcode Fuzzy Hash: 1f39a579d535edce93b33f8ad890ac1eeea552d42be0d6d7d28d92d913c1a808
                                                        • Instruction Fuzzy Hash: CB31A030608A488FE795EF28D8D8B9A77E5FB88350F104629E45AD31D2DF74C945CB82

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914401673.00007DF4C3611000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3611000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3611000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: InformationQuerySystem$malloc
                                                        • String ID:
                                                        • API String ID: 1603438391-0
                                                        • Opcode ID: eaf85d99e703aa885d9be82610ad3d8d03a394a4204a017367fdf17adc8f3dbe
                                                        • Instruction ID: 227827cfcd8ed6ece3bf47e23423be5a24e0e5f80167a5dfe1ea72ee2e42dfd1
                                                        • Opcode Fuzzy Hash: eaf85d99e703aa885d9be82610ad3d8d03a394a4204a017367fdf17adc8f3dbe
                                                        • Instruction Fuzzy Hash: 740119347199498BF799EF24DCACAA6B7F1FB94301F441128A44BC22A0DF38D945CB42

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 267 195528f2c64-195528f2c7d 268 195528f2c7f-195528f2c82 267->268 269 195528f2c87-195528f2c8a 267->269 270 195528f2d1a-195528f2d22 268->270 271 195528f2c8c-195528f2c91 269->271 272 195528f2c96-195528f2cab 269->272 271->270 273 195528f2cad-195528f2cb1 272->273 274 195528f2cb7-195528f2ce6 272->274 273->274 275 195528f2ce8-195528f2cf4 NtAcceptConnectPort 274->275 276 195528f2cf6 274->276 277 195528f2cfb-195528f2cfd 275->277 276->277 278 195528f2cff-195528f2d09 277->278 279 195528f2d18 277->279 280 195528f2d11 278->280 281 195528f2d0b-195528f2d0f 278->281 279->270 282 195528f2d16 280->282 281->282 282->279
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID: 0
                                                        • API String ID: 0-4108050209
                                                        • Opcode ID: f6b0f352e34b93935ac2a1f97fa2b0892be8d0a68ee0d9962c8f94757f801c03
                                                        • Instruction ID: d0c7bf570d945ab6de094ff667bc054c56029ff6acdef804f99ba92fcbe17428
                                                        • Opcode Fuzzy Hash: f6b0f352e34b93935ac2a1f97fa2b0892be8d0a68ee0d9962c8f94757f801c03
                                                        • Instruction Fuzzy Hash: 9221AE71608E484FF750EF9888D83AA77E2E798381F61053FF94AD3256DA249944C741
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2502333474.0000019552AC0000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000019552AB0000, based on PE: true
                                                        • Associated: 00000006.00000003.2474026747.0000019552AB0000.00000004.00000800.00020000.00000000.sdmpDownload File
                                                        • Associated: 00000006.00000003.2474074242.0000019552AB0000.00000004.00000800.00020000.00000000.sdmpDownload File
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_19552ab0000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: Free$HeapVirtual
                                                        • String ID:
                                                        • API String ID: 3783212868-0
                                                        • Opcode ID: 86272efb14c44565b31b536206d8a7e697bd049e512a224102b8fa292cb2c375
                                                        • Instruction ID: d09e69ead20ab270bfc359f0456f7901bdb574580bbfb3b86c1265ae93bd55b4
                                                        • Opcode Fuzzy Hash: 86272efb14c44565b31b536206d8a7e697bd049e512a224102b8fa292cb2c375
                                                        • Instruction Fuzzy Hash: 95024673604AA086E776EF29D0647AD7BE2F384784F498012FB9E63749EE78C944C750

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 355 195528e2628-195528e2662 call 19552922c58 358 195528e2734-195528e2737 355->358 359 195528e2668-195528e267c call 19552922c52 Thread32First 355->359 360 195528e273d-195528e2745 358->360 361 195528e288a-195528e289d 358->361 365 195528e2681-195528e2686 359->365 360->361 363 195528e274b-195528e274c 360->363 366 195528e274e-195528e2767 363->366 367 195528e2712-195528e271e call 19552922c4c 365->367 368 195528e268c-195528e2696 365->368 373 195528e276d-195528e2784 SuspendThread 366->373 374 195528e287a-195528e2884 366->374 372 195528e2723-195528e2725 367->372 368->367 375 195528e2698-195528e26a2 368->375 372->365 376 195528e272b-195528e272e CloseHandle 372->376 377 195528e2792-195528e2794 373->377 374->361 374->366 375->367 383 195528e26a4-195528e26aa 375->383 376->358 379 195528e286f-195528e2878 377->379 380 195528e279a-195528e279e 377->380 379->374 381 195528e27a0-195528e27aa 380->381 382 195528e27ac-195528e27ad 380->382 384 195528e27b0-195528e27b2 381->384 382->384 386 195528e26d2-195528e26d8 383->386 387 195528e26ac-195528e26ce 383->387 384->379 388 195528e27b8-195528e27ce 384->388 389 195528e2701-195528e270e 386->389 390 195528e26da-195528e26f4 386->390 387->376 395 195528e26d0 387->395 391 195528e27d0-195528e27e1 388->391 389->367 390->376 397 195528e26f6-195528e26fe 390->397 393 195528e27e3-195528e27e6 391->393 394 195528e27fa 391->394 398 195528e27f3-195528e27f8 393->398 399 195528e27e8-195528e27f1 393->399 400 195528e27fc-195528e2806 394->400 395->389 397->389 398->400 399->400 401 195528e285e-195528e2866 400->401 402 195528e2808-195528e280a 400->402 401->391 403 195528e286c-195528e286d 401->403 404 195528e2810-195528e281d 402->404 405 195528e28a9-195528e28ad 402->405 403->379 406 195528e281f-195528e282a 404->406 407 195528e2839 404->407 408 195528e28af-195528e28b9 405->408 409 195528e28bb-195528e28c8 405->409 410 195528e289e-195528e28a7 406->410 411 195528e282c-195528e2837 406->411 412 195528e283b-195528e283e 407->412 408->409 408->412 413 195528e28ca-195528e28d6 409->413 414 195528e28e5-195528e28e9 409->414 410->412 411->406 411->407 412->401 415 195528e2840-195528e2857 412->415 417 195528e28f7-195528e28ff 413->417 418 195528e28d8-195528e28e3 413->418 414->407 416 195528e28ef-195528e28f2 414->416 415->401 416->412 417->412 418->413 418->414
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: CloseHandleSuspendThread
                                                        • String ID:
                                                        • API String ID: 1038686644-0
                                                        • Opcode ID: ee0b4b29cbf429cf193f7da3647d56e0b1a845656fd74a12addcfb7ee39e090b
                                                        • Instruction ID: 6943677a20e6284900ee5ce8988829f94faf802c05409fcc5014246457c213e3
                                                        • Opcode Fuzzy Hash: ee0b4b29cbf429cf193f7da3647d56e0b1a845656fd74a12addcfb7ee39e090b
                                                        • Instruction Fuzzy Hash: 1D910430208F158BFB69DB58D8613B973E2FB45350F15415DE45BD718BDA35D842CB82
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914559508.00007DF4C3621000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3621000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3621000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FunctionProtectTableTimerVirtual
                                                        • String ID:
                                                        • API String ID: 2248422592-0
                                                        • Opcode ID: 907297c01f2e853a7e6e6be3efaf92a15819b9f7a160a726e89f0d05781fa5e1
                                                        • Instruction ID: 9b0ee2b067574bf706c4b79ab70abf6c08d0ad19bd1ebe144efa14e4e4d9d607
                                                        • Opcode Fuzzy Hash: 907297c01f2e853a7e6e6be3efaf92a15819b9f7a160a726e89f0d05781fa5e1
                                                        • Instruction Fuzzy Hash: 0BE1623160CA494FEBA4EF28D8A85BA77F1FF98300F15552EE48BC3291DB35E5858781
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AllocVirtual
                                                        • String ID:
                                                        • API String ID: 4275171209-0
                                                        • Opcode ID: 1463b6e579e83794cd598155eb9e3160b38bf0e3bcb0f61670329aaf0c67c5a2
                                                        • Instruction ID: d038e927091d94c3939e59efbab8d49e5691de921c22892add6bfa070cb89c8a
                                                        • Opcode Fuzzy Hash: 1463b6e579e83794cd598155eb9e3160b38bf0e3bcb0f61670329aaf0c67c5a2
                                                        • Instruction Fuzzy Hash: 6CF14A31A18A680EF72DDB6C98962B977D2F785341F28426EE4DBD2283D938C547C7C1
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: f13696e1930880e2e19ebf6412232386b6a4ab7a0f564d2111b2459b68bcc0da
                                                        • Instruction ID: d2afdbf74e62b199bf48654d401ac8985fb14f4fdf2b9ab74c4be8505084fda5
                                                        • Opcode Fuzzy Hash: f13696e1930880e2e19ebf6412232386b6a4ab7a0f564d2111b2459b68bcc0da
                                                        • Instruction Fuzzy Hash: 0781D43021CF098BF777DB9894657AAB3D2FB94380F524619F846D728BEA64D811C782
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: d9381645012d00cf6e7f8dfe8da443d67e907387f0873f85681973196ff3555c
                                                        • Instruction ID: 912c1a7d21452797694ee845f032dd9f65e678cdb8c6c84a3d3723007d26eca5
                                                        • Opcode Fuzzy Hash: d9381645012d00cf6e7f8dfe8da443d67e907387f0873f85681973196ff3555c
                                                        • Instruction Fuzzy Hash: 8EF0DA74A2CF448FEB64EF2CD489B9A77E1FB99300F504519E84CC3246DB34D8448B86
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 98d03459468cdcd74854b97b597847e55f0ea75636d4913b4c299d0c762e3800
                                                        • Instruction ID: a75c1b88834208dd57b50d1e19c39359755426d288108ae1ba5e502946a62bf9
                                                        • Opcode Fuzzy Hash: 98d03459468cdcd74854b97b597847e55f0ea75636d4913b4c299d0c762e3800
                                                        • Instruction Fuzzy Hash: D4E09271208B088FEB00EF98CCC1DA9B3E4E7D9301F404D2AEC8AC7165D264D648CB92
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 1d483c746a178fd7cebb358bd60c8d391381be698edd62c71eedc0381d53c554
                                                        • Instruction ID: cefaf7870d4e257059961d952ce096e6ede9131f376b49f151d9f1fa02fd82de
                                                        • Opcode Fuzzy Hash: 1d483c746a178fd7cebb358bd60c8d391381be698edd62c71eedc0381d53c554
                                                        • Instruction Fuzzy Hash: A5D0A734A3CF4D4FFB10B768894030537D2F7D5308F914608A848D325AD62DD40087C2
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: bd75e34d41d0a0c218f00c4b384fa59cf13494ae4b0fc6bee219bc2a66024f0a
                                                        • Instruction ID: e3c05d31d6f804c35958d2e90b5f61009b51f6ac9a33535f2df13dfc4c5c8d33
                                                        • Opcode Fuzzy Hash: bd75e34d41d0a0c218f00c4b384fa59cf13494ae4b0fc6bee219bc2a66024f0a
                                                        • Instruction Fuzzy Hash: 7AD05B34D6CF458BE710FBA8C8406497BE1FBD9354F654618F88593315E338D441C786
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 27a0ab9b8b81d19b55a36d5b88940b5d877d47714e961321c564cf766a84aa8c
                                                        • Instruction ID: bbb28da669a997571992535fecf66cb502b0a47bbce46fe4e0f8664d16fa9e76
                                                        • Opcode Fuzzy Hash: 27a0ab9b8b81d19b55a36d5b88940b5d877d47714e961321c564cf766a84aa8c
                                                        • Instruction Fuzzy Hash: 57D01234A18B458BE750AB6C89516097BE1B7C9358F554618F84893315E238D441C786
                                                        APIs
                                                        • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,?,00000195528E531B), ref: 00000195528F28F8
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 14fbc5d4ea2d13eb613c5f0cfb1986910ad3174e43fd425e2ce4bb45159b65c3
                                                        • Instruction ID: a3bb56e8eb04ce503dab46a41acb177fddd5b8867c11d0fe2d39ff621ed1696f
                                                        • Opcode Fuzzy Hash: 14fbc5d4ea2d13eb613c5f0cfb1986910ad3174e43fd425e2ce4bb45159b65c3
                                                        • Instruction Fuzzy Hash: 07C08C2062DE0E0AFA01A2F98C91B582380A349394F810000AC05D2186E80CD5C08392
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AcceptConnectPort
                                                        • String ID:
                                                        • API String ID: 1658770261-0
                                                        • Opcode ID: 2134b33d09b848e70ba1f23de37cfdd97cd4e92c7083e33fbb9b34bfa8345c36
                                                        • Instruction ID: e1eae6d40392d8cc3cffb3330a91bf86f208085473a78866d835f1730a93b5dd
                                                        • Opcode Fuzzy Hash: 2134b33d09b848e70ba1f23de37cfdd97cd4e92c7083e33fbb9b34bfa8345c36
                                                        • Instruction Fuzzy Hash: 1DC08C20A19D0B0AFA16A2FA8C907483280A7AA380FC20000B808C2186F48CC8D083E6
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2514012192.00007DF4C3601000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3601000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_7df4c3601000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: CloseInformationOpenQueryValueVolume
                                                        • String ID:
                                                        • API String ID: 4069062851-0
                                                        • Opcode ID: 3ebb744f0aebbecadcf06631c3d65907a1788fb7df7ced3004579ef494ef68f9
                                                        • Instruction ID: 99b954df7d3041c0c8cb4f7405de7d906f5c8a2b4717fd22c10fc9b62ba0fe5e
                                                        • Opcode Fuzzy Hash: 3ebb744f0aebbecadcf06631c3d65907a1788fb7df7ced3004579ef494ef68f9
                                                        • Instruction Fuzzy Hash: 78413E7061CA488BE765EF24C499BEBB3E1FB94301F005A2EE18BC6291DF7895448B46

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: socket$ErrorModegetsockopt
                                                        • String ID:
                                                        • API String ID: 552242919-0
                                                        • Opcode ID: 3bad8950bc8ed42d49e75fcab8a12e6def80f6fb96da2e8da31b13afe45452c3
                                                        • Instruction ID: 71dc0846e47a2c6dfd0998c891c3612f5f73a96f01c9324a72858cc3a3061457
                                                        • Opcode Fuzzy Hash: 3bad8950bc8ed42d49e75fcab8a12e6def80f6fb96da2e8da31b13afe45452c3
                                                        • Instruction Fuzzy Hash: D2417530618B498FF759EF68D8986AA77E6FB98300F51463DE04BC33A2DB788515CB41

                                                        Control-flow Graph

                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID: rE\
                                                        • API String ID: 544645111-988334199
                                                        • Opcode ID: fd197d1d460a7a7097ebc69198cfe8898b84731961e3c45740b5833891c72836
                                                        • Instruction ID: 62310f116ca28d28a0a8b4e9c7f3c1280bbf838b4b4b142474fae4111e3ddc78
                                                        • Opcode Fuzzy Hash: fd197d1d460a7a7097ebc69198cfe8898b84731961e3c45740b5833891c72836
                                                        • Instruction Fuzzy Hash: 3D116031308E090BFB46FB9898A1BF97297F7D8340F504529A40AD3287EE28DD458781

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: File$CloseHandleMappingOpenView
                                                        • String ID:
                                                        • API String ID: 2553196624-0
                                                        • Opcode ID: 8bb8605ac1c349b7ed951fd2da0efd1c73228fe5391c7a5f19e2fcd3618d3200
                                                        • Instruction ID: ed9fe3a441af88d35aa018f1883158c09974061d55f908a4540d783e29b87e75
                                                        • Opcode Fuzzy Hash: 8bb8605ac1c349b7ed951fd2da0efd1c73228fe5391c7a5f19e2fcd3618d3200
                                                        • Instruction Fuzzy Hash: 7D31A431618E088FFB56FF64D8966EAB3D5FB94340F51452AA44BC3183DE34D51D8781

                                                        Control-flow Graph

                                                        APIs
                                                        Strings
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: CreateWindow
                                                        • String ID: P
                                                        • API String ID: 716092398-3110715001
                                                        • Opcode ID: 3958d680dd61ed40200acf61cd907bfc270c34c5250da5fbb8d7e78c828db693
                                                        • Instruction ID: d07070a97c1680ac6a7fb4257046e02450a00fb8d395d76f3876d94df9a2b15b
                                                        • Opcode Fuzzy Hash: 3958d680dd61ed40200acf61cd907bfc270c34c5250da5fbb8d7e78c828db693
                                                        • Instruction Fuzzy Hash: 41518F70118B448FE7A5EF28E89679AB7E4FB99300F10462FE08EC2151DF349445CB83

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 284 7df4c3613018-7df4c361304d call 7df4c3611478 287 7df4c36132e0-7df4c3613302 call 7df4c36134f0 284->287 288 7df4c3613053-7df4c3613068 call 7df4c3611538 284->288 288->287 293 7df4c361306e-7df4c361309c call 7df4c3611708 call 7df4c3611740 call 7df4c3611818 288->293 293->287 301 7df4c36130a2-7df4c36130ca 293->301 301->287 303 7df4c36130d0-7df4c36130d8 301->303 304 7df4c361318a-7df4c361320a call 7df4c3613520 call 7df4c361368c call 7df4c3613686 call 7df4c3613680 SendMessageA 303->304 305 7df4c36130de-7df4c3613122 call 7df4c361365c * 2 303->305 330 7df4c3613213-7df4c3613219 304->330 318 7df4c3613185-7df4c3613188 305->318 318->304 321 7df4c3613124-7df4c3613128 318->321 322 7df4c361312a-7df4c361312e 321->322 323 7df4c3613130-7df4c3613146 calloc 321->323 322->323 325 7df4c3613182-7df4c3613183 322->325 323->325 326 7df4c3613148-7df4c3613163 call 7df4c3613510 323->326 325->318 331 7df4c3613165-7df4c361316f 326->331 332 7df4c3613171-7df4c3613175 326->332 333 7df4c36132dd-7df4c36132de 330->333 334 7df4c361321f-7df4c3613225 330->334 331->325 332->325 335 7df4c3613177-7df4c361317f 332->335 333->287 334->333 336 7df4c361322b-7df4c361323d 334->336 335->325 336->333 338 7df4c3613243-7df4c3613256 call 7df4c3613510 336->338 341 7df4c36132bf-7df4c36132d2 338->341 343 7df4c36132d4-7df4c36132d5 341->343 344 7df4c3613258-7df4c361325b 341->344 343->333 345 7df4c36132bd 344->345 346 7df4c361325d-7df4c3613280 call 7df4c361365c 344->346 345->341 350 7df4c361328a-7df4c36132b7 call 7df4c361365c 346->350 351 7df4c3613282-7df4c3613288 346->351 350->345 351->345
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914401673.00007DF4C3611000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3611000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3611000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FunctionMessageProtectSendTableVirtualcalloc
                                                        • String ID:
                                                        • API String ID: 2453823186-0
                                                        • Opcode ID: 06791c2761ba3497e0c9077ab5921302019734c58a86a701aa2be8a22ea6a1e2
                                                        • Instruction ID: c1f4f38a31433e9645ee11592337f46cff85e950f42ee8c9a79cbf4d50336209
                                                        • Opcode Fuzzy Hash: 06791c2761ba3497e0c9077ab5921302019734c58a86a701aa2be8a22ea6a1e2
                                                        • Instruction Fuzzy Hash: B891643571CA484FFBA5EF28D4A55BA73E2FB54300B60563AD08BC3291DA78EC958781

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 420 195528e22d0-195528e22ff GetSystemInfo 421 195528e2301-195528e230c 420->421 422 195528e230f-195528e2325 420->422 421->422 423 195528e232b-195528e232e 422->423 424 195528e2330-195528e2333 423->424 425 195528e234a-195528e2350 423->425 426 195528e2345-195528e2348 424->426 427 195528e2335-195528e2338 424->427 428 195528e2352-195528e2362 425->428 429 195528e23cb-195528e23ce 425->429 426->423 427->426 431 195528e233a-195528e233f 427->431 432 195528e2391-195528e2397 428->432 430 195528e245a 429->430 433 195528e245c-195528e245f 430->433 434 195528e2467-195528e247e 430->434 431->426 435 195528e24ad-195528e24bf 431->435 436 195528e2364-195528e237b 432->436 437 195528e2399 432->437 439 195528e23d3-195528e23f1 433->439 440 195528e2465 433->440 441 195528e2480-195528e249a 434->441 436->437 449 195528e237d-195528e2385 436->449 438 195528e239b-195528e239e 437->438 438->429 442 195528e23a0-195528e23c0 VirtualAlloc 438->442 444 195528e2433 439->444 445 195528e23f3-195528e240a 439->445 440->435 441->441 443 195528e249c-195528e24a7 441->443 442->434 447 195528e23c6-195528e23c9 442->447 443->435 448 195528e2435-195528e2438 444->448 445->444 453 195528e240c-195528e2414 445->453 447->428 447->429 448->435 451 195528e243a-195528e2458 448->451 449->438 452 195528e2387-195528e238f 449->452 451->430 452->432 452->437 453->448 454 195528e2416-195528e2431 453->454 454->444 454->445
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AllocInfoSystemVirtual
                                                        • String ID:
                                                        • API String ID: 3440192736-0
                                                        • Opcode ID: 9420d4d47bb5eb7f06d7fea4bf54311970c83033f74d5905fb72208c54926d5e
                                                        • Instruction ID: ac10cc54df6c9b8ef5185e9ec1ef809be7e5113e63f9e7798c6e18743dd70e9d
                                                        • Opcode Fuzzy Hash: 9420d4d47bb5eb7f06d7fea4bf54311970c83033f74d5905fb72208c54926d5e
                                                        • Instruction Fuzzy Hash: F851093021CF0D4FFB56EBAC94583A972D2F798385F154129F44AD31AAEE74C8818B81

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: CloseFileHandleView
                                                        • String ID:
                                                        • API String ID: 3964672402-0
                                                        • Opcode ID: f5e4ace49f8dbf4d208ab68c6c07d1c08f373a7b01313fe5be4b999b6ef0fbb6
                                                        • Instruction ID: 9d604e4fc59a21d1c98c32beaa6513d48bcce3754c03a537b322a1c2ccf84d5d
                                                        • Opcode Fuzzy Hash: f5e4ace49f8dbf4d208ab68c6c07d1c08f373a7b01313fe5be4b999b6ef0fbb6
                                                        • Instruction Fuzzy Hash: 4141B470214F088FF746FFA8D8946EA73A6FBA5341F024519B40AD7197DF24D8058781

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID:
                                                        • API String ID: 544645111-0
                                                        • Opcode ID: 9af94119fb7637b7a971dd9e5dfe6689dbe62cc4b897151fb24c5dcbfab40a36
                                                        • Instruction ID: 8fd473e6c5ac7835a0d05c2bd1bb3714269cdae0cdf2d3ce3046671e1f53f760
                                                        • Opcode Fuzzy Hash: 9af94119fb7637b7a971dd9e5dfe6689dbe62cc4b897151fb24c5dcbfab40a36
                                                        • Instruction Fuzzy Hash: 1A312B30308B854BFB159BAC98A4B953BC2FB5B354F160295E88AC72CADB58CC02C356
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2514012192.00007DF4C3601000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3601000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_7df4c3601000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID:
                                                        • API String ID: 544645111-0
                                                        • Opcode ID: 89563af4fe1d572c43706a2c5b782feb3df9d02bfd1ff06021ce1d81ad062eb6
                                                        • Instruction ID: a46b66cc1c8fb2ebaec874ce0071bf4c0cdf39744c2acfd7e94dbce8f7855b00
                                                        • Opcode Fuzzy Hash: 89563af4fe1d572c43706a2c5b782feb3df9d02bfd1ff06021ce1d81ad062eb6
                                                        • Instruction Fuzzy Hash: BD21BF3970868547FB2C9F3894A6676B3E1FF94300F14513AE88BC7B85D669F88182D9

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914401673.00007DF4C3611000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3611000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3611000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID:
                                                        • API String ID: 544645111-0
                                                        • Opcode ID: 555ee51bdfbe110a30625e9d65cd405c650e6e50b938efdbc78372c29de57681
                                                        • Instruction ID: c1047f9e9137d80326c84af7b140857f0121287a1f041e737e4bb44fe92673eb
                                                        • Opcode Fuzzy Hash: 555ee51bdfbe110a30625e9d65cd405c650e6e50b938efdbc78372c29de57681
                                                        • Instruction Fuzzy Hash: CC21D13A70868647FB289F2D94A8677B3F1FF94300F14512AE49BC7385D668ED818285

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914559508.00007DF4C3621000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3621000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3621000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ProtectVirtual
                                                        • String ID:
                                                        • API String ID: 544645111-0
                                                        • Opcode ID: aa55061d99e775b82e27cc6da46f8fa59da2ee6fc95db4891e67f0932caa2168
                                                        • Instruction ID: 0e9047d6a1c939543ac2e4ee6d3f86e6173248eead018052d04ad3dcdd0c40df
                                                        • Opcode Fuzzy Hash: aa55061d99e775b82e27cc6da46f8fa59da2ee6fc95db4891e67f0932caa2168
                                                        • Instruction Fuzzy Hash: C321D33170C58547FB28DF289464A76B3F2FF94340F16513AE88BC7B85D66AE88182D5
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 85df9ee76aeee916477ee65bd03fae0aa34298d7a375d21a792168504e9e5af9
                                                        • Instruction ID: 4707e5f48f3b92a9a6fee5aadddeb42597035c74710da5335c930aae01e46293
                                                        • Opcode Fuzzy Hash: 85df9ee76aeee916477ee65bd03fae0aa34298d7a375d21a792168504e9e5af9
                                                        • Instruction Fuzzy Hash: 10F09A30210E0E8FFB8AEF69C4E8765B3E1FB68346F6101A9E419C25A0C7749C50CB01
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2514012192.00007DF4C3601000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3601000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_7df4c3601000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FileMappingOpen
                                                        • String ID:
                                                        • API String ID: 1680863896-0
                                                        • Opcode ID: a4d7378eb0dc183d45dac9fde789c38604b4b9a60361aa9a1ccba498305d516d
                                                        • Instruction ID: 2a62fc16757fa8d5bd8d749418b000f5050627493341dabccc7e7fdb3fd27fcc
                                                        • Opcode Fuzzy Hash: a4d7378eb0dc183d45dac9fde789c38604b4b9a60361aa9a1ccba498305d516d
                                                        • Instruction Fuzzy Hash: AB71637061C7884BE775DF2894966BBB7E1FB94300F001A2EE5CFC3251EA34A9418786
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FileRead
                                                        • String ID:
                                                        • API String ID: 2738559852-0
                                                        • Opcode ID: e26a3d902f64fdb1e6a29b1ddfd8af137ced715061d327bbcfc87f3b72d7e64f
                                                        • Instruction ID: bb007ee1d064bc00a6448d20c62f786b999b474988267a599c3408c23b2fa5f6
                                                        • Opcode Fuzzy Hash: e26a3d902f64fdb1e6a29b1ddfd8af137ced715061d327bbcfc87f3b72d7e64f
                                                        • Instruction Fuzzy Hash: 2471F832608F084FF76AEB58D8A1AA573E2FBD4710F11061DE58BD3193DB30E9468781
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ErrorMode
                                                        • String ID:
                                                        • API String ID: 2340568224-0
                                                        • Opcode ID: c27442c9625b69612e30a0c621dafdc38b3cd1b2ea33eefe8ec2cdf5f7c33623
                                                        • Instruction ID: 8ea1ce173c72d212e7a7c07c1585cad52d4f510e6a6058f710e0846e36decd3e
                                                        • Opcode Fuzzy Hash: c27442c9625b69612e30a0c621dafdc38b3cd1b2ea33eefe8ec2cdf5f7c33623
                                                        • Instruction Fuzzy Hash: D9419130314F094BFB5AF7B898A17FA32D7EB94350F410629B84AE31C3DE29D9018742
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: InformationVolume
                                                        • String ID:
                                                        • API String ID: 2039140958-0
                                                        • Opcode ID: c6fe4b8a49b1c432d16a5d1b2244a4336856686fe2f0bc0d983b446ba2d85ae3
                                                        • Instruction ID: 61ac1705acb0daafb1fcec06fa7b8921df6853dd06dd1cd2ac7b7b98c434040a
                                                        • Opcode Fuzzy Hash: c6fe4b8a49b1c432d16a5d1b2244a4336856686fe2f0bc0d983b446ba2d85ae3
                                                        • Instruction Fuzzy Hash: C841307111CB488BE76AEB64C8A5BDBB3E1FB94340F014A1DF08AD3192EF759549CB42
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FileRead
                                                        • String ID:
                                                        • API String ID: 2738559852-0
                                                        • Opcode ID: 2f464fde3477c0bba4832f44d3340180ae7d23497e5ed422822a87f1e6a42210
                                                        • Instruction ID: 2c1069a24936e724568049153cc41f6ee0b5341e1661a4c65039211f02189417
                                                        • Opcode Fuzzy Hash: 2f464fde3477c0bba4832f44d3340180ae7d23497e5ed422822a87f1e6a42210
                                                        • Instruction Fuzzy Hash: ED01C471704A0C8FE741FB59D8819ADB7E9FBD8310F50062AF84AD2141EF20EA548781
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: ResumeThread
                                                        • String ID:
                                                        • API String ID: 947044025-0
                                                        • Opcode ID: a3e65a005f3911c52a3a19618f507bf36bcbd5794d57615cb3bbd7cad2f75c67
                                                        • Instruction ID: 910e23e9931e0ccba8eaef15fcbcf38b870762da0a7e854c1bdb508de3763c99
                                                        • Opcode Fuzzy Hash: a3e65a005f3911c52a3a19618f507bf36bcbd5794d57615cb3bbd7cad2f75c67
                                                        • Instruction Fuzzy Hash: 4B012631714E098FFB54EBADDCA8A6533D2FB8A356B054065E80AC3149DA3A9C41CB41
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914401673.00007DF4C3611000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3611000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3611000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: EventHook
                                                        • String ID:
                                                        • API String ID: 3661607649-0
                                                        • Opcode ID: e6b188324f96a1e03f166e4287a2793acb406422b2b30f8b11d607c185f61fee
                                                        • Instruction ID: f043cd9ba7629f6b13f540777d867073716357af0ec9632a4c2107f2479a5ab5
                                                        • Opcode Fuzzy Hash: e6b188324f96a1e03f166e4287a2793acb406422b2b30f8b11d607c185f61fee
                                                        • Instruction Fuzzy Hash: 6A113034A189454EFB64EF60D8797A672F0FB10319F601629D0CBC22D1DB39D8949741
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: LibraryLoad
                                                        • String ID:
                                                        • API String ID: 1029625771-0
                                                        • Opcode ID: 4d57d7d5982399080f90361c2699a999889f8feb933735bc5bb6e787f07df0d3
                                                        • Instruction ID: 1eaf613cefe04f4ff9a384a9be0e584fcede235339585d27e1d568cb1021c5c4
                                                        • Opcode Fuzzy Hash: 4d57d7d5982399080f90361c2699a999889f8feb933735bc5bb6e787f07df0d3
                                                        • Instruction Fuzzy Hash: D5018C30318F4D4FFB46EBB898663A972A6FB54341F51056AA00AD3293EA28CD088742
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: CreateHeap
                                                        • String ID:
                                                        • API String ID: 10892065-0
                                                        • Opcode ID: eab2b32177be9564e25d5777707ea1ca30621b5695f0306aefe172fe800bc35c
                                                        • Instruction ID: 54b042bb7c3bfccac3b681e6448c953e60678f2ea62b1d3fbe5bf875a47bf3a0
                                                        • Opcode Fuzzy Hash: eab2b32177be9564e25d5777707ea1ca30621b5695f0306aefe172fe800bc35c
                                                        • Instruction Fuzzy Hash: 2CF0E531704F088FF725AEF65CE43AB3243F3C4392F26093AF406D628AD83988418340
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: AddressCallerProc
                                                        • String ID:
                                                        • API String ID: 2663294120-0
                                                        • Opcode ID: c691d5039295ecc8b7e044fb40fc3c69618cf93c91779b6bda279d67736a12d8
                                                        • Instruction ID: e4fffc9765f6acdd145f62f41d470a55e0350fb84db44d2a60b91f537191f596
                                                        • Opcode Fuzzy Hash: c691d5039295ecc8b7e044fb40fc3c69618cf93c91779b6bda279d67736a12d8
                                                        • Instruction Fuzzy Hash: EDE08C21704D290BAB6961EE2498AB611C6C7E82A2704027AB41CC229AED10CC410380
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000003.2514012192.00007DF4C3601000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3601000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_3_7df4c3601000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FunctionTable
                                                        • String ID:
                                                        • API String ID: 1252446317-0
                                                        • Opcode ID: fc492990cf9c193ed0fed28dab1318ef1c2e9243cee28bd6a774944ac56baf31
                                                        • Instruction ID: 3a3478d107bdac111e3b544a8ee32e5ef53c26fd2f5a171acadc6302ad4557c5
                                                        • Opcode Fuzzy Hash: fc492990cf9c193ed0fed28dab1318ef1c2e9243cee28bd6a774944ac56baf31
                                                        • Instruction Fuzzy Hash: A5E04F34A049055BEBA8DB1DC80A7603AE0FB5830AF608669D505C9291CB79D4DBCF85
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914401673.00007DF4C3611000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3611000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3611000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FunctionTable
                                                        • String ID:
                                                        • API String ID: 1252446317-0
                                                        • Opcode ID: 62df2a061ef9a83e40c3da8f8fbf33d98cfabe8aaf6c816d3fbd47a45bbcd3fe
                                                        • Instruction ID: 76a05e3f2d73c7651866d01bd3a325cf1df100a9b418ec0a23001b58e78f9a86
                                                        • Opcode Fuzzy Hash: 62df2a061ef9a83e40c3da8f8fbf33d98cfabe8aaf6c816d3fbd47a45bbcd3fe
                                                        • Instruction Fuzzy Hash: 8FE04F346509054BEBA8EB1DC85D76036E0EB58306F604269D445CA391CB3998DBCF82
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FunctionTable
                                                        • String ID:
                                                        • API String ID: 1252446317-0
                                                        • Opcode ID: a4029a93bfcd341c8676454adb8c6f5f12b6913b14ed0bccef0902b234b6dd47
                                                        • Instruction ID: 7bf5d4020bd822077cd196132438d44c66797059df1bc9fb99fa56935061e143
                                                        • Opcode Fuzzy Hash: a4029a93bfcd341c8676454adb8c6f5f12b6913b14ed0bccef0902b234b6dd47
                                                        • Instruction Fuzzy Hash: E5E04F30100A055BFB9CDB5DC9093A036D1EB9830AF604258E404C9296CB3AC8DBCF41
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FreeVirtual
                                                        • String ID:
                                                        • API String ID: 1263568516-0
                                                        • Opcode ID: ef59572018a9deb8cc9717970e2f4ccce5bc515e763955c946e33fff9a11c9f9
                                                        • Instruction ID: 6b087159b50a4c0b11072835012d17d1b18f2d28b41281d0933f7cd437e02ed6
                                                        • Opcode Fuzzy Hash: ef59572018a9deb8cc9717970e2f4ccce5bc515e763955c946e33fff9a11c9f9
                                                        • Instruction Fuzzy Hash: 12914C30218F098BEB4AEF58D895AEA73E2FB98340F414569F44AC7197DF30E955CB81
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2914559508.00007DF4C3621000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4C3621000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_7df4c3621000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: FunctionTable
                                                        • String ID:
                                                        • API String ID: 1252446317-0
                                                        • Opcode ID: cff89ce48d21670ef986fb34dbe231ab83686b2b911df37c38ad495f9c0b2048
                                                        • Instruction ID: c482f35c6f726e5c2b70d67c2d47d07ed0c14c805e7d045a465301f08b08c2dc
                                                        • Opcode Fuzzy Hash: cff89ce48d21670ef986fb34dbe231ab83686b2b911df37c38ad495f9c0b2048
                                                        • Instruction Fuzzy Hash: F7E04F30A059054BEBA8DB1DC90976136E0EB5C306F604669E505C92D1CB3AD8DBCF85
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: LibraryLoad
                                                        • String ID:
                                                        • API String ID: 1029625771-0
                                                        • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                                        • Instruction ID: 4571e7a4aa1b39d4cd63627f3951ab5b8305c6d0d8ac9b384fe0e0016ce62438
                                                        • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                                                        • Instruction Fuzzy Hash: 0DD0A720320E0D1BFB4C637D1CA537551D6E7DC362F51023AB80AC2287D958CC560340
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 59198f789e8770a8feb484424aff911a50a4b1632d60f2ad6db9f6e5577744bf
                                                        • Instruction ID: b3b0198135eca9a3de71f53a61f5ec783a32e167c30ab856355966193c777a75
                                                        • Opcode Fuzzy Hash: 59198f789e8770a8feb484424aff911a50a4b1632d60f2ad6db9f6e5577744bf
                                                        • Instruction Fuzzy Hash: D3916F7151CF484BE766FF54C8957EEB3E2FBA8341F410A2EE18AD3193DA3099458782
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: malloc
                                                        • String ID:
                                                        • API String ID: 2803490479-0
                                                        • Opcode ID: d2cb0783aaccdf533b8783a245833ea662784d452517a49626c29c14fb2d72e4
                                                        • Instruction ID: 9ea1755dda248aa29fb8e67427ae7593915f83b0279d767f7a5559cc3ba06ee3
                                                        • Opcode Fuzzy Hash: d2cb0783aaccdf533b8783a245833ea662784d452517a49626c29c14fb2d72e4
                                                        • Instruction Fuzzy Hash: 8941C631214E0E8FEB95EF6CC898AA5B7E1FB68751711466AE419C3661DB30E885CBC0
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: e53db298d0d7d8de9701e8a24c72cb59212fc55ca396913229799ff2ccd7724d
                                                        • Instruction ID: 40d19d335bcd589fed3cf12bc5930a29c1d46373d99513e1492c7705a0e25800
                                                        • Opcode Fuzzy Hash: e53db298d0d7d8de9701e8a24c72cb59212fc55ca396913229799ff2ccd7724d
                                                        • Instruction Fuzzy Hash: EE114031204E198FFFAA9FA988A43A533E1FB58355F15017AE919DA19BCB708C41CB91
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000006.00000002.2913278510.00000195528E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000195528E1000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_6_2_195528e1000_wmplayer.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 5a17d2a82900e38e66e0587de357cfea25c88adc918405c2cab64094945da2f0
                                                        • Instruction ID: 8900146590ea75dd9fa01416fc30f9a1a1a9a645735511b20fc779f6973a805a
                                                        • Opcode Fuzzy Hash: 5a17d2a82900e38e66e0587de357cfea25c88adc918405c2cab64094945da2f0
                                                        • Instruction Fuzzy Hash: 55F036B0218D0A4FFF95DBAD84E4F6133E1FB58350F512254A81EC729ADA25DC81CB40

                                                        Execution Graph

                                                        Execution Coverage:2.2%
                                                        Dynamic/Decrypted Code Coverage:0%
                                                        Signature Coverage:0%
                                                        Total number of Nodes:253
                                                        Total number of Limit Nodes:8
                                                        execution_graph 15310 2e6557928a0 15311 2e6557928bc 15310->15311 15312 2e6557928c1 GetProcAddressForCaller 15311->15312 15313 2e6557928ca 15311->15313 15312->15313 15437 2e655795340 15438 2e6557953b5 15437->15438 15443 2e655795356 15437->15443 15449 2e655794f78 15438->15449 15440 2e6557953b3 15442 2e6557953c4 15442->15440 15453 2e6557952c0 15442->15453 15443->15440 15445 2e655794d38 15443->15445 15447 2e655794d61 15445->15447 15446 2e655794f0a 15446->15443 15447->15446 15448 2e655794630 free 15447->15448 15448->15446 15451 2e655794f9c 15449->15451 15450 2e655795008 15450->15442 15451->15450 15452 2e655794630 free 15451->15452 15452->15450 15454 2e655795302 15453->15454 15455 2e6557952c5 15453->15455 15454->15440 15455->15454 15456 2e6557945b0 free 15455->15456 15456->15454 15515 2e655792e80 15518 2e655792e9a 15515->15518 15519 2e655792f97 15515->15519 15516 2e6557945b0 free 15517 2e655792f95 15516->15517 15518->15517 15518->15519 15520 2e655792f1d 15518->15520 15519->15516 15520->15517 15522 2e655795bd4 15520->15522 15526 2e655795bf0 15522->15526 15529 2e655795c72 15522->15529 15523 2e655795c65 15524 2e6557945b0 free 15523->15524 15525 2e655795c6d 15524->15525 15525->15517 15526->15523 15527 2e6557952c0 free 15526->15527 15527->15526 15529->15525 15530 2e655795768 15529->15530 15531 2e6557957af 15530->15531 15532 2e655795ba2 15530->15532 15534 2e655795a18 15531->15534 15535 2e6557957b8 15531->15535 15533 2e65579583a 15532->15533 15558 2e655794b64 15532->15558 15533->15529 15538 2e655795af3 15534->15538 15540 2e655795a28 15534->15540 15539 2e6557957c1 15535->15539 15545 2e65579585e 15535->15545 15537 2e655794c20 free 15537->15533 15538->15533 15541 2e655795b22 15538->15541 15543 2e655795ae3 15538->15543 15539->15533 15546 2e6557952c0 free 15539->15546 15548 2e6557954cc 15540->15548 15541->15533 15554 2e655794c20 15541->15554 15543->15533 15543->15537 15545->15533 15547 2e655794630 free 15545->15547 15546->15533 15547->15533 15549 2e6557954f8 15548->15549 15550 2e65579559d 15549->15550 15551 2e655794804 4 API calls 15549->15551 15550->15543 15552 2e655795583 15551->15552 15552->15550 15553 2e6557952c0 free 15552->15553 15553->15550 15556 2e655794c46 15554->15556 15555 2e655794cca 15555->15533 15556->15555 15557 2e655794630 free 15556->15557 15557->15555 15560 2e655794b80 15558->15560 15559 2e655794bb6 15559->15533 15560->15559 15561 2e655794630 free 15560->15561 15561->15559 15348 2e6557b6e1c SetErrorMode 15349 2e6557b6e30 15348->15349 15350 2e6557ba3f6 socket 15349->15350 15351 2e6557ba483 socket 15350->15351 15352 2e6557ba43a getsockopt 15350->15352 15354 2e6557ba4a3 15351->15354 15352->15351 15299 2e6557b7dd0 15300 2e6557b7df4 socket 15299->15300 15302 2e6557b7e0c 15299->15302 15301 2e6557b7e27 15300->15301 15300->15302 15301->15302 15304 2e6557b79e0 15301->15304 15305 2e6557b7a12 15304->15305 15306 2e6557b7a35 CreateIoCompletionPort 15305->15306 15309 2e6557b7a1d 15305->15309 15307 2e6557b7a4d 15306->15307 15308 2e6557b7a82 SetFileCompletionNotificationModes 15307->15308 15307->15309 15308->15309 15309->15302 15314 2e655792690 15317 2e6557928d4 15314->15317 15318 2e6557926a2 15317->15318 15319 2e6557928dd 15317->15319 15319->15318 15320 2e655792944 SetErrorMode 15319->15320 15321 2e655792955 15320->15321 15323 2e65579385c 15321->15323 15324 2e65579387d 15323->15324 15330 2e6557939d5 15324->15330 15331 2e655793484 15324->15331 15326 2e6557938ae 15326->15330 15335 2e655793658 15326->15335 15328 2e65579394a 15329 2e6557939bf NtQuerySystemInformation 15328->15329 15328->15330 15329->15330 15330->15318 15332 2e6557934ac 15331->15332 15333 2e655793574 GetVolumeInformationW 15332->15333 15334 2e6557935c5 15332->15334 15333->15334 15334->15326 15336 2e65579368a 15335->15336 15337 2e65579376a CreateFileMappingW 15336->15337 15338 2e6557937a4 MapViewOfFile 15337->15338 15339 2e6557937c7 15337->15339 15338->15339 15339->15328 15457 2e655793130 15459 2e65579314d 15457->15459 15458 2e655793157 15460 2e6557945b0 free 15458->15460 15459->15458 15462 2e65579316c 15459->15462 15461 2e65579315f 15460->15461 15466 2e65579423c 15462->15466 15464 2e6557931ef 15470 2e655794750 15464->15470 15467 2e655794254 15466->15467 15473 2e655799c80 15467->15473 15469 2e6557942ac 15469->15464 15471 2e655797ef4 free 15470->15471 15472 2e655794763 15471->15472 15472->15461 15474 2e655799ca8 15473->15474 15475 2e655799aac free 15474->15475 15476 2e655799cb4 15474->15476 15475->15476 15476->15469 15576 2e6557b9434 15577 2e6557b943e 15576->15577 15578 2e6557b9458 15576->15578 15577->15578 15580 2e6557b7ec0 15577->15580 15581 2e6557b7dd0 3 API calls 15580->15581 15582 2e6557b7ef1 15581->15582 15582->15578 15340 2e655797ff4 15341 2e655797ff9 15340->15341 15342 2e655798019 15340->15342 15341->15342 15343 2e65579800f free 15341->15343 15343->15342 15344 2e655792874 15345 2e65579288e 15344->15345 15346 2e655792893 LoadLibraryA 15345->15346 15347 2e655792898 15345->15347 15346->15347 15562 2e655793254 15563 2e6557932c0 15562->15563 15564 2e655793266 15562->15564 15564->15563 15566 2e655795660 15564->15566 15567 2e6557956a3 15566->15567 15568 2e655795665 15566->15568 15567->15564 15569 2e6557954cc 4 API calls 15568->15569 15570 2e655795687 15568->15570 15569->15570 15570->15567 15571 2e655794c20 free 15570->15571 15571->15567 15596 2e6557956b4 15597 2e6557956d1 15596->15597 15598 2e65579575d 15597->15598 15599 2e65579574f 15597->15599 15601 2e655794630 free 15597->15601 15599->15598 15600 2e6557952c0 free 15599->15600 15600->15598 15601->15599 15572 2e655792a46 15573 2e655792a5b 15572->15573 15574 2e655792a69 15573->15574 15575 2e6557945b0 free 15573->15575 15575->15574 15481 2e6557933c8 15482 2e6557933db 15481->15482 15483 2e655793432 15482->15483 15485 2e655794804 15482->15485 15487 2e65579482a 15485->15487 15486 2e655794832 15486->15483 15487->15486 15489 2e655794896 15487->15489 15491 2e6557b9530 15487->15491 15489->15486 15490 2e6557945b0 free 15489->15490 15490->15486 15492 2e6557b9574 15491->15492 15493 2e6557b9547 15491->15493 15492->15489 15493->15492 15495 2e6557b8694 15493->15495 15496 2e6557b86d2 15495->15496 15498 2e6557b86ba 15495->15498 15496->15498 15499 2e6557b9484 15496->15499 15498->15492 15500 2e6557b94b6 15499->15500 15501 2e6557b9493 15499->15501 15500->15498 15501->15500 15503 2e6557b7f04 15501->15503 15506 2e6557b7dd0 15503->15506 15505 2e6557b7f4d 15505->15500 15507 2e6557b7df4 socket 15506->15507 15509 2e6557b7e0c 15506->15509 15508 2e6557b7e27 15507->15508 15507->15509 15508->15509 15510 2e6557b79e0 2 API calls 15508->15510 15509->15505 15510->15509 15592 2e655794ac8 15593 2e655794ae1 15592->15593 15594 2e655794b5b 15593->15594 15595 2e655794630 free 15593->15595 15595->15594 15355 2e65579302c 15359 2e65579305f 15355->15359 15356 2e65579306c 15362 2e6557945b0 15356->15362 15358 2e655793071 15359->15356 15360 2e6557930eb 15359->15360 15366 2e655794630 15360->15366 15363 2e6557945c2 15362->15363 15365 2e6557945db 15363->15365 15370 2e655794520 15363->15370 15365->15358 15367 2e655794656 15366->15367 15369 2e6557946aa 15366->15369 15367->15369 15384 2e655799e94 15367->15384 15371 2e65579453b 15370->15371 15373 2e65579454c 15371->15373 15374 2e655798038 15371->15374 15373->15365 15376 2e6557980fa 15374->15376 15377 2e655798041 15374->15377 15375 2e655797ff4 free 15375->15376 15376->15373 15379 2e6557980cb 15377->15379 15380 2e655797ff4 15377->15380 15379->15375 15379->15376 15381 2e655797ff9 15380->15381 15382 2e655798019 15380->15382 15381->15382 15383 2e65579800f free 15381->15383 15382->15379 15383->15382 15385 2e655799eae 15384->15385 15389 2e655799ed3 15384->15389 15385->15389 15390 2e655799e1c 15385->15390 15389->15367 15391 2e655799e2c 15390->15391 15393 2e655799e86 15390->15393 15391->15393 15398 2e655799dd4 15391->15398 15393->15389 15394 2e655797ef4 15393->15394 15395 2e655797f04 15394->15395 15397 2e655797f21 15394->15397 15395->15397 15408 2e655797ec4 15395->15408 15397->15389 15399 2e655799e0f 15398->15399 15401 2e655799de2 15398->15401 15399->15393 15400 2e655799df9 15400->15399 15402 2e655797ef4 free 15400->15402 15401->15399 15401->15400 15404 2e655799aac 15401->15404 15402->15399 15405 2e655799ac3 15404->15405 15406 2e655797ff4 free 15405->15406 15407 2e655799ad6 15405->15407 15406->15407 15407->15400 15409 2e655797ed2 15408->15409 15410 2e655797ee8 15408->15410 15409->15410 15412 2e65579f11c 15409->15412 15410->15395 15413 2e65579f130 15412->15413 15415 2e65579f16f 15412->15415 15413->15415 15416 2e6557999d4 15413->15416 15415->15410 15417 2e6557999ee 15416->15417 15418 2e655797ff4 free 15417->15418 15419 2e655799a1e 15417->15419 15418->15419 15419->15415 15420 2e65579436c 15421 2e655794386 15420->15421 15423 2e6557943c6 15421->15423 15424 2e655794110 15421->15424 15425 2e655794127 15424->15425 15427 2e655794188 15424->15427 15425->15427 15428 2e65579a9f4 15425->15428 15427->15423 15429 2e65579aa14 15428->15429 15434 2e65579abe0 15428->15434 15430 2e655799e1c free 15429->15430 15429->15434 15431 2e65579aa22 15430->15431 15432 2e655797ef4 free 15431->15432 15433 2e65579aa40 15431->15433 15431->15434 15432->15433 15433->15434 15435 2e655799aac free 15433->15435 15436 2e655797ef4 free 15433->15436 15434->15425 15435->15433 15436->15433 15583 2e65579542c 15584 2e65579544a 15583->15584 15585 2e655795454 15584->15585 15586 2e655795487 15584->15586 15587 2e655794c20 free 15585->15587 15588 2e655794c20 free 15586->15588 15589 2e655795472 15587->15589 15588->15589 15590 2e6557952c0 free 15589->15590 15591 2e655795476 15589->15591 15590->15591

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: Information$QuerySystemVolume
                                                        • String ID:
                                                        • API String ID: 2187445334-0
                                                        • Opcode ID: 9cda15ed55e2a7ba7de315ef6492aa6becad9ce158532766a68201cba1800474
                                                        • Instruction ID: 62e5a5794707cbf66cb003386be87e922877392b8527d0913abff8601d0f7265
                                                        • Opcode Fuzzy Hash: 9cda15ed55e2a7ba7de315ef6492aa6becad9ce158532766a68201cba1800474
                                                        • Instruction Fuzzy Hash: 4B91BE31208E494FE7A5FB34C88D7EA77F1FB68351F500A2EA45BC32A1EE3495458B81

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 238 2e655792ac4-2e655792bb5 call 2e655793b44 call 2e655791030 call 2e655791914 call 2e655791488 call 2e6557916a0 call 2e655791488 call 2e6557911dc call 2e655791488 call 2e6557911dc call 2e655791488 call 2e6557911dc 262 2e655792bbb-2e655792bc3 call 2e6557c2736 238->262 263 2e655792dba-2e655792dd5 call 2e655791488 call 2e6557917dc 238->263 266 2e655792bc8-2e655792bcd 262->266 272 2e655792dda-2e655792df6 263->272 268 2e655792bcf-2e655792bd2 266->268 269 2e655792bd4-2e655792bf0 266->269 268->269 271 2e655792c01-2e655792c03 268->271 269->271 286 2e655792bf2-2e655792bff call 2e6557c2736 269->286 274 2e655792c05-2e655792c08 271->274 275 2e655792c19-2e655792c1c 271->275 281 2e655792df8-2e655792e38 call 2e655794a20 call 2e655795dc6 272->281 282 2e655792e3b-2e655792e50 call 2e655793cb0 272->282 274->263 278 2e655792c0e-2e655792c17 274->278 275->263 276 2e655792c22-2e655792c25 275->276 279 2e655792c27-2e655792c2e 276->279 278->275 284 2e655792c30 279->284 285 2e655792c32-2e655792c38 279->285 281->282 284->285 285->279 290 2e655792c3a-2e655792c5b call 2e655791488 call 2e6557917dc 285->290 286->271 300 2e655792c5d-2e655792c64 290->300 301 2e655792da3-2e655792da9 300->301 302 2e655792c6a-2e655792d9e call 2e655791914 call 2e655791488 call 2e655795dcc call 2e655791488 * 2 call 2e655795dcc call 2e655791488 * 2 call 2e655795dcc call 2e655791488 * 2 call 2e655795dcc call 2e655791488 * 2 call 2e6557916a0 call 2e655791488 call 2e655795dcc call 2e655791488 300->302 301->300 303 2e655792daf-2e655792db8 301->303 302->301 303->272
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID:
                                                        • String ID:
                                                        • API String ID:
                                                        • Opcode ID: 703e722334347091989988504ac40cbefe3db69d05a69e833e7a4d3043c5a1eb
                                                        • Instruction ID: 125a6e7c7b79e620a22b01ab4cc0ce5eb5e0caddcd69e4e75d8c6602544dc9df
                                                        • Opcode Fuzzy Hash: 703e722334347091989988504ac40cbefe3db69d05a69e833e7a4d3043c5a1eb
                                                        • Instruction Fuzzy Hash: 00B18131358A494BE746FB24C89DBDA77F1FBA8344F80062DA48BC3196DE24E615CB91

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: socket$ErrorModegetsockopt
                                                        • String ID:
                                                        • API String ID: 552242919-0
                                                        • Opcode ID: 5a3a09ad36e99d91617d654de1f36bf2412fe4f51233c70e6a56741e3c3ef59c
                                                        • Instruction ID: 516bbeeef748cbc59c0748fbd4747ddfc1d1c7aa7f99654f90366fe182639ada
                                                        • Opcode Fuzzy Hash: 5a3a09ad36e99d91617d654de1f36bf2412fe4f51233c70e6a56741e3c3ef59c
                                                        • Instruction Fuzzy Hash: 06412430618A488FE758EF28D89C69977E1FBA8310F40872EE057C36E5EF398504CB41

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: File$CreateMappingView
                                                        • String ID:
                                                        • API String ID: 3452162329-0
                                                        • Opcode ID: d524499d0e29cdaf98b4d00c754c14caea704ede928588d45a67ef148b981a3e
                                                        • Instruction ID: d742a9eb99416adf20abf7e9d05d0c87bbde50b89c46408bd8652a40438eeaaa
                                                        • Opcode Fuzzy Hash: d524499d0e29cdaf98b4d00c754c14caea704ede928588d45a67ef148b981a3e
                                                        • Instruction Fuzzy Hash: 8A517F3161CB888BD725EB65C8897EABBE0FB95341F40492FA4DAC2291DF349505CB92

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: Completion$CreateFileModesNotificationPort
                                                        • String ID:
                                                        • API String ID: 3755109111-0
                                                        • Opcode ID: c6288dfa1786a6fb75177450ca3c1fe821ae558465ed26039621da67ec740ac4
                                                        • Instruction ID: 076fdbdb3b349eef394631cc48612e9306196bdfc6955647e27353b0866e86c8
                                                        • Opcode Fuzzy Hash: c6288dfa1786a6fb75177450ca3c1fe821ae558465ed26039621da67ec740ac4
                                                        • Instruction Fuzzy Hash: 0731B2703545994FFBA8AB2CD88D3797AD4F7643A5FD001ADE80BD21D2EB25CD418781

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: InformationVolume
                                                        • String ID:
                                                        • API String ID: 2039140958-0
                                                        • Opcode ID: 59036ef0396e356dc6f6313af6403c98a85e650be2999bddb75ebc14ecc77cbe
                                                        • Instruction ID: 5a5772e355086022b1eccb779cf02e457a110677ce385a7e313695520cd87518
                                                        • Opcode Fuzzy Hash: 59036ef0396e356dc6f6313af6403c98a85e650be2999bddb75ebc14ecc77cbe
                                                        • Instruction Fuzzy Hash: 3C5111312587488BE76AEB24C89C7EBB7F1FBA4340F504A2DE08AC2191EF759505CB42

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: socket
                                                        • String ID:
                                                        • API String ID: 98920635-0
                                                        • Opcode ID: 7ccfdc6c01b82d6bb1a71dce0885d899065f286cb590b5326cb92d22b59c2518
                                                        • Instruction ID: b784c998446d9642f3d7e4e2924df7738830eaa80e81cc3443b723985a22eb26
                                                        • Opcode Fuzzy Hash: 7ccfdc6c01b82d6bb1a71dce0885d899065f286cb590b5326cb92d22b59c2518
                                                        • Instruction Fuzzy Hash: F12190303446044FEB58AB78D88D7693BD1FB68375F6047ADE82AC72D6EB258C418691

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: ErrorMode
                                                        • String ID:
                                                        • API String ID: 2340568224-0
                                                        • Opcode ID: 393edf68712105e001428b4aafcbbbb097da0f947cd5e6f2a07d9e58f078e8c4
                                                        • Instruction ID: 771b9b4f97d8caecf818c0f889f76ac60ab09319c1185980192a12f76f502078
                                                        • Opcode Fuzzy Hash: 393edf68712105e001428b4aafcbbbb097da0f947cd5e6f2a07d9e58f078e8c4
                                                        • Instruction Fuzzy Hash: E4019630394E890AFB59B3B4C85D3BD26E6FBE4390FC4016D690AD31D6DE14C9144661

                                                        Control-flow Graph

                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: AddressCallerProc
                                                        • String ID:
                                                        • API String ID: 2663294120-0
                                                        • Opcode ID: 9acc209a63f3bfe3531e109f9954961de4b4815462c4a09656cea33e1b416fa5
                                                        • Instruction ID: a4c9c0b1746f269ca50b75581a76b55f02cd21d6572a64df5a0931ff4c6c4210
                                                        • Opcode Fuzzy Hash: 9acc209a63f3bfe3531e109f9954961de4b4815462c4a09656cea33e1b416fa5
                                                        • Instruction Fuzzy Hash: 8DE0C211704D090BAB6861AE648C67655D6D7EC2B2B44027FE41CC3295ED10CC5103A0

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 223 2e655792874-2e655792891 call 2e655791994 226 2e655792893-2e655792896 LoadLibraryA 223->226 227 2e655792898-2e65579289e 223->227 226->227
                                                        APIs
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: LibraryLoad
                                                        • String ID:
                                                        • API String ID: 1029625771-0
                                                        • Opcode ID: 382c3635b645ee6af092a9e813f7fba1e2c89dd6e7ba9d0495e7ab367bb23739
                                                        • Instruction ID: 14902450682d91b2045d515ebccd47bfbbe61137e1876a69c42de1bd5c039e1b
                                                        • Opcode Fuzzy Hash: 382c3635b645ee6af092a9e813f7fba1e2c89dd6e7ba9d0495e7ab367bb23739
                                                        • Instruction Fuzzy Hash: 7AD0A710360D0E1BEA48637D5C9C77515D9F7EC365F90113EB409C2281D958CC550350

                                                        Control-flow Graph

                                                        • Executed
                                                        • Not Executed
                                                        control_flow_graph 228 2e655797ff4-2e655797ff7 229 2e655798035 228->229 230 2e655797ff9-2e655798008 228->230 231 2e655798019-2e655798034 call 2e65579ac54 230->231 232 2e65579800a-2e655798013 call 2e6557a0db0 free 230->232 231->229 232->231
                                                        APIs
                                                        • free.MSVCRT(?,?,?,?,?,?,?,000002E6557980FA,?,?,?,?,?,?,?,000002E65579454C), ref: 000002E655798013
                                                        Memory Dump Source
                                                        • Source File: 00000008.00000002.2913120685.000002E655790000.00000040.00000400.00020000.00000000.sdmp, Offset: 000002E655790000, based on PE: false
                                                        Joe Sandbox IDA Plugin
                                                        • Snapshot File: hcaresult_8_2_2e655790000_dllhost.jbxd
                                                        Similarity
                                                        • API ID: free
                                                        • String ID:
                                                        • API String ID: 1294909896-0
                                                        • Opcode ID: 87bf2b7766d88df3a9026e9b77d2279797cbf1b8374387caf5c71efd3627d98c
                                                        • Instruction ID: 6cf932e4647dff208c56ba8931a1b9af4089f6f5200f4b9ab7638304999e2142
                                                        • Opcode Fuzzy Hash: 87bf2b7766d88df3a9026e9b77d2279797cbf1b8374387caf5c71efd3627d98c
                                                        • Instruction Fuzzy Hash: 84E0D830345D094BFF5CFB68C49C7383BA5FB68341F80006C5406C22A3CA14DC45D340