Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Fast Download.exe

Overview

General Information

Sample name:Fast Download.exe
Analysis ID:1575633
MD5:97d80681daef809909ac1b1e3b9898ba
SHA1:f0ecc4ef701ea6ff61290f6fd4407049cd904e60
SHA256:345d5d2759abd08a84c4c2e2a337a1babd02b5eda3921db1b83eb5d5f5ccc011
Tags:exeNjRATuser-lontze7
Infos:

Detection

Njrat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Njrat
.NET source code contains potential unpacker
AI detected suspicious sample
Disables zone checking for all users
Machine Learning detection for sample
Uses cmd line tools excessively to alter registry or file data
Allocates memory with a write watch (potentially for evading sandboxes)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • Fast Download.exe (PID: 7752 cmdline: "C:\Users\user\Desktop\Fast Download.exe" MD5: 97D80681DAEF809909AC1B1E3B9898BA)
    • attrib.exe (PID: 7956 cmdline: attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.exe" MD5: 0E938DD280E83B1596EC6AA48729C2B0)
      • conhost.exe (PID: 7972 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • attrib.exe (PID: 7964 cmdline: attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Windows.exe" MD5: 0E938DD280E83B1596EC6AA48729C2B0)
      • conhost.exe (PID: 7984 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
NjRATRedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
  • AQUATIC PANDA
  • Earth Lusca
  • Operation C-Major
  • The Gorgon Group
https://malpedia.caad.fkie.fraunhofer.de/details/win.njrat
{"Host": "late-lil.at.ply.gg", "Port": "35022", "Registry Value": "Windows", "Auto Run": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Campaign ID": "Crash", "Network Seprator": "|-F-|", "Install Dir": "TEMP", "Install Name": "Payload.exe", "Version": "v2.0"}
SourceRuleDescriptionAuthorStrings
Fast Download.exeJoeSecurity_NjratYara detected NjratJoe Security
    Fast Download.exeWindows_Trojan_Njrat_30f3c220unknownunknown
    • 0x4c2e:$a1: get_Registry
    • 0x5ac4:$a2: SEE_MASK_NOZONECHECKS
    • 0x5c9f:$a4: cmd.exe /c ping 0 -n 2 & del "
    • 0x5c3f:$a5: netsh firewall delete allowedprogram "
    • 0x5bbd:$a6: [+] System :
    Fast Download.exeCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
    • 0x5c9f:$x1: cmd.exe /c ping 0 -n 2 & del "
    • 0x58de:$s3: Executed As
    • 0x4305:$s5: Stub.exe
    Fast Download.exeNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
    • 0x5ac4:$reg: SEE_MASK_NOZONECHECKS
    • 0x58b6:$msg: Execute ERROR
    • 0x58f8:$msg: Execute ERROR
    • 0x5c9f:$ping: cmd.exe /c ping 0 -n 2 & del
    Fast Download.exeINDICATOR_SUSPICIOUS_EXE_ASEP_REG_ReverseDetects file containing reversed ASEP Autorun registry keysditekSHen
    • 0x5602:$s1: nuR\noisreVtnerruC\swodniW\tfosorciM
    Click to see the 2 entries
    SourceRuleDescriptionAuthorStrings
    00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_NjratYara detected NjratJoe Security
      00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmpWindows_Trojan_Njrat_30f3c220unknownunknown
      • 0x4a2e:$a1: get_Registry
      • 0x58c4:$a2: SEE_MASK_NOZONECHECKS
      • 0x5a9f:$a4: cmd.exe /c ping 0 -n 2 & del "
      • 0x5a3f:$a5: netsh firewall delete allowedprogram "
      • 0x59bd:$a6: [+] System :
      00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmpNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
      • 0x58c4:$reg: SEE_MASK_NOZONECHECKS
      • 0x56b6:$msg: Execute ERROR
      • 0x56f8:$msg: Execute ERROR
      • 0x5a9f:$ping: cmd.exe /c ping 0 -n 2 & del
      00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmpINDICATOR_SUSPICIOUS_EXE_ASEP_REG_ReverseDetects file containing reversed ASEP Autorun registry keysditekSHen
      • 0x5402:$s1: nuR\noisreVtnerruC\swodniW\tfosorciM
      00000000.00000002.3756289646.0000000002CE1000.00000004.00000800.00020000.00000000.sdmpINDICATOR_SUSPICIOUS_EXE_ASEP_REG_ReverseDetects file containing reversed ASEP Autorun registry keysditekSHen
      • 0xec8:$s1: nuR\noisreVtnerruC\swodniW\tfosorciM
      Click to see the 2 entries
      SourceRuleDescriptionAuthorStrings
      0.0.Fast Download.exe.5a0000.0.unpackJoeSecurity_NjratYara detected NjratJoe Security
        0.0.Fast Download.exe.5a0000.0.unpackWindows_Trojan_Njrat_30f3c220unknownunknown
        • 0x4c2e:$a1: get_Registry
        • 0x5ac4:$a2: SEE_MASK_NOZONECHECKS
        • 0x5c9f:$a4: cmd.exe /c ping 0 -n 2 & del "
        • 0x5c3f:$a5: netsh firewall delete allowedprogram "
        • 0x5bbd:$a6: [+] System :
        0.0.Fast Download.exe.5a0000.0.unpackCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
        • 0x5c9f:$x1: cmd.exe /c ping 0 -n 2 & del "
        • 0x58de:$s3: Executed As
        • 0x4305:$s5: Stub.exe
        0.0.Fast Download.exe.5a0000.0.unpackNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
        • 0x5ac4:$reg: SEE_MASK_NOZONECHECKS
        • 0x58b6:$msg: Execute ERROR
        • 0x58f8:$msg: Execute ERROR
        • 0x5c9f:$ping: cmd.exe /c ping 0 -n 2 & del
        0.0.Fast Download.exe.5a0000.0.unpackINDICATOR_SUSPICIOUS_EXE_ASEP_REG_ReverseDetects file containing reversed ASEP Autorun registry keysditekSHen
        • 0x5602:$s1: nuR\noisreVtnerruC\swodniW\tfosorciM
        Click to see the 2 entries

        System Summary

        barindex
        Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\Fast Download.exe, ProcessId: 7752, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2024-12-16T07:29:47.764440+010020211761Malware Command and Control Activity Detected192.168.2.1049735147.185.221.22935022TCP
        2024-12-16T07:30:11.691550+010020211761Malware Command and Control Activity Detected192.168.2.1049795147.185.221.22935022TCP
        2024-12-16T07:30:35.705640+010020211761Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:59.742964+010020211761Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:23.787950+010020211761Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:47.841943+010020211761Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:11.887344+010020211761Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:35.947756+010020211761Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:33:00.046436+010020211761Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:24.065571+010020211761Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2024-12-16T07:29:47.764440+010020331321Malware Command and Control Activity Detected192.168.2.1049735147.185.221.22935022TCP
        2024-12-16T07:30:11.691550+010020331321Malware Command and Control Activity Detected192.168.2.1049795147.185.221.22935022TCP
        2024-12-16T07:30:35.705640+010020331321Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:59.742964+010020331321Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:23.787950+010020331321Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:47.841943+010020331321Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:11.887344+010020331321Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:35.947756+010020331321Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:33:00.046436+010020331321Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:24.065571+010020331321Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2024-12-16T07:29:52.881906+010028255641Malware Command and Control Activity Detected192.168.2.1049735147.185.221.22935022TCP
        2024-12-16T07:30:16.972016+010028255641Malware Command and Control Activity Detected192.168.2.1049795147.185.221.22935022TCP
        2024-12-16T07:30:36.234946+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:42.393653+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:42.674946+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:43.893723+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:44.018620+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:44.632028+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:46.552201+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:46.802082+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:46.921925+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:49.220931+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:51.593117+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:51.821014+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:52.760325+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:54.900896+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:30:55.836886+010028255641Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        2024-12-16T07:31:02.667501+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:02.787422+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:06.241064+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:06.957171+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:07.189053+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:07.425922+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:07.661200+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:08.143590+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:09.578417+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:10.281260+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:11.017887+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:11.253038+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:11.988382+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:12.225191+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:14.157286+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:14.649058+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:15.129249+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:15.365074+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:16.078369+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:17.065078+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:17.805051+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:19.165051+010028255641Malware Command and Control Activity Detected192.168.2.1049908147.185.221.22935022TCP
        2024-12-16T07:31:25.911285+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:29.361154+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:31.005178+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:33.357080+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:34.540409+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:34.997183+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:35.229481+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:37.364309+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:39.050340+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:40.017363+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:40.265246+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:42.621397+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:44.750235+010028255641Malware Command and Control Activity Detected192.168.2.1049969147.185.221.22935022TCP
        2024-12-16T07:31:49.061029+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:51.992359+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:53.237322+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:54.414524+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:55.145844+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:57.041384+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:58.521355+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:59.233382+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:31:59.713324+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:01.433317+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:01.917393+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:03.609593+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:05.089326+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:09.646397+010028255641Malware Command and Control Activity Detected192.168.2.1049979147.185.221.22935022TCP
        2024-12-16T07:32:12.250765+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:12.944147+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:22.765470+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:23.477408+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:23.717597+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:26.869543+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:28.548349+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:30.141604+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:32.886099+010028255641Malware Command and Control Activity Detected192.168.2.1049980147.185.221.22935022TCP
        2024-12-16T07:32:38.749598+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:38.870518+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:38.991468+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:39.113248+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:39.233088+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:39.821774+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:40.067067+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:42.975430+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:48.269593+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:49.221528+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:53.720324+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:54.206087+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:55.153709+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:55.871260+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:56.693642+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:32:57.349759+010028255641Malware Command and Control Activity Detected192.168.2.1049981147.185.221.22935022TCP
        2024-12-16T07:33:02.100898+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:02.220964+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:03.517647+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:03.762457+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:03.882617+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:04.006499+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:05.021766+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:05.405116+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:05.525918+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:05.888394+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:10.965676+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:13.734512+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:15.601748+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:19.364435+010028255641Malware Command and Control Activity Detected192.168.2.1049982147.185.221.22935022TCP
        2024-12-16T07:33:29.088362+010028255641Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        2024-12-16T07:33:30.217775+010028255641Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        2024-12-16T07:33:33.421820+010028255641Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        2024-12-16T07:33:34.993855+010028255641Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        2024-12-16T07:33:35.473856+010028255641Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        2024-12-16T07:33:35.697870+010028255641Malware Command and Control Activity Detected192.168.2.1049983147.185.221.22935022TCP
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2024-12-16T07:29:47.884362+010028255631Malware Command and Control Activity Detected192.168.2.1049735147.185.221.22935022TCP
        2024-12-16T07:30:11.811439+010028255631Malware Command and Control Activity Detected192.168.2.1049795147.185.221.22935022TCP
        2024-12-16T07:30:35.825744+010028255631Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2024-12-16T07:29:47.884362+010028384861Malware Command and Control Activity Detected192.168.2.1049735147.185.221.22935022TCP
        2024-12-16T07:30:11.811439+010028384861Malware Command and Control Activity Detected192.168.2.1049795147.185.221.22935022TCP
        2024-12-16T07:30:35.825744+010028384861Malware Command and Control Activity Detected192.168.2.1049852147.185.221.22935022TCP

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: Fast Download.exeAvira: detected
        Source: 0.0.Fast Download.exe.5a0000.0.unpackMalware Configuration Extractor: Njrat {"Host": "late-lil.at.ply.gg", "Port": "35022", "Registry Value": "Windows", "Auto Run": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Campaign ID": "Crash", "Network Seprator": "|-F-|", "Install Dir": "TEMP", "Install Name": "Payload.exe", "Version": "v2.0"}
        Source: Fast Download.exeVirustotal: Detection: 81%Perma Link
        Source: Fast Download.exeReversingLabs: Detection: 84%
        Source: Yara matchFile source: Fast Download.exe, type: SAMPLE
        Source: Yara matchFile source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Fast Download.exe PID: 7752, type: MEMORYSTR
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.6% probability
        Source: Fast Download.exeJoe Sandbox ML: detected
        Source: Fast Download.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
        Source: Fast Download.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppDataJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start MenuJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\userJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior

        Networking

        barindex
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49735 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49735 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49795 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49795 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.10:49795 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.10:49795 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49795 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.10:49735 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.10:49735 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49735 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49852 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49852 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.10:49852 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.10:49852 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49852 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49908 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49908 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49908 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49980 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49980 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49979 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49979 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49980 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49979 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49981 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49981 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49969 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49969 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49981 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49969 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49983 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49983 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.10:49982 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.10:49982 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49982 -> 147.185.221.229:35022
        Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.10:49983 -> 147.185.221.229:35022
        Source: global trafficTCP traffic: 192.168.2.10:49735 -> 147.185.221.229:35022
        Source: Joe Sandbox ViewASN Name: SALSGIVERUS SALSGIVERUS
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: late-lil.at.ply.gg
        Source: Fast Download.exeString found in binary or memory: https://gg.ylp.ta.lil-etal

        E-Banking Fraud

        barindex
        Source: Yara matchFile source: Fast Download.exe, type: SAMPLE
        Source: Yara matchFile source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Fast Download.exe PID: 7752, type: MEMORYSTR

        System Summary

        barindex
        Source: Fast Download.exe, type: SAMPLEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
        Source: Fast Download.exe, type: SAMPLEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
        Source: Fast Download.exe, type: SAMPLEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
        Source: Fast Download.exe, type: SAMPLEMatched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen
        Source: Fast Download.exe, type: SAMPLEMatched rule: Detects executables using attrib with suspicious attributes attributes Author: ditekSHen
        Source: Fast Download.exe, type: SAMPLEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables using attrib with suspicious attributes attributes Author: ditekSHen
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
        Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
        Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
        Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen
        Source: 00000000.00000002.3756289646.0000000002CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen
        Source: Process Memory Space: Fast Download.exe PID: 7752, type: MEMORYSTRMatched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen
        Source: C:\Users\user\Desktop\Fast Download.exeCode function: 0_2_011603700_2_01160370
        Source: C:\Users\user\Desktop\Fast Download.exeCode function: 0_2_011603600_2_01160360
        Source: Fast Download.exe, 00000000.00000002.3755152265.0000000000C5E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemscorwks.dllT vs Fast Download.exe
        Source: Fast Download.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: Fast Download.exe, type: SAMPLEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
        Source: Fast Download.exe, type: SAMPLEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
        Source: Fast Download.exe, type: SAMPLEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
        Source: Fast Download.exe, type: SAMPLEMatched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys
        Source: Fast Download.exe, type: SAMPLEMatched rule: INDICATOR_SUSPICIOUS_EXE_attrib author = ditekSHen, description = Detects executables using attrib with suspicious attributes attributes
        Source: Fast Download.exe, type: SAMPLEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_attrib author = ditekSHen, description = Detects executables using attrib with suspicious attributes attributes
        Source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
        Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
        Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
        Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys
        Source: 00000000.00000002.3756289646.0000000002CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys
        Source: Process Memory Space: Fast Download.exe PID: 7752, type: MEMORYSTRMatched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys
        Source: classification engineClassification label: mal100.phis.troj.evad.winEXE@7/2@1/1
        Source: C:\Users\user\Desktop\Fast Download.exeCode function: 0_2_0566280E AdjustTokenPrivileges,0_2_0566280E
        Source: C:\Users\user\Desktop\Fast Download.exeCode function: 0_2_056627D7 AdjustTokenPrivileges,0_2_056627D7
        Source: C:\Users\user\Desktop\Fast Download.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnkJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeMutant created: NULL
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7972:120:WilError_03
        Source: C:\Users\user\Desktop\Fast Download.exeMutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7984:120:WilError_03
        Source: C:\Users\user\Desktop\Fast Download.exeMutant created: \Sessions\1\BaseNamedObjects\Windows
        Source: Fast Download.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: Fast Download.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
        Source: C:\Users\user\Desktop\Fast Download.exeFile read: C:\Users\desktop.iniJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: Fast Download.exeVirustotal: Detection: 81%
        Source: Fast Download.exeReversingLabs: Detection: 84%
        Source: unknownProcess created: C:\Users\user\Desktop\Fast Download.exe "C:\Users\user\Desktop\Fast Download.exe"
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: C:\Windows\SysWOW64\attrib.exe attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.exe"
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: C:\Windows\SysWOW64\attrib.exe attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Windows.exe"
        Source: C:\Windows\SysWOW64\attrib.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Windows\SysWOW64\attrib.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: C:\Windows\SysWOW64\attrib.exe attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.exe"Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: C:\Windows\SysWOW64\attrib.exe attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Windows.exe"Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: mscoree.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: shfolder.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: sxs.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: scrrun.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: wbemcomn.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: amsi.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: avicap32.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: msvfw32.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Windows\SysWOW64\attrib.exeSection loaded: ulib.dllJump to behavior
        Source: C:\Windows\SysWOW64\attrib.exeSection loaded: fsutilext.dllJump to behavior
        Source: C:\Windows\SysWOW64\attrib.exeSection loaded: ulib.dllJump to behavior
        Source: C:\Windows\SysWOW64\attrib.exeSection loaded: fsutilext.dllJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dllJump to behavior
        Source: Fast Download.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
        Source: Fast Download.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

        Data Obfuscation

        barindex
        Source: Fast Download.exe, L.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
        Source: C:\Users\user\Desktop\Fast Download.exeCode function: 0_2_05700773 push 69E7C360h; ret 0_2_0570078A
        Source: C:\Users\user\Desktop\Fast Download.exeCode function: 0_2_0570064F push 69E7C310h; ret 0_2_05700666

        Persistence and Installation Behavior

        barindex
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: attrib.exe
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: attrib.exe
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: attrib.exeJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess created: attrib.exeJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnkJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnkJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeMemory allocated: C40000 memory reserve | memory write watchJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeMemory allocated: 2CE0000 memory reserve | memory write watchJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeMemory allocated: 1060000 memory commit | memory reserve | memory write watchJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeWindow / User API: threadDelayed 900Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeWindow / User API: threadDelayed 9087Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeWindow / User API: foregroundWindowGot 1772Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exe TID: 7756Thread sleep count: 900 > 30Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exe TID: 7756Thread sleep time: -900000s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exe TID: 7756Thread sleep count: 9087 > 30Jump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exe TID: 7756Thread sleep time: -9087000s >= -30000sJump to behavior
        Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
        Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppDataJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start MenuJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\userJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
        Source: Fast Download.exe, 00000000.00000002.3755152265.0000000000CEA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWrter, system.w
        Source: Fast Download.exe, 00000000.00000002.3755152265.0000000000CEA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll8
        Source: Fast Download.exe, 00000000.00000002.3755152265.0000000000CEA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\P\
        Source: C:\Users\user\Desktop\Fast Download.exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeMemory allocated: page read and write | page guardJump to behavior
        Source: Fast Download.exe, 00000000.00000002.3756289646.0000000002D5C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
        Source: Fast Download.exe, 00000000.00000002.3756289646.0000000002D5C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager@9_l
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Fast Download.exeQueries volume information: C:\ VolumeInformationJump to behavior

        Lowering of HIPS / PFW / Operating System Security Settings

        barindex
        Source: C:\Users\user\Desktop\Fast Download.exeRegistry value created: HKEY_CURRENT_USER\Environment SEE_MASK_NOZONECHECKSJump to behavior

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: Fast Download.exe, type: SAMPLE
        Source: Yara matchFile source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Fast Download.exe PID: 7752, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: Fast Download.exe, type: SAMPLE
        Source: Yara matchFile source: 0.0.Fast Download.exe.5a0000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Fast Download.exe PID: 7752, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
        Command and Scripting Interpreter
        2
        Registry Run Keys / Startup Folder
        1
        Access Token Manipulation
        1
        Masquerading
        OS Credential Dumping1
        Security Software Discovery
        Remote Services1
        Archive Collected Data
        1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        DLL Side-Loading
        2
        Process Injection
        2
        Virtualization/Sandbox Evasion
        LSASS Memory2
        Virtualization/Sandbox Evasion
        Remote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)2
        Registry Run Keys / Startup Folder
        11
        Disable or Modify Tools
        Security Account Manager1
        Process Discovery
        SMB/Windows Admin SharesData from Network Shared Drive1
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
        DLL Side-Loading
        1
        Access Token Manipulation
        NTDS1
        Application Window Discovery
        Distributed Component Object ModelInput Capture1
        Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
        Process Injection
        LSA Secrets2
        File and Directory Discovery
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
        Obfuscated Files or Information
        Cached Domain Credentials11
        System Information Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
        Software Packing
        DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
        DLL Side-Loading
        Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1575633 Sample: Fast Download.exe Startdate: 16/12/2024 Architecture: WINDOWS Score: 100 20 late-lil.at.ply.gg 2->20 24 Suricata IDS alerts for network traffic 2->24 26 Found malware configuration 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 7 other signatures 2->30 8 Fast Download.exe 2 7 2->8         started        signatures3 process4 dnsIp5 22 late-lil.at.ply.gg 147.185.221.229, 35022, 49735, 49795 SALSGIVERUS United States 8->22 32 Uses cmd line tools excessively to alter registry or file data 8->32 34 Disables zone checking for all users 8->34 12 attrib.exe 1 8->12         started        14 attrib.exe 1 8->14         started        signatures6 process7 process8 16 conhost.exe 12->16         started        18 conhost.exe 14->18         started       

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        Fast Download.exe82%VirustotalBrowse
        Fast Download.exe84%ReversingLabsByteCode-MSIL.Backdoor.njRAT
        Fast Download.exe100%AviraTR/Dropper.Gen7
        Fast Download.exe100%Joe Sandbox ML
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        https://gg.ylp.ta.lil-etal0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        s-part-0035.t-0009.t-msedge.net
        13.107.246.63
        truefalse
          high
          late-lil.at.ply.gg
          147.185.221.229
          truetrue
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            https://gg.ylp.ta.lil-etalFast Download.exefalse
            • Avira URL Cloud: safe
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            147.185.221.229
            late-lil.at.ply.ggUnited States
            12087SALSGIVERUStrue
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1575633
            Start date and time:2024-12-16 07:28:37 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 6m 49s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:10
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:Fast Download.exe
            Detection:MAL
            Classification:mal100.phis.troj.evad.winEXE@7/2@1/1
            EGA Information:
            • Successful, ratio: 100%
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 84
            • Number of non-executed functions: 0
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Override analysis time to 240000 for current running targets taking high CPU consumption
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
            • Excluded IPs from analysis (whitelisted): 13.107.246.63, 4.245.163.56
            • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, ctldl.windowsupdate.com, azureedge-t-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenKeyEx calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            TimeTypeDescription
            01:30:12API Interceptor1123980x Sleep call for process: Fast Download.exe modified
            07:29:34AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            147.185.221.229cheker.exeGet hashmaliciousOrcusBrowse
              CheatsCheker.exeGet hashmaliciousOrcusBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                s-part-0035.t-0009.t-msedge.netClient.exeGet hashmaliciousAsyncRATBrowse
                • 13.107.246.63
                backd00rhome.exeGet hashmaliciousMetasploitBrowse
                • 13.107.246.63
                fern_wifi_recon%2.34.exeGet hashmaliciousMetasploitBrowse
                • 13.107.246.63
                CrSpoofer.exeGet hashmaliciousAsyncRATBrowse
                • 13.107.246.63
                ImageMso.Gallery.xllGet hashmaliciousUnknownBrowse
                • 13.107.246.63
                iAERhkhaZC.exeGet hashmaliciousUnknownBrowse
                • 13.107.246.63
                I37faEaz1K.exeGet hashmaliciousLummaCBrowse
                • 13.107.246.63
                6eftz6UKDm.exeGet hashmaliciousCredential FlusherBrowse
                • 13.107.246.63
                Adver Ransomware.exeGet hashmaliciousUnknownBrowse
                • 13.107.246.63
                Starcat Ransomware 32bit.exeGet hashmaliciousStarcatBrowse
                • 13.107.246.63
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                SALSGIVERUSServer1.exeGet hashmaliciousNjratBrowse
                • 147.185.221.17
                njSilent.exeGet hashmaliciousNjratBrowse
                • 147.185.221.19
                Minet.exeGet hashmaliciousNjratBrowse
                • 147.185.221.22
                Discordd.exeGet hashmaliciousAsyncRATBrowse
                • 147.185.221.18
                Discord2.exeGet hashmaliciousAsyncRATBrowse
                • 147.185.221.18
                Discord3.exeGet hashmaliciousAsyncRATBrowse
                • 147.185.221.18
                Loader.exeGet hashmaliciousAsyncRATBrowse
                • 147.185.221.20
                72OWK7wBVH.exeGet hashmaliciousXWormBrowse
                • 147.185.221.24
                aZDwfEKorn.exeGet hashmaliciousXWormBrowse
                • 147.185.221.24
                HdTSntLSMB.exeGet hashmaliciousXWormBrowse
                • 147.185.221.24
                No context
                No context
                Process:C:\Users\user\Desktop\Fast Download.exe
                File Type:MS Windows shortcut, Item id list present, Has Relative path, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
                Category:dropped
                Size (bytes):1232
                Entropy (8bit):2.888801358734272
                Encrypted:false
                SSDEEP:24:8q2CzKgWLgD4/BOmRC87q8MHBJrXE+1sd04qy:8RgDsvRC87tMhJrR1y
                MD5:28D0C8271344646A4430F6C4B9AD1F6A
                SHA1:67B7D902FD587413552A9BFCB908C754BD127B43
                SHA-256:E1C8E50710A323345A1BBAAFC982B91C573A1404DB5E71C71D65E4117808E75C
                SHA-512:446DC44DF95C69B571112BF35E0A0D11E7994565766E676235CA3CFD27501688B1C759DAF616B5908AA107A649699EB6F40D24237075FBB512C144E428C391F7
                Malicious:false
                Reputation:low
                Preview:L..................F.............................................................P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....N.1...........user..:............................................b.r.o.k.....V.1...........AppData.@............................................A.p.p.D.a.t.a.....V.1...........Roaming.@............................................R.o.a.m.i.n.g.....\.1...........Microsoft.D............................................M.i.c.r.o.s.o.f.t.....V.1...........Windows.@............................................W.i.n.d.o.w.s.....`.1...........Start Menu..F............................................S.t.a.r.t. .M.e.n.u.....Z.1...........Programs..B............................................P.r.o.g.r.a.m.s.....V.1...........Startup.@............................................S.t.a.r.t.u.p.....b.2...........Windows.exe.H............................................W.i.n.d.o.w.s...e.x.e....
                Process:C:\Users\user\Desktop\Fast Download.exe
                File Type:MS Windows shortcut, Item id list present, Has Relative path, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
                Category:dropped
                Size (bytes):1052
                Entropy (8bit):2.9330746486067603
                Encrypted:false
                SSDEEP:12:8gl02sXyllEzKg/tz0/CSLwrHj4/3BVwzyDilVBJrXE+1gwbNfB94t2YZ/elFlS0:8d2CzKgWLgD4/BUBJrXE+1NJpqy
                MD5:75CC3C81702869BE4A7EB0FA719E201F
                SHA1:A9551815F38C52EBD27DCBA455B17AAA1D33E746
                SHA-256:CF74A8C383E45F7467390A810E076932CB85AC9C6DEA951C6AE0958E4BAFC05D
                SHA-512:318D96B6B4DF93C201E4F100313DEB2B2A7D93B4EC2829BCE670F055ACAE8C507217176938B2FABE2B632744B7FC1E1449473C06A9FF5E8981E3A512E7BBE538
                Malicious:false
                Reputation:low
                Preview:L..................F.............................................................P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....N.1...........user..:............................................b.r.o.k.....V.1...........AppData.@............................................A.p.p.D.a.t.a.....V.1...........Roaming.@............................................R.o.a.m.i.n.g.....\.1...........Microsoft.D............................................M.i.c.r.o.s.o.f.t.....V.1...........Windows.@............................................W.i.n.d.o.w.s.....\.1...........Templates.D............................................T.e.m.p.l.a.t.e.s.....b.2...........Windows.exe.H............................................W.i.n.d.o.w.s...e.x.e...........\.W.i.n.d.o.w.s...e.x.e.............w.............>.e.L.:..er.=w...............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.
                File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                Entropy (8bit):5.583188702280738
                TrID:
                • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                • Win32 Executable (generic) a (10002005/4) 49.75%
                • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                • Windows Screen Saver (13104/52) 0.07%
                • Generic Win/DOS Executable (2004/3) 0.01%
                File name:Fast Download.exe
                File size:27'648 bytes
                MD5:97d80681daef809909ac1b1e3b9898ba
                SHA1:f0ecc4ef701ea6ff61290f6fd4407049cd904e60
                SHA256:345d5d2759abd08a84c4c2e2a337a1babd02b5eda3921db1b83eb5d5f5ccc011
                SHA512:f90bb8868612f5bc52c07cf90c4e62daf47ba3a3418fae3a82030bff449d62cd83ce185b22fdae632abdb661c8e3a725cc5fa5c44e47ca34f9ccbda6fafd21da
                SSDEEP:384:YL1q6J1G4APO7l0j8YCYPPdR9MZAQk93vmhm7UMKmIEecKdbXTzm9bVhcaW6mr6s:mccEY6AZA/vMHTi9bD
                TLSH:2DC2F82D37B68232D1EE067E9562EA5043B5D04BF633FB0E4CD954DD4B1B38A0A41EE4
                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.c.................d..........~.... ........@.. ....................................@................................
                Icon Hash:90cececece8e8eb0
                Entrypoint:0x40837e
                Entrypoint Section:.text
                Digitally signed:false
                Imagebase:0x400000
                Subsystem:windows gui
                Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Time Stamp:0x63E472FC [Thu Feb 9 04:13:48 2023 UTC]
                TLS Callbacks:
                CLR (.Net) Version:
                OS Version Major:4
                OS Version Minor:0
                File Version Major:4
                File Version Minor:0
                Subsystem Version Major:4
                Subsystem Version Minor:0
                Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                Instruction
                jmp dword ptr [00402000h]
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IMPORT0x83280x53.text
                IMAGE_DIRECTORY_ENTRY_RESOURCE0xa0000x240.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                IMAGE_DIRECTORY_ENTRY_BASERELOC0xc0000xc.reloc
                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x20000x63840x6400d88204e814d8dfe59e4daf621c442751False0.4735546875data5.6289662693846205IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .rsrc0xa0000x2400x4005b346ed223699f15252c1fdad182859fFalse0.3134765625data4.968771659524424IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .reloc0xc0000xc0x200d9f8966941971e46f1f81f427591a2e8False0.044921875data0.07763316234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                NameRVASizeTypeLanguageCountryZLIB Complexity
                RT_MANIFEST0xa0580x1e7XML 1.0 document, ASCII text, with CRLF line terminators0.5338809034907598
                DLLImport
                mscoree.dll_CorExeMain
                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                2024-12-16T07:29:47.764440+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049735147.185.221.22935022TCP
                2024-12-16T07:29:47.764440+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049735147.185.221.22935022TCP
                2024-12-16T07:29:47.884362+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.1049735147.185.221.22935022TCP
                2024-12-16T07:29:47.884362+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.1049735147.185.221.22935022TCP
                2024-12-16T07:29:52.881906+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049735147.185.221.22935022TCP
                2024-12-16T07:30:11.691550+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049795147.185.221.22935022TCP
                2024-12-16T07:30:11.691550+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049795147.185.221.22935022TCP
                2024-12-16T07:30:11.811439+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.1049795147.185.221.22935022TCP
                2024-12-16T07:30:11.811439+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.1049795147.185.221.22935022TCP
                2024-12-16T07:30:16.972016+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049795147.185.221.22935022TCP
                2024-12-16T07:30:35.705640+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:35.705640+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:35.825744+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:35.825744+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:36.234946+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:42.393653+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:42.674946+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:43.893723+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:44.018620+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:44.632028+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:46.552201+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:46.802082+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:46.921925+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:49.220931+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:51.593117+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:51.821014+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:52.760325+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:54.900896+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:55.836886+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049852147.185.221.22935022TCP
                2024-12-16T07:30:59.742964+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:30:59.742964+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:02.667501+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:02.787422+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:06.241064+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:06.957171+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:07.189053+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:07.425922+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:07.661200+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:08.143590+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:09.578417+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:10.281260+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:11.017887+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:11.253038+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:11.988382+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:12.225191+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:14.157286+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:14.649058+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:15.129249+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:15.365074+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:16.078369+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:17.065078+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:17.805051+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:19.165051+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049908147.185.221.22935022TCP
                2024-12-16T07:31:23.787950+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:23.787950+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:25.911285+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:29.361154+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:31.005178+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:33.357080+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:34.540409+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:34.997183+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:35.229481+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:37.364309+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:39.050340+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:40.017363+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:40.265246+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:42.621397+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:44.750235+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049969147.185.221.22935022TCP
                2024-12-16T07:31:47.841943+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:47.841943+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:49.061029+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:51.992359+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:53.237322+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:54.414524+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:55.145844+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:57.041384+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:58.521355+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:59.233382+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:31:59.713324+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:32:01.433317+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:32:01.917393+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:32:03.609593+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:32:05.089326+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:32:09.646397+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049979147.185.221.22935022TCP
                2024-12-16T07:32:11.887344+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:11.887344+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:12.250765+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:12.944147+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:22.765470+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:23.477408+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:23.717597+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:26.869543+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:28.548349+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:30.141604+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:32.886099+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049980147.185.221.22935022TCP
                2024-12-16T07:32:35.947756+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:35.947756+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:38.749598+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:38.870518+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:38.991468+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:39.113248+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:39.233088+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:39.821774+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:40.067067+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:42.975430+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:48.269593+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:49.221528+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:53.720324+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:54.206087+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:55.153709+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:55.871260+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:56.693642+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:32:57.349759+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049981147.185.221.22935022TCP
                2024-12-16T07:33:00.046436+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:00.046436+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:02.100898+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:02.220964+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:03.517647+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:03.762457+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:03.882617+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:04.006499+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:05.021766+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:05.405116+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:05.525918+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:05.888394+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:10.965676+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:13.734512+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:15.601748+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:19.364435+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049982147.185.221.22935022TCP
                2024-12-16T07:33:24.065571+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:24.065571+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:29.088362+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:30.217775+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:33.421820+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:34.993855+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:35.473856+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049983147.185.221.22935022TCP
                2024-12-16T07:33:35.697870+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.1049983147.185.221.22935022TCP
                TimestampSource PortDest PortSource IPDest IP
                Dec 16, 2024 07:29:47.532463074 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:29:47.652254105 CET3502249735147.185.221.229192.168.2.10
                Dec 16, 2024 07:29:47.652359962 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:29:47.764440060 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:29:47.884212017 CET3502249735147.185.221.229192.168.2.10
                Dec 16, 2024 07:29:47.884361982 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:29:48.004115105 CET3502249735147.185.221.229192.168.2.10
                Dec 16, 2024 07:29:52.881906033 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:29:53.001622915 CET3502249735147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:09.554671049 CET3502249735147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:09.554759026 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:11.566200018 CET4973535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:11.567800045 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:11.686060905 CET3502249735147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:11.687603951 CET3502249795147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:11.687724113 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:11.691550016 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:11.811304092 CET3502249795147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:11.811439037 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:11.931415081 CET3502249795147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:16.972016096 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:17.091825962 CET3502249795147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:33.571950912 CET3502249795147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:33.572032928 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:35.580892086 CET4979535022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:35.582067013 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:35.700691938 CET3502249795147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:35.701771975 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:35.701894045 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:35.705640078 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:35.825432062 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:35.825743914 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:35.945528984 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:36.234946012 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:36.356060028 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:42.393652916 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:42.513415098 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:42.674946070 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:42.794972897 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:43.893723011 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:44.013772011 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:44.018620014 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:44.138401985 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:44.632028103 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:44.752397060 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:44.752655983 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:44.872559071 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:44.872788906 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:44.992619991 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:44.992743015 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.112545013 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.112648964 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.232572079 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.232762098 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.352556944 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.352720022 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.472645044 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.472776890 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.592698097 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.592865944 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.712652922 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.712820053 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.832643986 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.832814932 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:45.952594995 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:45.952743053 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.072516918 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.072690010 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.192425966 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.192526102 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.312278032 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.312489033 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.432257891 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.432351112 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.552100897 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.552201033 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.672024965 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.802082062 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:46.921796083 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:46.921925068 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.041724920 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.041841984 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.161560059 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.161627054 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.281336069 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.281404018 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.401230097 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.401302099 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.521095991 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.521169901 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.640966892 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.641088009 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.760885954 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.760960102 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:47.880754948 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:47.880892038 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.000730991 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.000854969 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.120912075 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.121004105 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.241076946 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.242306948 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.370307922 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.371387005 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.532798052 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.536293983 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.736777067 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.736869097 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:48.976761103 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:48.976890087 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:49.213308096 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:49.220798969 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:49.220931053 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:49.456865072 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:49.457035065 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:49.704741955 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:49.704876900 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:49.944777012 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:49.944909096 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:50.186880112 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:50.186965942 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:50.428730965 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:50.428826094 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:50.642751932 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:50.668865919 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:50.669003010 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:50.858283043 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:50.887473106 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:50.887610912 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:51.101239920 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:51.101361990 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:51.348865986 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:51.349041939 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:51.580590963 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:51.592874050 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:51.593116999 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:51.806210995 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:51.820867062 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:51.821013927 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:52.052840948 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:52.053010941 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:52.267069101 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:52.297000885 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:52.299732924 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:52.509021997 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:52.512336969 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:52.756778002 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:52.760324955 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:53.004941940 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:53.008342981 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:53.248842001 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:53.248920918 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:53.492796898 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:53.492881060 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:53.727430105 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:53.732867002 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:53.940505028 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:53.968826056 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:53.968914986 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:54.184937954 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:54.185127020 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:54.414093018 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:54.428853035 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:54.432339907 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:54.657531977 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:54.660969973 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:54.887852907 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:54.900791883 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:54.900896072 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:55.110505104 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:55.129174948 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:55.129370928 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:55.352797031 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:55.352947950 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:55.592830896 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:55.592956066 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:55.836812019 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:55.836885929 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:56.076824903 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:56.076977968 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:56.320822001 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:56.320911884 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:56.560796976 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:56.560873032 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:56.800908089 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:56.801033974 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:56.985711098 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:57.044833899 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:57.045031071 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:57.228816986 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:57.230385065 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:57.436567068 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:57.476862907 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:57.478534937 CET4985235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:57.602984905 CET3502249852147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:59.617337942 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:59.737838984 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:59.738964081 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:59.742964029 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:59.862696886 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:59.866992950 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:30:59.986845016 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:30:59.988411903 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.108609915 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.112307072 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.232137918 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.232217073 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.352045059 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.352360964 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.472176075 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.472349882 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.592097044 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.592310905 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.712138891 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.712255001 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.832134962 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.832300901 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:00.952131987 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:00.953082085 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.106148958 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.106309891 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.329310894 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.351145029 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.352330923 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.449465990 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.449525118 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.449826956 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.472275972 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.476324081 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.569474936 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.572629929 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.596095085 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.596273899 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.692461967 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.696331978 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.716171026 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.716576099 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.816284895 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.816409111 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.836278915 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.838671923 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.936389923 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.940560102 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:01.958492994 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:01.960300922 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.060374975 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.065917969 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.080102921 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.081844091 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.185676098 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.185781956 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.202086926 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.202266932 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.305469990 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.305567026 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.322097063 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.322252989 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.426047087 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.427340984 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.442267895 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.547501087 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.547579050 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.667397022 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.667500973 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.787321091 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.787421942 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:02.907377005 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:02.907569885 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.027410030 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.027496099 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.147403955 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.147615910 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.267406940 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.267520905 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.387227058 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.387295008 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.511384964 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.511518002 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.631385088 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.631537914 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.751355886 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.751684904 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:03.912981987 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:03.913357973 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:04.116848946 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:04.117013931 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:04.335038900 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:04.364969015 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:04.365127087 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:04.580920935 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:04.581098080 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:04.828850985 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:04.831335068 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.052829027 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.076920986 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:05.080938101 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.300846100 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:05.301063061 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.506385088 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.548877954 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:05.549000978 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.752942085 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:05.753158092 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:05.994276047 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:06.000922918 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:06.223797083 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:06.240837097 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:06.241064072 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:06.464564085 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:06.468852997 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:06.708931923 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:06.709167004 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:06.944468975 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:06.956998110 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:06.957170963 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.175777912 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.188875914 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:07.189053059 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.412250996 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.425288916 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:07.425921917 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.645875931 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.660875082 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:07.661200047 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:07.892930031 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:07.893491030 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:08.131428957 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:08.140896082 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:08.143589973 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:08.368324041 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:08.376914978 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:08.612843037 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:08.612914085 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:08.856928110 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:08.857197046 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:09.104907036 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:09.105051041 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:09.331105947 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:09.348942041 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:09.352313995 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:09.570818901 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:09.576936007 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:09.578417063 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:09.812872887 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:09.815783024 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:10.035861969 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:10.061048985 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:10.064382076 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:10.269443989 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:10.280881882 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:10.281260014 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:10.516948938 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:10.517134905 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:10.764964104 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:10.765196085 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.005557060 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.017687082 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:11.017887115 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.242723942 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.252904892 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:11.253037930 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.492927074 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:11.496398926 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.740627050 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.741003990 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:11.977576971 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:11.984880924 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:11.988382101 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.212563992 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.224922895 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:12.225191116 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.456983089 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:12.458983898 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.716236115 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.768316031 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.837923050 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:12.838089943 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:12.957911015 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:12.958260059 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:13.165921926 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:13.204967976 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:13.205135107 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:13.413059950 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:13.413343906 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:13.661025047 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:13.661199093 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:13.908993959 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:13.909323931 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:14.157083035 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:14.157285929 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:14.404886007 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:14.405023098 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:14.639071941 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:14.648936987 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:14.649058104 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:14.881855965 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:14.884892941 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:15.118804932 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:15.128948927 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:15.129249096 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:15.354295969 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:15.364942074 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:15.365073919 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:15.601088047 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:15.603723049 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:15.825711966 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:15.848915100 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:15.849172115 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:16.066376925 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:16.077080011 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:16.078368902 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:16.312987089 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:16.313111067 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:16.565118074 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:16.565778017 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:16.816958904 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:16.817415953 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:17.064980030 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:17.065078020 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:17.308969975 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:17.309104919 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:17.552978039 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:17.553189039 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:17.774054050 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:17.804927111 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:17.805051088 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.020945072 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:18.021107912 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.212385893 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.265013933 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:18.268352985 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.457087994 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:18.457273960 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.667912960 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.705116034 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:18.705924034 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:18.912914991 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:18.913315058 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:19.149447918 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:19.164959908 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:19.165050983 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:19.397043943 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:19.400352955 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:19.644951105 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:19.648396969 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:19.892884016 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:19.896676064 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:20.140955925 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:20.141180992 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:20.389100075 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:20.389173031 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:20.636977911 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:20.637077093 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:20.876302958 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:20.881027937 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:21.085624933 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:21.121200085 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:21.121371031 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:21.332611084 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:21.332880974 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:21.574222088 CET4990835022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:21.580934048 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:21.651042938 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:21.694046021 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:21.694227934 CET3502249908147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:23.661017895 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:23.780703068 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:23.784420013 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:23.787950039 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:23.907659054 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:23.907723904 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.027482033 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.028328896 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.148232937 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.151339054 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.271018982 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.271128893 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.390826941 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.391349077 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.511432886 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.511580944 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.631412983 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.631628990 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.751355886 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.751504898 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.871175051 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.871334076 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:24.991050005 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:24.991336107 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.111268997 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.111341953 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.431241989 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.502616882 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.502799988 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.551136017 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.551167965 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.551254034 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.622536898 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.671041965 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.671185970 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.791095972 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.791212082 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:25.911125898 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:25.911284924 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.031177998 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.031380892 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.151191950 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.151252031 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.271060944 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.271214962 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.391066074 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.391231060 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.511300087 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.511449099 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.631483078 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.631633043 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.751641989 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.751816034 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.871815920 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.871912003 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:26.991916895 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:26.992033958 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.112230062 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.112395048 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.232381105 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.232677937 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.352655888 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.352850914 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.473215103 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.473356962 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.593729973 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.593833923 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.757958889 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.758055925 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:27.961061001 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:27.961301088 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.179404974 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.209109068 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:28.209252119 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.425151110 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:28.425371885 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.647474051 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.673026085 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:28.673113108 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.866540909 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:28.893001080 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:28.893132925 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:29.112965107 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:29.113090992 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:29.325120926 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:29.361031055 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:29.361154079 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:29.569276094 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:29.569380999 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:29.821046114 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:29.821170092 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.069185019 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:30.069331884 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.284379959 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.317019939 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:30.318320990 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.529241085 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:30.529340029 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.760780096 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.777040005 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:30.778636932 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:30.992870092 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:31.005088091 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:31.005177975 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:31.236938000 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:31.237119913 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:31.481132984 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:31.481232882 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:31.728107929 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:31.729055882 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:31.973078012 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:31.973186016 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:32.210988998 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:32.217061996 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:32.419222116 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:32.457042933 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:32.457540989 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:32.665177107 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:32.666538000 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:32.864799976 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:32.913027048 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:32.914788008 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:33.109225988 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:33.109323978 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:33.348937035 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:33.357002020 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:33.357079983 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:33.593029976 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:33.593158007 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:33.837188005 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:33.837270021 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.044317961 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.089029074 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:34.089103937 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.289073944 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:34.290395975 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.531611919 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.537053108 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:34.540409088 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.750904083 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.777192116 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:34.778930902 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.995138884 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:34.997107983 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:34.997183084 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:35.218278885 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:35.229041100 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:35.229480982 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:35.440850973 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:35.441133976 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:35.665013075 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:35.665700912 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:35.872184038 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:35.913206100 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:35.913551092 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:36.101381063 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:36.117017984 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:36.117213011 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:36.331620932 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:36.349100113 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:36.349306107 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:36.581202984 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:36.581423044 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:36.829149008 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:36.829238892 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:37.095467091 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:37.095648050 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:37.360735893 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:37.364309072 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:37.609055042 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:37.610338926 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:37.861150026 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:37.862385988 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:38.109076977 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:38.109178066 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:38.357064009 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:38.360342979 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:38.553808928 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:38.609116077 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:38.610358953 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:38.801141024 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:38.801318884 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:39.027992964 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:39.049079895 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:39.050339937 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:39.274102926 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:39.275933027 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:39.521112919 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:39.524221897 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:39.769179106 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:39.769361019 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:40.017107010 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:40.017363071 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:40.265141964 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:40.265245914 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:40.509232044 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:40.509342909 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:40.757225990 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:40.757369041 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.009094954 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:41.009198904 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.229394913 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.257158995 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:41.257317066 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.454420090 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.477091074 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:41.478357077 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.672209024 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.705241919 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:41.705982924 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:41.921128988 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:41.922388077 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:42.127635956 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:42.169183969 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:42.171364069 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:42.373296022 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:42.373424053 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:42.591034889 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:42.621135950 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:42.621397018 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:42.837076902 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:42.837403059 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:43.085289955 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:43.085481882 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:43.333230972 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:43.333355904 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:43.582185030 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:43.582298994 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:43.800250053 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:43.833350897 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:43.836313009 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.045303106 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:44.046349049 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.255093098 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.293387890 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:44.293597937 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.501152992 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:44.501374960 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.736234903 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.749301910 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:44.750235081 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.942179918 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:44.981180906 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:44.981614113 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:45.189086914 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:45.189395905 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:45.437098980 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:45.437304974 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:45.684175014 CET4996935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:45.685169935 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:45.691406965 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:45.804124117 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:45.804182053 CET3502249969147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:47.707941055 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:47.828134060 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:47.828239918 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:47.841943026 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:47.961872101 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:47.962179899 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.082084894 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.082194090 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.202194929 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.202404976 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.322479010 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.326469898 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.446408033 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.447068930 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.566858053 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.567831993 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.687736034 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.687971115 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.807946920 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:48.808345079 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:48.928250074 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.061028957 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.180933952 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.181052923 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.300921917 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.301239967 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.422370911 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.422446012 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.542263031 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.542350054 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.662169933 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.662271976 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.782874107 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.782996893 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:49.907506943 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:49.907602072 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.069209099 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.069447041 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.273315907 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.273436069 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.394411087 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.396373034 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.516479969 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.520394087 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.642349005 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.643594027 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.763896942 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.764496088 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:50.884566069 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:50.888360977 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.008336067 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.008852959 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.129086971 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.129189014 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.249284029 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.252336025 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.372329950 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.376359940 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.496232986 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.500385046 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.620417118 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.620522022 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.740544081 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.744405031 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.864547014 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.868371010 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:51.988220930 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:51.992358923 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:52.237170935 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:52.237447023 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:52.489350080 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:52.489445925 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:52.741198063 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:52.741298914 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:52.989201069 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:52.989468098 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.227637053 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.237202883 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:53.237322092 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.443264008 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.477200031 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:53.480334044 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.670634985 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.690622091 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:53.691195011 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:53.917421103 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:53.920447111 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:54.169073105 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:54.169218063 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:54.399806023 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:54.414446115 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:54.414524078 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:54.645234108 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:54.645344973 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:54.897396088 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:54.897500992 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:55.145782948 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:55.145843983 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:55.393663883 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:55.393804073 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:55.636034012 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:55.641180992 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:55.866645098 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:55.944417000 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:55.944509983 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:56.113311052 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:56.113471985 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:56.343431950 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:56.365190029 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:56.366719007 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:56.593143940 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:56.593235016 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:56.793885946 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:56.841177940 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:56.842907906 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:57.029639959 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:57.041167021 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:57.041383982 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:57.277389050 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:57.277509928 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:57.525331020 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:57.526325941 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:57.773222923 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:57.775064945 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.021210909 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:58.022592068 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.273313999 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:58.273432970 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.513479948 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.521270990 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:58.521354914 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.731327057 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.761281967 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:58.761570930 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:58.981328011 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:58.981614113 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.217070103 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.233263969 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:59.233381987 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.461349010 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:59.461837053 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.706690073 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.713219881 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:31:59.713324070 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.953105927 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:31:59.953295946 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:00.197279930 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:00.198532104 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:00.445161104 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:00.445410967 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:00.697246075 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:00.697506905 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:00.945158958 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:00.945223093 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:01.189132929 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:01.189193964 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:01.423872948 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:01.433231115 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:01.433316946 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:01.669207096 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:01.669372082 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:01.903707027 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:01.917237043 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:01.917392969 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:02.149409056 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:02.149516106 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:02.397406101 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:02.397567987 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:02.613327026 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:02.645289898 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:02.648374081 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:02.861278057 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:02.861438990 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:03.105873108 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:03.109483004 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:03.353241920 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:03.353421926 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:03.601358891 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:03.609592915 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:03.857332945 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:03.857397079 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:04.106731892 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:04.106823921 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:04.356038094 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:04.357294083 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:04.594583988 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:04.601300001 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:04.841384888 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:04.841501951 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.081217051 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.089224100 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:05.089325905 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.333221912 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:05.334790945 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.559201956 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.581367016 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:05.581485987 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.776504040 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:05.805282116 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:05.805516005 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:06.021475077 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:06.021651983 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:06.269347906 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:06.270797014 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:06.521370888 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:06.521547079 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:06.769671917 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:06.769737005 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.017333984 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:07.017400026 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.230863094 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.269254923 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:07.269387960 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.477202892 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:07.477366924 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.695964098 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.721407890 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:07.721570015 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.936507940 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:07.941205978 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:08.179058075 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:08.181237936 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:08.395797968 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:08.425328016 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:08.425417900 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:08.641927958 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:08.642034054 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:08.889338017 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:08.889502048 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:09.137339115 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:09.137458086 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:09.526151896 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:09.526420116 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:09.646197081 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:09.646397114 CET4997935022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:09.737931013 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:09.766138077 CET3502249979147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:11.763878107 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:11.883822918 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:11.883932114 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:11.887343884 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:12.007103920 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:12.007400036 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:12.127331018 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:12.127820969 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:12.247735977 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:12.250765085 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:12.370577097 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:12.944147110 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.064097881 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.064198971 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.184640884 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.184734106 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.304636955 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.304776907 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.424748898 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.424904108 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.544770956 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.544876099 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.664747953 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.664834023 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.784635067 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.784725904 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:13.904548883 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:13.904769897 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.024574041 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.024652958 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.144417048 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.144540071 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.264303923 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.264398098 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.384083033 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.384336948 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.504183054 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.506448984 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.626208067 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.626571894 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.746309042 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.747088909 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:14.866960049 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:14.867059946 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.029274940 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.029414892 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.149610996 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.152362108 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.353763103 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.353929996 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.474103928 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.474200964 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.594355106 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.594453096 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.714673042 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.714811087 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.835053921 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.835177898 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:15.956623077 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:15.956732988 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:16.076924086 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:16.077017069 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:16.197216988 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:16.197323084 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:16.437505960 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:16.437654018 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:16.682100058 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:16.684351921 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:16.925323963 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:16.925539017 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:17.169277906 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:17.170403004 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:17.413408995 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:17.413592100 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:17.657326937 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:17.657490015 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:17.901360989 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:17.901529074 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:18.145365953 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:18.145487070 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:18.389374971 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:18.389533997 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:18.637281895 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:18.637356997 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:18.881402969 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:18.881506920 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:19.125257015 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:19.125364065 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:19.365278006 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:19.366663933 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:19.609270096 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:19.609373093 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:19.853426933 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:19.856386900 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:20.097315073 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:20.098423004 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:20.341360092 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:20.344525099 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:20.585293055 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:20.585392952 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:20.829313993 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:20.829538107 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:21.063657999 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:21.073837996 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:21.305315018 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:21.305433035 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:21.545420885 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:21.545537949 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:21.789483070 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:21.789668083 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:22.033302069 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:22.033479929 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:22.277451992 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:22.277615070 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:22.521521091 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:22.521630049 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:22.751766920 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:22.765319109 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:22.765470028 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:22.993240118 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:22.993403912 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:23.233457088 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:23.233624935 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:23.477324009 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:23.477407932 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:23.717514038 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:23.717597008 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:23.961360931 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:23.961483955 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:24.201376915 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:24.201570988 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:24.445420980 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:24.445532084 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:24.689295053 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:24.689445972 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:24.929347038 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:24.929450035 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:25.173377991 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:25.173621893 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:25.413274050 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:25.417339087 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:25.653356075 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:25.653501987 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:25.897420883 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:25.897588015 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:26.141508102 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:26.141627073 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:26.385322094 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:26.385494947 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:26.625472069 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:26.625647068 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:26.869415045 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:26.869543076 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:27.113667011 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:27.113806963 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:27.357387066 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:27.357465982 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:27.597491980 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:27.597740889 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:27.845381021 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:27.845546961 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.060636044 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.089354038 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:28.089545965 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.301335096 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:28.301523924 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.531737089 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.545291901 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:28.548348904 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.749228954 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.777396917 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:28.780422926 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:28.989443064 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:28.991640091 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:29.195149899 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:29.235965014 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:29.236402988 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:29.437407017 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:29.437510014 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:29.677341938 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:29.677633047 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:29.898447037 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:29.925479889 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:29.925719023 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:30.118153095 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:30.141443968 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:30.141603947 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:30.358588934 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:30.361385107 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:30.562864065 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:30.601435900 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:30.604370117 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:30.805341005 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:30.808370113 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.028556108 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.053360939 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:31.056370974 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.269421101 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:31.269539118 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.492639065 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.517339945 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:31.517482996 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.737456083 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:31.737612009 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.953274965 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:31.981368065 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:31.981518030 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:32.185832977 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:32.193370104 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:32.405673981 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:32.429600000 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:32.429773092 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:32.642678022 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:32.649468899 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:32.860053062 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:32.886003971 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:32.886099100 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:33.101360083 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:33.101438999 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:33.343422890 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:33.343615055 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:33.585370064 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:33.586534977 CET4998035022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:33.801570892 CET3502249980147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:35.818965912 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:35.938707113 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:35.944489002 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:35.947756052 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.067513943 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.067630053 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.187417030 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.190550089 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.310439110 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.314826965 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.434762955 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.436438084 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.556385040 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.558492899 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.678406000 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.678508997 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.798362017 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.799333096 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:36.919246912 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:36.924371958 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.044200897 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.044939995 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.164781094 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.167541027 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.287291050 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.288407087 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.408206940 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.408288956 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.528121948 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.528204918 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.648045063 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.648219109 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.768049002 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.768205881 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:37.888045073 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:37.888192892 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.008635044 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.008727074 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.128540993 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.128711939 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.293452978 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.293670893 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.497467041 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.497584105 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.740386963 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.749464035 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.749598026 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.864424944 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.864578009 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.870431900 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.870517969 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.985295057 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.985457897 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:38.991384029 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:38.991467953 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.107300997 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.107570887 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.113147974 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.113248110 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.227366924 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.227462053 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.233026028 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.233088017 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.347712040 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.347901106 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.401431084 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.401494026 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.565453053 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.565531015 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.805404902 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:39.821701050 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:39.821774006 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:40.048760891 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:40.066879988 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:40.067066908 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:40.297488928 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:40.297703028 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:40.549478054 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:40.549668074 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:40.766843081 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:40.801486969 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:40.801655054 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:41.017436028 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:41.017455101 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:41.265480042 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:41.265677929 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:41.517591000 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:41.517678976 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:41.769407988 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:41.769642115 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:41.997107983 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.025513887 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:42.025710106 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.245460987 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:42.245563984 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.474076033 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.493622065 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:42.496392012 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.722954035 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.725456953 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:42.957230091 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:42.973504066 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:42.975430012 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:43.205495119 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:43.208400965 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:43.458985090 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:43.459089041 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:43.713591099 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:43.713694096 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:43.969831944 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:43.969997883 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.181494951 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.221539974 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:44.221663952 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.433835983 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:44.436395884 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.657830954 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.685566902 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:44.688592911 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.906692982 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:44.909533024 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:45.135668039 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:45.157401085 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:45.159112930 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:45.380331039 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:45.385473967 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:45.629570961 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:45.629703999 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:45.881520033 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:45.881650925 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:46.098901987 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:46.137451887 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:46.137584925 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:46.349415064 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:46.349515915 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:46.559881926 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:46.597503901 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:46.600385904 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:46.809453011 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:46.811134100 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:47.045573950 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:47.061486006 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:47.063208103 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:47.293910980 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:47.294107914 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:47.545407057 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:47.545496941 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:47.793621063 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:47.793802023 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.018852949 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.045553923 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:48.045686960 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.255614042 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.269510031 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:48.269593000 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.486778021 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.505527020 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:48.505656958 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.741329908 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.741492033 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:48.965847969 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:48.989510059 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:48.989674091 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:49.203685999 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:49.221451998 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:49.221528053 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:49.453448057 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:49.453538895 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:49.677232981 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:49.701417923 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:49.701551914 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:49.929434061 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:49.929599047 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:50.151895046 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:50.177500963 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:50.177647114 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:50.401443958 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:50.401546955 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:50.616664886 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:50.649406910 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:50.649518967 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:50.865436077 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:50.865562916 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:51.075896025 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:51.117801905 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:51.117877007 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:51.325493097 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:51.325609922 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:51.553566933 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:51.573493958 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:51.576391935 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:51.805491924 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:51.808412075 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.041910887 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.057522058 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:52.060374022 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.276772976 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.297466040 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:52.300363064 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.525516987 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:52.525600910 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.773590088 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:52.773710966 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:52.987673998 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.025408030 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:53.025491953 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.241476059 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:53.241592884 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.466702938 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.493391037 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:53.496367931 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.714426994 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.717505932 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:53.720324039 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.955619097 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:53.957565069 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:54.168541908 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:54.205478907 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:54.206087112 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:54.417566061 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:54.417934895 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:54.651364088 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:54.673773050 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:54.676476955 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:54.901519060 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:54.902920008 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.137732983 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.153546095 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:55.153708935 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.367197037 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.389741898 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:55.390707970 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.619379044 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:55.619565964 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.854315042 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:55.871109009 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:55.871259928 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:56.104933977 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:56.107095003 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:56.409020901 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:56.600858927 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:56.600961924 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:56.693559885 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:56.693641901 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:56.849509954 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:56.849575996 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.097009897 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.101509094 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:57.337328911 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.349569082 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:57.349759102 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.564029932 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.589493990 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:57.589802980 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.813518047 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:57.813703060 CET4998135022192.168.2.10147.185.221.229
                Dec 16, 2024 07:32:57.880584955 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:57.933695078 CET3502249981147.185.221.229192.168.2.10
                Dec 16, 2024 07:32:59.895169020 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.015012980 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.015089035 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.046436071 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.166857958 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.166918039 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.286683083 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.286766052 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.406609058 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.406711102 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.526565075 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.526827097 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.646775007 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.646924973 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.766814947 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.768323898 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:00.888292074 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:00.890400887 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.010370016 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.015372038 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.135229111 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.138602018 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.258567095 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.260356903 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.380378008 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.380522966 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.500504971 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.500669003 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.620596886 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.620749950 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.740647078 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.740775108 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.860641956 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.860734940 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:01.980796099 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:01.980874062 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.100797892 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.100898027 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.220841885 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.220963955 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.340840101 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.340924978 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.460922003 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.461056948 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.581062078 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.581140041 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.701091051 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.701172113 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.821150064 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.821218967 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:02.941128969 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:02.941456079 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.061491966 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.061642885 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.277626991 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.362198114 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.380796909 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.380909920 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.397629976 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.397727013 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.500977039 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.501151085 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.517585039 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.517647028 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.620894909 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.623632908 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.637579918 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.639353037 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.743383884 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.746495962 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.759207964 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.762456894 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.866333961 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.871128082 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.882536888 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.882616997 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:03.990986109 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:03.994837046 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:04.002568007 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:04.006499052 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:04.114950895 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:04.115042925 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:04.173804045 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:04.174782991 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:04.294712067 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:04.294979095 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:04.521661043 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:04.521882057 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:04.769609928 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:04.769722939 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:05.021670103 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:05.021765947 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:05.269593954 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:05.405116081 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:05.525244951 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:05.525918007 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:05.645921946 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:05.646558046 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:05.766623974 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:05.766817093 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:05.886626005 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:05.888394117 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.008361101 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.012370110 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.132224083 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.132316113 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.252374887 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.252456903 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.372489929 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.376372099 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.496400118 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.500480890 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.620270014 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.624365091 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.744457006 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.748380899 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.868251085 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.872118950 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:06.992079020 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:06.992878914 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:07.112947941 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:07.116389036 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:07.236330986 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:07.238909006 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:07.358920097 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:07.364480019 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:07.525857925 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:07.526029110 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:07.733689070 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:07.734059095 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:07.981650114 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:07.981827974 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:08.229860067 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:08.230072021 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:08.477643967 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:08.477770090 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:08.729538918 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:08.730686903 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:08.977579117 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:08.978955984 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:09.225677967 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:09.225780964 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:09.469687939 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:09.473567009 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:09.717559099 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:09.717694044 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:09.966021061 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:09.966176033 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:10.228971004 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:10.302522898 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:10.302788019 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:10.477583885 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:10.477709055 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:10.721545935 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:10.721652031 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:10.963466883 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:10.965570927 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:10.965676069 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:11.205637932 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:11.205791950 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:11.453521967 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:11.453640938 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:11.680521011 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:11.697542906 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:11.700382948 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:11.925647974 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:11.928389072 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.177609921 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:12.180397987 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.401134968 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.425503969 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:12.428342104 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.673029900 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.815450907 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.952483892 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:12.952686071 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:12.993621111 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:12.993783951 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:13.072424889 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:13.113768101 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:13.113972902 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:13.277596951 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:13.277769089 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:13.481648922 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:13.481895924 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:13.703821898 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:13.733797073 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:13.734512091 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:13.949652910 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:13.950980902 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.182442904 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.197664022 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:14.200577021 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.410376072 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.433677912 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:14.436486006 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.657619953 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:14.657789946 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.905023098 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:14.905904055 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:15.105000019 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:15.149641037 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:15.149811983 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:15.353530884 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:15.353625059 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:15.581202030 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:15.601629972 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:15.601747990 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:15.825592041 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:15.826416016 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:16.055305004 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:16.073643923 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:16.073733091 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:16.301671028 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:16.302448034 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:16.542052984 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:16.553626060 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:16.783555031 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:16.789638996 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:16.998303890 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.033550024 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:17.033826113 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.246172905 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:17.246270895 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.468703032 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.497664928 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:17.497796059 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.694091082 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.713711023 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:17.713861942 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.939805984 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:17.941659927 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:18.156091928 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:18.185621023 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:18.185710907 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:18.405703068 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:18.405853033 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:18.619363070 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:18.653645039 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:18.654361010 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:18.865721941 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:18.868400097 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:19.110902071 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:19.113782883 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:19.356762886 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:19.361641884 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:19.364434958 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:19.601677895 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:19.601682901 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:19.845700979 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:19.845907927 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.053550959 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.093585014 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:20.093760967 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.297748089 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:20.297837019 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.545766115 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.549674034 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:20.747253895 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.793699026 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:20.796489954 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:20.993762016 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:20.993972063 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.202789068 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.241703987 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:21.244379997 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.453684092 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:21.456490040 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.680119038 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.701666117 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:21.701877117 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.925581932 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:21.925734997 CET4998235022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:21.927571058 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:22.045598984 CET3502249982147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:23.942358017 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.062268972 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.062347889 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.065571070 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.185357094 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.185425997 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.305190086 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.305293083 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.424998045 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.425151110 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.544900894 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.545003891 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.664860010 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.664973021 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.785397053 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.785528898 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:24.905507088 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:24.905651093 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.025882006 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.026024103 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.146348953 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.146492004 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.266503096 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.266611099 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.386754036 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.386873007 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.506891012 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.506989002 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.626784086 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.626935959 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.746869087 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.747015953 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.867607117 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.867691040 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:25.987528086 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:25.987601042 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.107677937 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.107759953 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.227857113 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.228046894 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.348663092 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.348900080 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.469120026 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.469283104 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.589104891 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.589200974 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.708978891 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.709150076 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.829981089 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.830152035 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:26.950627089 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:26.950793028 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:27.070693970 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:27.070822001 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:27.191104889 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:27.191206932 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:27.311965942 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:27.312135935 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:27.473668098 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:27.473799944 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:27.673652887 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:27.673773050 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:27.913821936 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:27.913921118 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:28.136795044 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:28.157776117 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:28.157929897 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:28.377871037 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:28.377966881 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:28.599086046 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:28.621690989 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:28.624404907 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:28.841728926 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:28.844403982 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.074764967 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.085781097 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:29.088361979 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.294172049 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.317678928 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:29.320380926 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.507366896 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.537632942 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:29.537792921 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.749768972 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:29.749866009 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.970957994 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:29.993727922 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:29.993918896 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.200361013 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.217704058 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:30.217775106 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.419322968 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.441692114 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:30.441890955 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.661672115 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:30.664414883 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.867371082 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:30.909603119 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:30.912002087 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:31.109970093 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:31.112449884 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:31.322804928 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:31.353703976 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:31.356420040 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:31.565735102 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:31.565834045 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:31.809756994 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:31.809989929 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.029470921 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.053694963 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:32.053905010 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.269745111 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:32.269963980 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.489834070 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.513648033 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:32.513756037 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.733789921 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:32.733911991 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.936454058 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:32.977766037 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:32.977921009 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:33.177746058 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:33.177947044 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:33.389182091 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:33.421750069 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:33.421819925 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:33.629800081 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:33.629934072 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:33.848797083 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:33.873811960 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:33.873893976 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.089786053 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:34.089979887 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.283037901 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.333781958 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:34.333998919 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.526032925 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:34.526137114 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.750107050 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.780966043 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:34.781110048 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.986567020 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:34.993731976 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:34.993855000 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:35.229738951 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:35.229832888 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:35.455250978 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:35.473764896 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:35.473855972 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:35.684735060 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:35.697737932 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:35.697870016 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:35.925774097 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:35.925868988 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:36.165854931 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:36.166007996 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:36.413734913 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:36.413852930 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:36.657747030 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:36.657957077 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:36.901634932 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:36.904412031 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:37.145674944 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:37.145797014 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:37.385648012 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:37.385727882 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:37.625622988 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:37.625700951 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:37.869699955 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:37.869784117 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.109925985 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:38.110006094 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.327769041 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.353673935 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:38.353790045 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.549189091 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.569760084 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:38.572396994 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.789776087 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:38.792396069 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:38.987284899 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:39.033730030 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:39.036358118 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:39.223356962 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:39.229733944 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:39.469779968 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:39.469882965 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:39.695385933 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:39.713942051 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:39.716459990 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:39.937797070 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:39.940376043 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:40.135483027 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:40.181747913 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:40.184400082 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:40.377808094 CET3502249983147.185.221.229192.168.2.10
                Dec 16, 2024 07:33:40.377918959 CET4998335022192.168.2.10147.185.221.229
                Dec 16, 2024 07:33:40.621741056 CET3502249983147.185.221.229192.168.2.10
                TimestampSource PortDest PortSource IPDest IP
                Dec 16, 2024 07:29:47.262314081 CET5350153192.168.2.101.1.1.1
                Dec 16, 2024 07:29:47.529774904 CET53535011.1.1.1192.168.2.10
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Dec 16, 2024 07:29:47.262314081 CET192.168.2.101.1.1.10x7980Standard query (0)late-lil.at.ply.ggA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Dec 16, 2024 07:29:31.576926947 CET1.1.1.1192.168.2.100xd8a0No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                Dec 16, 2024 07:29:31.576926947 CET1.1.1.1192.168.2.100xd8a0No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false
                Dec 16, 2024 07:29:47.529774904 CET1.1.1.1192.168.2.100x7980No error (0)late-lil.at.ply.gg147.185.221.229A (IP address)IN (0x0001)false

                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:01:29:34
                Start date:16/12/2024
                Path:C:\Users\user\Desktop\Fast Download.exe
                Wow64 process (32bit):true
                Commandline:"C:\Users\user\Desktop\Fast Download.exe"
                Imagebase:0x5a0000
                File size:27'648 bytes
                MD5 hash:97D80681DAEF809909AC1B1E3B9898BA
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, Author: unknown
                • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, Author: JPCERT/CC Incident Response Group
                • Rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse, Description: Detects file containing reversed ASEP Autorun registry keys, Source: 00000000.00000000.1300697966.00000000005A2000.00000002.00000001.01000000.00000003.sdmp, Author: ditekSHen
                • Rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse, Description: Detects file containing reversed ASEP Autorun registry keys, Source: 00000000.00000002.3756289646.0000000002CE1000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:01:29:44
                Start date:16/12/2024
                Path:C:\Windows\SysWOW64\attrib.exe
                Wow64 process (32bit):true
                Commandline:attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.exe"
                Imagebase:0x170000
                File size:19'456 bytes
                MD5 hash:0E938DD280E83B1596EC6AA48729C2B0
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:moderate
                Has exited:true

                Target ID:3
                Start time:01:29:44
                Start date:16/12/2024
                Path:C:\Windows\SysWOW64\attrib.exe
                Wow64 process (32bit):true
                Commandline:attrib +h +r +s "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Windows.exe"
                Imagebase:0x170000
                File size:19'456 bytes
                MD5 hash:0E938DD280E83B1596EC6AA48729C2B0
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:moderate
                Has exited:true

                Target ID:4
                Start time:01:29:44
                Start date:16/12/2024
                Path:C:\Windows\System32\conhost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:0x7ff620390000
                File size:862'208 bytes
                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:5
                Start time:01:29:44
                Start date:16/12/2024
                Path:C:\Windows\System32\conhost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:0x7ff620390000
                File size:862'208 bytes
                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Reset < >

                  Execution Graph

                  Execution Coverage:18.2%
                  Dynamic/Decrypted Code Coverage:100%
                  Signature Coverage:3.5%
                  Total number of Nodes:173
                  Total number of Limit Nodes:6
                  execution_graph 6310 b9b2ba 6311 b9b2e9 WaitForInputIdle 6310->6311 6313 b9b31f 6310->6313 6312 b9b2f7 6311->6312 6313->6311 6529 56600e2 6530 5660102 ReadFile 6529->6530 6532 5660169 6530->6532 6613 56622e2 6614 566230e RegCreateKeyExW 6613->6614 6616 56623b8 6614->6616 6569 b9a23c 6570 b9a25e CloseHandle 6569->6570 6572 b9a298 6570->6572 6617 b9af30 6618 b9af6e RegOpenKeyExW 6617->6618 6620 b9affc 6618->6620 6573 b9ae32 6575 b9ae66 CreateMutexW 6573->6575 6576 b9aee1 6575->6576 6493 b9b035 6496 b9b076 SendMessageTimeoutA 6493->6496 6495 b9b0f9 6496->6495 6322 b9a4aa 6323 b9a50c 6322->6323 6324 b9a4d6 OleInitialize 6322->6324 6323->6324 6325 b9a4e4 6324->6325 6326 1161781 6327 116142a 6326->6327 6332 11617d0 6327->6332 6337 1161839 6327->6337 6342 116189e 6327->6342 6347 1161871 6327->6347 6333 116180b 6332->6333 6334 1161981 6333->6334 6352 1161cc8 6333->6352 6357 1161cd8 6333->6357 6334->6334 6338 1161842 6337->6338 6339 1161981 6338->6339 6340 1161cd8 3 API calls 6338->6340 6341 1161cc8 3 API calls 6338->6341 6340->6339 6341->6339 6343 11618a7 6342->6343 6344 1161981 6343->6344 6345 1161cd8 3 API calls 6343->6345 6346 1161cc8 3 API calls 6343->6346 6344->6344 6345->6344 6346->6344 6348 116187a 6347->6348 6349 1161981 6348->6349 6350 1161cd8 3 API calls 6348->6350 6351 1161cc8 3 API calls 6348->6351 6350->6349 6351->6349 6353 1161d03 KiUserExceptionDispatcher 6352->6353 6354 1161d1f 6353->6354 6355 1161d4c 6354->6355 6362 1162518 6354->6362 6355->6334 6358 1161d03 KiUserExceptionDispatcher 6357->6358 6359 1161d1f 6358->6359 6360 1161d4c 6359->6360 6361 1162518 2 API calls 6359->6361 6360->6334 6361->6360 6363 116255b 6362->6363 6367 56613ae 6363->6367 6370 566131a 6363->6370 6364 116258a 6364->6355 6368 56613fe GetVolumeInformationA 6367->6368 6369 5661406 6368->6369 6369->6364 6371 5661354 GetVolumeInformationA 6370->6371 6373 5661406 6371->6373 6373->6364 6519 1161401 6520 116142a 6519->6520 6521 11617d0 4 API calls 6520->6521 6522 1161871 4 API calls 6520->6522 6523 116189e 4 API calls 6520->6523 6524 1161839 4 API calls 6520->6524 6521->6520 6522->6520 6523->6520 6524->6520 6497 56615fa 6499 566161a LoadLibraryA 6497->6499 6500 5661692 6499->6500 6553 b9b298 6556 b9b2ba WaitForInputIdle 6553->6556 6555 b9b2f7 6556->6555 6382 b9a09a 6383 b9a0cf send 6382->6383 6384 b9a107 6382->6384 6385 b9a0dd 6383->6385 6384->6383 6533 b9a51a 6535 b9a54e GetTokenInformation 6533->6535 6536 b9a5c0 6535->6536 6589 5662a43 6590 5662a66 GetProcessWorkingSetSize 6589->6590 6592 5662ac7 6590->6592 6390 b9ab1e 6391 b9ab4a SetErrorMode 6390->6391 6392 b9ab73 6390->6392 6393 b9ab5f 6391->6393 6392->6391 6537 5660ccd 6538 5660cfa shutdown 6537->6538 6540 5660d58 6538->6540 6557 566034a 6559 566036a WSASocketW 6557->6559 6560 56603de 6559->6560 6577 56627d7 6578 56627e1 AdjustTokenPrivileges 6577->6578 6580 566285f 6578->6580 6597 b9ab81 6598 b9abb2 RegQueryValueExW 6597->6598 6600 b9ac3b 6598->6600 6601 566125e 6603 566128e WSAConnect 6601->6603 6604 56612e2 6603->6604 6481 b9ac82 6482 b9aca6 RegSetValueExW 6481->6482 6484 b9ad27 6482->6484 6485 5662959 6487 566298a GetExitCodeProcess 6485->6487 6488 56629e8 6487->6488 6501 b9a078 6504 b9a09a send 6501->6504 6503 b9a0dd 6504->6503 6561 5662b27 6563 5662b4a SetProcessWorkingSetSize 6561->6563 6564 5662bab 6563->6564 6565 b9aafc 6566 b9ab1e SetErrorMode 6565->6566 6568 b9ab5f 6566->6568 6417 b9bcfe 6420 b9bd36 CreateFileW 6417->6420 6419 b9bd85 6420->6419 6425 b9b3f2 6426 b9b430 DuplicateHandle 6425->6426 6427 b9b468 6425->6427 6428 b9b43e 6426->6428 6427->6426 6605 5660a36 6608 5660a56 MapViewOfFile 6605->6608 6607 5660add 6608->6607 6505 b9a46a 6506 b9a4aa OleInitialize 6505->6506 6508 b9a4e4 6506->6508 6541 56624bb 6542 56624de ioctlsocket 6541->6542 6544 566253f 6542->6544 6445 b9ae66 6446 b9ae9e CreateMutexW 6445->6446 6448 b9aee1 6446->6448 6581 5660f84 6582 5660fa2 GetProcessTimes 6581->6582 6584 5661029 6582->6584 6449 5660102 6450 5660137 ReadFile 6449->6450 6452 5660169 6450->6452 6545 5660880 6546 56608a6 ConvertStringSecurityDescriptorToSecurityDescriptorW 6545->6546 6548 566091f 6546->6548 6453 b9a25e 6454 b9a2c9 6453->6454 6455 b9a28a CloseHandle 6453->6455 6454->6455 6456 b9a298 6455->6456 6509 5662581 6512 56625ba select 6509->6512 6511 5662618 6512->6511 6457 566280e 6458 566283d AdjustTokenPrivileges 6457->6458 6460 566285f 6458->6460 6549 566108c 6551 56610ae getaddrinfo 6549->6551 6552 566115b 6551->6552 6525 b9bdd4 6527 b9be16 GetFileType 6525->6527 6528 b9be78 6527->6528 6609 b9b3cb 6610 b9b3f2 DuplicateHandle 6609->6610 6612 b9b43e 6610->6612 6477 566161a 6479 5661655 LoadLibraryA 6477->6479 6480 5661692 6479->6480 6489 b9bcc7 6491 b9bcfe CreateFileW 6489->6491 6492 b9bd85 6491->6492
                  APIs
                  • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 05662857
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: AdjustPrivilegesToken
                  • String ID:
                  • API String ID: 2874748243-0
                  • Opcode ID: 00c7ecb4868255fd73b08973b44973fd852914798555c6bf2089fc5740f655b8
                  • Instruction ID: 3eeedca76e5dc6a4e045e974ddb2416fb0a609894fa4661b8240af9fde9c6c6d
                  • Opcode Fuzzy Hash: 00c7ecb4868255fd73b08973b44973fd852914798555c6bf2089fc5740f655b8
                  • Instruction Fuzzy Hash: 1121D1755097809FDB128F25DC50B52BFF8EF06310F0884DAE9858F663D235D818DB62
                  APIs
                  • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 05662857
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: AdjustPrivilegesToken
                  • String ID:
                  • API String ID: 2874748243-0
                  • Opcode ID: 247dfec67595160ee11e941c4816d606beacb5eb1f1d478812a3c66157ef6865
                  • Instruction ID: 0eb0b307e012188b011dbd4f6cc7661964e0ff0dad2b981c48fb0598a0170fa7
                  • Opcode Fuzzy Hash: 247dfec67595160ee11e941c4816d606beacb5eb1f1d478812a3c66157ef6865
                  • Instruction Fuzzy Hash: 8A111C755006449FDB60CF55D844B66BBE4EF04220F08C4AEDD468BA52D375E818DF61
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756097641.0000000001160000.00000040.00000800.00020000.00000000.sdmp, Offset: 01160000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_1160000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: bb15f49faf2048fe2147bf05227e6d7b4dc70c6b2c456486725a83825efce8f6
                  • Instruction ID: 27d1c936c9d7513f242af7ad28cb93c06f54dc9369fef89b9bb359617f659e8d
                  • Opcode Fuzzy Hash: bb15f49faf2048fe2147bf05227e6d7b4dc70c6b2c456486725a83825efce8f6
                  • Instruction Fuzzy Hash: C651C230B00200ABDF48FBB59C11BAE76E7ABC9314F144538A505DF7E9DE369D058B90
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756097641.0000000001160000.00000040.00000800.00020000.00000000.sdmp, Offset: 01160000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_1160000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 564c85ed03d4f5204fd361e01c448edb9ec24684e56a1a36c30467d87bdbc921
                  • Instruction ID: 179470d0e90e05a16222292f8601fa7ae5cbd8d19af2482f3c5ff9ad472278bc
                  • Opcode Fuzzy Hash: 564c85ed03d4f5204fd361e01c448edb9ec24684e56a1a36c30467d87bdbc921
                  • Instruction Fuzzy Hash: C151C230B00200ABDF48F7B59C11BAE76EB9BC9304F144538A506DF7E9DE369D058B90

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 359 1161cd8-1161d30 KiUserExceptionDispatcher 363 1161d92-1161e07 359->363 364 1161d32-1161d46 call 1162518 359->364 379 1161e55-1161fa5 363->379 368 1161d4c-1161d8d 364->368 368->379 485 1161fa7 call 11f05df 379->485 486 1161fa7 call 11f0606 379->486 397 1161fac-11621a0 423 11621a2-11621b0 397->423 424 11621b3-11621b9 397->424 423->424 425 11621d1 424->425 426 11621bb-11621be 424->426 428 11621d6-116220b 425->428 426->428 429 11621c0-11621cf 426->429 432 1162210-1162232 428->432 429->432 437 1162234-116224b 432->437 438 116224d-1162264 432->438 443 116229b-11622a3 call 11625d0 437->443 438->443 447 11622a5-11622bc 443->447 448 11622be-11622d2 443->448 451 11622d5-1162329 call 1162682 447->451 448->451 458 116232f-116239d 451->458 466 116239f-11623a2 458->466 467 11623f9-116240b 458->467 468 11623a4-11623ac 466->468 469 11623d0-11623f4 466->469 471 11623ae-11623bc 468->471 472 11623bf-11623c2 468->472 469->467 471->472 473 11623c4-11623c7 472->473 474 11623cb 472->474 473->466 477 11623c9 473->477 474->469 477->467 485->397 486->397
                  APIs
                  • KiUserExceptionDispatcher.NTDLL ref: 01161D12
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756097641.0000000001160000.00000040.00000800.00020000.00000000.sdmp, Offset: 01160000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_1160000_Fast Download.jbxd
                  Similarity
                  • API ID: DispatcherExceptionUser
                  • String ID:
                  • API String ID: 6842923-0
                  • Opcode ID: 8168ebe01a63d4d835ceb6507500648c6c069395345eb2f4a6e6d5657cf4bcc5
                  • Instruction ID: 2694e9feccb58f97e2f08d68f9a76f1edfb6cf2bb2c37b8ade06e374e8a683e6
                  • Opcode Fuzzy Hash: 8168ebe01a63d4d835ceb6507500648c6c069395345eb2f4a6e6d5657cf4bcc5
                  • Instruction Fuzzy Hash: 29F13934B04214CFCB1AFF74D850B5D77B6AF88319B158929D906DB3A8EB369C52CB90

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 488 1161cc8-1161d30 KiUserExceptionDispatcher 492 1161d92-1161e07 488->492 493 1161d32-1161d46 call 1162518 488->493 508 1161e55-1161fa5 492->508 497 1161d4c-1161d8d 493->497 497->508 614 1161fa7 call 11f05df 508->614 615 1161fa7 call 11f0606 508->615 526 1161fac-11621a0 552 11621a2-11621b0 526->552 553 11621b3-11621b9 526->553 552->553 554 11621d1 553->554 555 11621bb-11621be 553->555 557 11621d6-116220b 554->557 555->557 558 11621c0-11621cf 555->558 561 1162210-1162232 557->561 558->561 566 1162234-116224b 561->566 567 116224d-1162264 561->567 572 116229b-11622a3 call 11625d0 566->572 567->572 576 11622a5-11622bc 572->576 577 11622be-11622d2 572->577 580 11622d5-1162329 call 1162682 576->580 577->580 587 116232f-116239d 580->587 595 116239f-11623a2 587->595 596 11623f9-116240b 587->596 597 11623a4-11623ac 595->597 598 11623d0-11623f4 595->598 600 11623ae-11623bc 597->600 601 11623bf-11623c2 597->601 598->596 600->601 602 11623c4-11623c7 601->602 603 11623cb 601->603 602->595 606 11623c9 602->606 603->598 606->596 614->526 615->526
                  APIs
                  • KiUserExceptionDispatcher.NTDLL ref: 01161D12
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756097641.0000000001160000.00000040.00000800.00020000.00000000.sdmp, Offset: 01160000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_1160000_Fast Download.jbxd
                  Similarity
                  • API ID: DispatcherExceptionUser
                  • String ID:
                  • API String ID: 6842923-0
                  • Opcode ID: 4af2233da7973d3109b63001de571b434cca41ec475196467924c7a94233e47a
                  • Instruction ID: f829182a93ea879f9a56a21c6e79c6c09a0580fd3414fa4644684fb818f79573
                  • Opcode Fuzzy Hash: 4af2233da7973d3109b63001de571b434cca41ec475196467924c7a94233e47a
                  • Instruction Fuzzy Hash: 9CD13834B04204DFCB19FF74D950B5D77B6AF88315B248929D906DB3A9EB329C92CB90

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 617 566131a-5661400 GetVolumeInformationA 621 5661406-566142f 617->621
                  APIs
                  • GetVolumeInformationA.KERNEL32(?,00000E24,?,?), ref: 056613FE
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: InformationVolume
                  • String ID:
                  • API String ID: 2039140958-0
                  • Opcode ID: cfff762aca2f8065f7687a0b708a7123fb6c71121510be88ec76ce305ef71783
                  • Instruction ID: 6376a8dab4f1ef0e09374d87747530a0769310bfa769e5306d589f000f70e96b
                  • Opcode Fuzzy Hash: cfff762aca2f8065f7687a0b708a7123fb6c71121510be88ec76ce305ef71783
                  • Instruction Fuzzy Hash: A6415D6140E3C16FD7038B358C61AA2BFB4AF47210F0E45CBD8C4CF5A3D6256959D7A2

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 623 b9af30-b9afc9 627 b9afcb 623->627 628 b9afce-b9afe5 623->628 627->628 630 b9b027-b9b02c 628->630 631 b9afe7-b9affa RegOpenKeyExW 628->631 630->631 632 b9affc-b9b024 631->632 633 b9b02e-b9b033 631->633 633->632
                  APIs
                  • RegOpenKeyExW.KERNEL32(?,00000E24), ref: 00B9AFED
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: Open
                  • String ID:
                  • API String ID: 71445658-0
                  • Opcode ID: f119ca6ca7af2536f8577b4bd0a02f0ca1831d8938ce10378cd5e0e5f7abd02d
                  • Instruction ID: 4770f3eff2d842f28ee89d804d394b328717ebcaa1675eaddae243335b13a7dd
                  • Opcode Fuzzy Hash: f119ca6ca7af2536f8577b4bd0a02f0ca1831d8938ce10378cd5e0e5f7abd02d
                  • Instruction Fuzzy Hash: EF31C4B24043446FEB228B11DC45FA7BFBCEF05324F0885AAE9848B553D325E909CB71

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 638 56622e2-5662366 642 566236b-5662377 638->642 643 5662368 638->643 644 566237c-5662385 642->644 645 5662379 642->645 643->642 646 5662387 644->646 647 566238a-56623a1 644->647 645->644 646->647 649 56623e3-56623e8 647->649 650 56623a3-56623b6 RegCreateKeyExW 647->650 649->650 651 56623ea-56623ef 650->651 652 56623b8-56623e0 650->652 651->652
                  APIs
                  • RegCreateKeyExW.KERNEL32(?,00000E24), ref: 056623A9
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: Create
                  • String ID:
                  • API String ID: 2289755597-0
                  • Opcode ID: 57c67ed0cc4c10f9d3beae92f43db062eaa7931e8a148f0bb4f51da158a258fb
                  • Instruction ID: 8b3ca5c98ea2a1cba0e6ae79fd0232ddf48b6ca83092e36caa811efd11de2c1b
                  • Opcode Fuzzy Hash: 57c67ed0cc4c10f9d3beae92f43db062eaa7931e8a148f0bb4f51da158a258fb
                  • Instruction Fuzzy Hash: 70318172504744AFEB218B51CC44FA7BBFCEF09210F08459AE9859B652D324E908CB61

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 657 b9bcc7-b9bd56 661 b9bd58 657->661 662 b9bd5b-b9bd67 657->662 661->662 663 b9bd69 662->663 664 b9bd6c-b9bd75 662->664 663->664 665 b9bd77-b9bd9b CreateFileW 664->665 666 b9bdc6-b9bdcb 664->666 669 b9bdcd-b9bdd2 665->669 670 b9bd9d-b9bdc3 665->670 666->665 669->670
                  APIs
                  • CreateFileW.KERNEL32(?,?,?,?,?,?), ref: 00B9BD7D
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: CreateFile
                  • String ID:
                  • API String ID: 823142352-0
                  • Opcode ID: ddee3bb1a955e42b67d721e21cb2590b19b91268736f51a9e8117f3551b9cbb3
                  • Instruction ID: 1e257ac8adeac41146e160fa4be4f7c776d4de70195d12b2dc1b0036c2dfb298
                  • Opcode Fuzzy Hash: ddee3bb1a955e42b67d721e21cb2590b19b91268736f51a9e8117f3551b9cbb3
                  • Instruction Fuzzy Hash: A33194B1505340AFEB22CF65DD44F62BFF8EF05314F08449AE9858B652D365E909CB71

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 673 5660257-5660277 674 5660299-56602cb 673->674 675 5660279-5660298 673->675 679 56602ce-5660326 RegQueryValueExW 674->679 675->674 681 566032c-5660342 679->681
                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E24,?,?), ref: 0566031E
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: 97c7191c9552078e3a3e90f0a886e038519ea2ea3c8f1cc3c687be593d2174b1
                  • Instruction ID: 32a35ec9a5e0bf61a929ab0032161161d7201dd86ac2837675c35e178a4a200a
                  • Opcode Fuzzy Hash: 97c7191c9552078e3a3e90f0a886e038519ea2ea3c8f1cc3c687be593d2174b1
                  • Instruction Fuzzy Hash: 5E317C7510E3C06FD3138B258C65A61BFB4EF47610B0E45CBE8C48F6A3D629A919D7B2

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 682 566108c-566114b 688 566119d-56611a2 682->688 689 566114d-5661155 getaddrinfo 682->689 688->689 690 566115b-566116d 689->690 692 56611a4-56611a9 690->692 693 566116f-566119a 690->693 692->693
                  APIs
                  • getaddrinfo.WS2_32(?,00000E24), ref: 05661153
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: getaddrinfo
                  • String ID:
                  • API String ID: 300660673-0
                  • Opcode ID: 41b26d7b5fc5b0bf3f658e0d3aa1703bbc1f74ab2583169d11103b3fd2d06e5b
                  • Instruction ID: ec0a3266bbff95a25feafa48668c8ad41c130862d9680d1ad46d3161133b93b5
                  • Opcode Fuzzy Hash: 41b26d7b5fc5b0bf3f658e0d3aa1703bbc1f74ab2583169d11103b3fd2d06e5b
                  • Instruction Fuzzy Hash: C83191B2505344BFFB21CB51DC84FA6FBACEF05314F04489AFA489B192D775A908CB61

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 697 b9ae32-b9aeb5 701 b9aeba-b9aec3 697->701 702 b9aeb7 697->702 703 b9aec8-b9aed1 701->703 704 b9aec5 701->704 702->701 705 b9aed3-b9aef7 CreateMutexW 703->705 706 b9af22-b9af27 703->706 704->703 709 b9af29-b9af2e 705->709 710 b9aef9-b9af1f 705->710 706->705 709->710
                  APIs
                  • CreateMutexW.KERNEL32(?,?), ref: 00B9AED9
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: CreateMutex
                  • String ID:
                  • API String ID: 1964310414-0
                  • Opcode ID: d331263d6be373b497a808dac11d4399d79b8e742a0798c8abc093838b674788
                  • Instruction ID: 0bd5c0e136c992280b05e6135357e14537a3a580b728b7416215e8353110f476
                  • Opcode Fuzzy Hash: d331263d6be373b497a808dac11d4399d79b8e742a0798c8abc093838b674788
                  • Instruction Fuzzy Hash: B031A4B15097806FEB11CB25DC44B96BFF8EF06310F08849AE944CB292D325E808CB62

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 728 5660f84-5661019 733 5661066-566106b 728->733 734 566101b-5661023 GetProcessTimes 728->734 733->734 735 5661029-566103b 734->735 737 566106d-5661072 735->737 738 566103d-5661063 735->738 737->738
                  APIs
                  • GetProcessTimes.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05661021
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ProcessTimes
                  • String ID:
                  • API String ID: 1995159646-0
                  • Opcode ID: f16178d11434415144a8deedfeb06d60a1cd765d326894e46c1dd6168612314a
                  • Instruction ID: 1b54513e24c398914b1d05cf2662224ab9ed82671dd8f886733d56385b475e15
                  • Opcode Fuzzy Hash: f16178d11434415144a8deedfeb06d60a1cd765d326894e46c1dd6168612314a
                  • Instruction Fuzzy Hash: 8131C5724057806FEB12CF61DC45FA6BFB8EF06314F08849AE9858B553D2259909CBB1

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 713 5660880-5660901 717 5660906-566090f 713->717 718 5660903 713->718 719 5660967-566096c 717->719 720 5660911-5660919 ConvertStringSecurityDescriptorToSecurityDescriptorW 717->720 718->717 719->720 721 566091f-5660931 720->721 723 5660933-5660964 721->723 724 566096e-5660973 721->724 724->723
                  APIs
                  • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000E24), ref: 05660917
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: DescriptorSecurity$ConvertString
                  • String ID:
                  • API String ID: 3907675253-0
                  • Opcode ID: 31103737f464a094f7abfcdee5cec5d6ed2b6a7d2b5d6a18afe1f7f09aa47009
                  • Instruction ID: 7dce28a9ff59cdc06306fbad8de3afbfdc698b3991636c5ccaa337fdb61abd1a
                  • Opcode Fuzzy Hash: 31103737f464a094f7abfcdee5cec5d6ed2b6a7d2b5d6a18afe1f7f09aa47009
                  • Instruction Fuzzy Hash: F5317372508344AFEB21CB65DC45FA7BFF8EF05224F0885AAE945DB652D364E808CB61
                  APIs
                  • GetTokenInformation.KERNELBASE(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9A5B8
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: InformationToken
                  • String ID:
                  • API String ID: 4114910276-0
                  • Opcode ID: b134266616b9347715436b4728ff135908fd2106244e587d3475cd4a0729fc3d
                  • Instruction ID: 465df5d6a6ad385463c0038f8d1bd9836d0209b22fc91df3231cbb9c49900389
                  • Opcode Fuzzy Hash: b134266616b9347715436b4728ff135908fd2106244e587d3475cd4a0729fc3d
                  • Instruction Fuzzy Hash: F23195724093806FEB228B61DC54F96BFB8EF06214F0885DBE985CB553D225A908C7B2
                  APIs
                  • SendMessageTimeoutA.USER32(?,00000E24), ref: 00B9B0F1
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: MessageSendTimeout
                  • String ID:
                  • API String ID: 1599653421-0
                  • Opcode ID: a61ad3940c0f228b02a48d5023018686f82948c74afdb305598cf6ea4b096db8
                  • Instruction ID: 9681315fdaf8ac634a1358e0a66a03af1fad04adc242fac25c76ee5f1eeab71b
                  • Opcode Fuzzy Hash: a61ad3940c0f228b02a48d5023018686f82948c74afdb305598cf6ea4b096db8
                  • Instruction Fuzzy Hash: 3931D472005380AFEB228F60DC45FA2FFB8EF46324F08849EE9854B553D375A808CB65
                  APIs
                  • RegCreateKeyExW.KERNEL32(?,00000E24), ref: 056623A9
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: Create
                  • String ID:
                  • API String ID: 2289755597-0
                  • Opcode ID: f341767dd003b4d944072057ff148328b0d3c9d90cee629230ecebbfe612ca8b
                  • Instruction ID: 3de0d9b113954c50883fbd6c66a6863167d858515aa95608c17046329a083f11
                  • Opcode Fuzzy Hash: f341767dd003b4d944072057ff148328b0d3c9d90cee629230ecebbfe612ca8b
                  • Instruction Fuzzy Hash: 7421BF76500604AFEB21DE15CC80FABBBECEF08214F08855AFA45DBA52D320E808CF61
                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9AC2C
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: a53767aaf362663625af66079d155a92b4732ff0863e7dd5ff55086051eaf578
                  • Instruction ID: 853b6793d67ffce50df12662d92eef1995caebbfd72768bdf07f2ad51aca2cfb
                  • Opcode Fuzzy Hash: a53767aaf362663625af66079d155a92b4732ff0863e7dd5ff55086051eaf578
                  • Instruction Fuzzy Hash: B9318075505740AFEB22CB11CC44F92BFF8EF06710F0885DAE9458B652D324E908CBA1
                  APIs
                  • getaddrinfo.WS2_32(?,00000E24), ref: 05661153
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: getaddrinfo
                  • String ID:
                  • API String ID: 300660673-0
                  • Opcode ID: 705def70233a6a99ffd2d1dc8491f86e3e85a2972a02221d4e51a936bb87c97e
                  • Instruction ID: e31cdfce6902b5179235e9bcdc93a08d0ba07b779568f8033bdcf67b9d1b0f53
                  • Opcode Fuzzy Hash: 705def70233a6a99ffd2d1dc8491f86e3e85a2972a02221d4e51a936bb87c97e
                  • Instruction Fuzzy Hash: 9121BF71500204AEFB21DB51DC84FAAFBACEF04714F04885AEA489B681D7B5A909CBB1
                  APIs
                  • GetFileType.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9BE69
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: FileType
                  • String ID:
                  • API String ID: 3081899298-0
                  • Opcode ID: a81b4142dc5eccc68eb4beca596ed61a3d64d3ce5a3f2149b5df93cbf1042e03
                  • Instruction ID: 540cef09bac08ff9669f8ff2ba60f53adb00a7a44315f42b7475414c72baa518
                  • Opcode Fuzzy Hash: a81b4142dc5eccc68eb4beca596ed61a3d64d3ce5a3f2149b5df93cbf1042e03
                  • Instruction Fuzzy Hash: E721FBB54097806FE7128B21DC41BA2BFBCDF06724F0985D6E9848B253D264990DC771
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: select
                  • String ID:
                  • API String ID: 1274211008-0
                  • Opcode ID: 1bf6fe6a335e05ad4b792d2af6598ec2b064d0259278cd6179afd6f476fb3a0f
                  • Instruction ID: d53b004e725b0f6f7c6d32caaea4e976e7770f423e736d568bf2ebec25ff9959
                  • Opcode Fuzzy Hash: 1bf6fe6a335e05ad4b792d2af6598ec2b064d0259278cd6179afd6f476fb3a0f
                  • Instruction Fuzzy Hash: 4F216B755093809FDB22CF25DC54BA2BFF8EF06214F0884DAE984CB663D265E849DB61
                  APIs
                  • GetExitCodeProcess.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 056629E0
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: CodeExitProcess
                  • String ID:
                  • API String ID: 3861947596-0
                  • Opcode ID: 009f022c2217101065bbee5d9c75f994ff0afbf3994792ee560a84f770ee7a72
                  • Instruction ID: 73f2e6b5476e65578c84208c130f0e2a740102277d1629d0aed2f202dcbbe89f
                  • Opcode Fuzzy Hash: 009f022c2217101065bbee5d9c75f994ff0afbf3994792ee560a84f770ee7a72
                  • Instruction Fuzzy Hash: 3F21A4B55093806FEB12CB15DC45FA6BFB8EF42214F0884DBE944CF693D264A908C7A1
                  APIs
                  • RegSetValueExW.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9AD18
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: Value
                  • String ID:
                  • API String ID: 3702945584-0
                  • Opcode ID: f3ae86193ce46d721320a72327bfdad3a76635e15b553c07e4b268e3ec09cd2d
                  • Instruction ID: e731d9a9b029bf92e3f45ecd806c575d5ccb351351872eb19663a13b0ba5772f
                  • Opcode Fuzzy Hash: f3ae86193ce46d721320a72327bfdad3a76635e15b553c07e4b268e3ec09cd2d
                  • Instruction Fuzzy Hash: 5021A4B25053806FDB228B11DC44F97BFFCEF45314F08859AE9859B652D264E848CBB1
                  APIs
                  • WSASocketW.WS2_32(?,?,?,?,?), ref: 056603D6
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: Socket
                  • String ID:
                  • API String ID: 38366605-0
                  • Opcode ID: 8694a25d76a4bd617eccdc54882ddf6528bd4e39d664477a21c3920e50a27ece
                  • Instruction ID: 47aea5d11b340dbee7ade5fe65a5b30f33d5e18ff4bdaf8bc678709dbcd37337
                  • Opcode Fuzzy Hash: 8694a25d76a4bd617eccdc54882ddf6528bd4e39d664477a21c3920e50a27ece
                  • Instruction Fuzzy Hash: A0219171405380AFEB22CF51DC45FA6FFF8EF05224F08899EE9858B652D375A408CB61
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: FileView
                  • String ID:
                  • API String ID: 3314676101-0
                  • Opcode ID: d328f7eba262a1097a86648fc2693ebba0738a6fd79b166877add47bf5e3c0a2
                  • Instruction ID: 82553c04fa0e6dee6a37616d5f9232c206186f5a8333225d995aba5a1816d8c2
                  • Opcode Fuzzy Hash: d328f7eba262a1097a86648fc2693ebba0738a6fd79b166877add47bf5e3c0a2
                  • Instruction Fuzzy Hash: 8B21D371409340AFE722CF55DC44F96FFF8EF09224F08859EE9858B652D365E508CBA1
                  APIs
                  • CreateFileW.KERNEL32(?,?,?,?,?,?), ref: 00B9BD7D
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: CreateFile
                  • String ID:
                  • API String ID: 823142352-0
                  • Opcode ID: 8c3ea0fb82203ffc55d95f068c46d27c34b4628bfbcd32a8ad15167886940f9c
                  • Instruction ID: fa4ec6f0048b82e0b251bc7262d61467d39d26e24604fd3c6a080c33b1e23f37
                  • Opcode Fuzzy Hash: 8c3ea0fb82203ffc55d95f068c46d27c34b4628bfbcd32a8ad15167886940f9c
                  • Instruction Fuzzy Hash: 58219271501200AFEB21CF65DD85FA6FBE8EF04314F0889ADE9458B652D775E808CB61
                  APIs
                  • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000E24), ref: 05660917
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: DescriptorSecurity$ConvertString
                  • String ID:
                  • API String ID: 3907675253-0
                  • Opcode ID: d7f5741f2c314a77431bc061c98d7381844ed7a6163ac11e42dd8954a5549b27
                  • Instruction ID: 69e0d05f82e263809a8ea65e4606d960284da3a63ce1f67813538d0936509437
                  • Opcode Fuzzy Hash: d7f5741f2c314a77431bc061c98d7381844ed7a6163ac11e42dd8954a5549b27
                  • Instruction Fuzzy Hash: 1421CF72504204AFFB20DF25DC44FAABBACEF04224F08856AE945DB642D374E808CAA1
                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 0566082C
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: 11ac7f8be759dd970503c9ffaa5d6834164c8d0b06787be3e200cf2b6aa06b47
                  • Instruction ID: 296089a4d1f092fc59782d56c987ba604d7a0450df7cd6cb545074b205043e9c
                  • Opcode Fuzzy Hash: 11ac7f8be759dd970503c9ffaa5d6834164c8d0b06787be3e200cf2b6aa06b47
                  • Instruction Fuzzy Hash: EF219072505740AFEB22CB11DC44FA6BFF8EF05220F08859AE9468B652D364E908CBA1
                  APIs
                  • RegOpenKeyExW.KERNEL32(?,00000E24), ref: 00B9AFED
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: Open
                  • String ID:
                  • API String ID: 71445658-0
                  • Opcode ID: cfae6854cc4ded4783f825e5abd90f474c222fcfd8ca74db8f2012622a3d90d5
                  • Instruction ID: b578322679e003c532dfcb2e46d2125dd623382097fd83d4bb79b207b1d4a0ac
                  • Opcode Fuzzy Hash: cfae6854cc4ded4783f825e5abd90f474c222fcfd8ca74db8f2012622a3d90d5
                  • Instruction Fuzzy Hash: A221C6B2500204AEFB219F51DC44FABFBECEF08314F04855AEA45CB652D775E908CAB1
                  APIs
                  • GetProcessWorkingSetSize.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05662ABF
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ProcessSizeWorking
                  • String ID:
                  • API String ID: 3584180929-0
                  • Opcode ID: 572c7d94f7817486d7327e7c5a5cac925210e43d78c6f291f263e4b30b6ffb5b
                  • Instruction ID: 2425d9aa06ea882ce3bf2fa56ea94ab46f70039072d548f028d962ae5625acc9
                  • Opcode Fuzzy Hash: 572c7d94f7817486d7327e7c5a5cac925210e43d78c6f291f263e4b30b6ffb5b
                  • Instruction Fuzzy Hash: 8721A4B55093806FEB22CF51DC44FA6BFB8EF45214F08849BE945CB652D364A908CBA5
                  APIs
                  • SetProcessWorkingSetSize.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05662BA3
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ProcessSizeWorking
                  • String ID:
                  • API String ID: 3584180929-0
                  • Opcode ID: 572c7d94f7817486d7327e7c5a5cac925210e43d78c6f291f263e4b30b6ffb5b
                  • Instruction ID: 9d7c947fc8908b526e651776302b33ae225e9517632f8e78d90546f01e20a4ee
                  • Opcode Fuzzy Hash: 572c7d94f7817486d7327e7c5a5cac925210e43d78c6f291f263e4b30b6ffb5b
                  • Instruction Fuzzy Hash: BB21D4754093806FEB22CF11DC44FA6BFB8EF45214F08849BE944CB652D364A908CBA5
                  APIs
                  • CreateMutexW.KERNEL32(?,?), ref: 00B9AED9
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: CreateMutex
                  • String ID:
                  • API String ID: 1964310414-0
                  • Opcode ID: 92b2a8594427b2a3d1bae954a93caa39cffa62dc11672ffbe2cc3ce3561d8c1f
                  • Instruction ID: 2ea7c03fb76b899d1dab682d2675568d8042cad33dab3123c56cc21a740df4bf
                  • Opcode Fuzzy Hash: 92b2a8594427b2a3d1bae954a93caa39cffa62dc11672ffbe2cc3ce3561d8c1f
                  • Instruction Fuzzy Hash: 38218071501204AFEB20DF65DD85BA6FBE8EF04324F1884AAE9448B641D775E808CAA6
                  APIs
                  • shutdown.WS2_32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05660D50
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: shutdown
                  • String ID:
                  • API String ID: 2510479042-0
                  • Opcode ID: 3072824f83a12a442ca0e6120f661a659323c6a9a8d65acb55174c9e119aa503
                  • Instruction ID: 8ff21040b45b524ebdf5c992cdfc6dd465061bd58451d78c682522809707198f
                  • Opcode Fuzzy Hash: 3072824f83a12a442ca0e6120f661a659323c6a9a8d65acb55174c9e119aa503
                  • Instruction Fuzzy Hash: 5821AAB54093806FEB12CB51DC44F96FFB8EF46224F0885DBE9449F653C364A548CB61
                  APIs
                  • ReadFile.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05660161
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: FileRead
                  • String ID:
                  • API String ID: 2738559852-0
                  • Opcode ID: b534fb93e95fa0b257262253833ea8b7d5569deb8a5317b9e73ed0ba08a333e8
                  • Instruction ID: aabc3a79454c9ce0afc5505f2156b67c07abc8f68e02d8354787d3efff4fdf02
                  • Opcode Fuzzy Hash: b534fb93e95fa0b257262253833ea8b7d5569deb8a5317b9e73ed0ba08a333e8
                  • Instruction Fuzzy Hash: 4021A472405340AFEB22CF51DC44F97FFB8EF45224F08849AE9458B652C335A408CBB1
                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9AC2C
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: b60268c3e4fd5aea730e6ef8c81e5ae9e85f4df0dc4acce6ad2697d80d248ae3
                  • Instruction ID: 70415cd2f99a1553ac7dbc8b9cf45c96c3e226aca78a2f409eaa93159811afad
                  • Opcode Fuzzy Hash: b60268c3e4fd5aea730e6ef8c81e5ae9e85f4df0dc4acce6ad2697d80d248ae3
                  • Instruction Fuzzy Hash: C8219075500604AFEB21CF15DC84FA6BBFCEF04714F0885AAE945CB651D764E808CAB6
                  APIs
                  • GetTokenInformation.KERNELBASE(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9A5B8
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: InformationToken
                  • String ID:
                  • API String ID: 4114910276-0
                  • Opcode ID: d4944c10d5f97cbdc1c1251ab469415f25cff0200c9967a4d790eec0bbf4d6ab
                  • Instruction ID: 0402621d11cf54cd4016b45317da3dcb99c26e25c953eea14e405e7e1636f803
                  • Opcode Fuzzy Hash: d4944c10d5f97cbdc1c1251ab469415f25cff0200c9967a4d790eec0bbf4d6ab
                  • Instruction Fuzzy Hash: FE11A272500204AFEB21CF55DC84FAAB7ECEF14314F04856AE945CB651D775E8488BB6
                  APIs
                  • ioctlsocket.WS2_32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05662537
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ioctlsocket
                  • String ID:
                  • API String ID: 3577187118-0
                  • Opcode ID: b177d93f9f8ed5d2d9e910103532896093c3f3ddc1d1cfbe18c7d313bb83ac77
                  • Instruction ID: ae77c6b9a5a5c596cadcef71c928bfbeb29db4087aed1c1e6532f2cbb572308a
                  • Opcode Fuzzy Hash: b177d93f9f8ed5d2d9e910103532896093c3f3ddc1d1cfbe18c7d313bb83ac77
                  • Instruction Fuzzy Hash: 2E21C3754093806FEB22CF51DC44FA6BFB8EF45214F08849BE9449B652C374A508CBA6
                  APIs
                  • WSASocketW.WS2_32(?,?,?,?,?), ref: 056603D6
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: Socket
                  • String ID:
                  • API String ID: 38366605-0
                  • Opcode ID: 38a3dbaa57729b1ee3484184ba241305cba61d2437bc3550ea538614a8d6dcc8
                  • Instruction ID: b59d577daef2d47a69199f3fbd8907edab23b56b4e13586191a8fd386e050f15
                  • Opcode Fuzzy Hash: 38a3dbaa57729b1ee3484184ba241305cba61d2437bc3550ea538614a8d6dcc8
                  • Instruction Fuzzy Hash: BA21A171501200AFEB21DF55DD45FA6FBE8EF08324F04896EEA458B652D376E409CB61
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: FileView
                  • String ID:
                  • API String ID: 3314676101-0
                  • Opcode ID: 60be45c2c7f5ad9eb1639d4282586579aa56538341784956027c5f50598c2241
                  • Instruction ID: 3af8524613b0780afd542931dc0605ed57350cc40a1e522ef399ef1593055438
                  • Opcode Fuzzy Hash: 60be45c2c7f5ad9eb1639d4282586579aa56538341784956027c5f50598c2241
                  • Instruction Fuzzy Hash: CE21DE71401204AFEB21CF55DD48FA6FBE8EF08324F04856AE9458BA82D376E408CBA1
                  APIs
                  • WSAConnect.WS2_32(?,?,?,?,?,?,?), ref: 056612DA
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: Connect
                  • String ID:
                  • API String ID: 3144859779-0
                  • Opcode ID: 41528b4e417e1b05c4a9fe4e6c8adf023b82cd294e38a2a3a3c31172ecc4e368
                  • Instruction ID: f25f5d5660f46123dfb4a56b46aa0f1bde1afa65fad6b5a759f06fff29565f7d
                  • Opcode Fuzzy Hash: 41528b4e417e1b05c4a9fe4e6c8adf023b82cd294e38a2a3a3c31172ecc4e368
                  • Instruction Fuzzy Hash: B2219F75408380AFDB228F51DC44B62BFF8EF06210F0885DAE9858B663D375E818DB61
                  APIs
                  • SendMessageTimeoutA.USER32(?,00000E24), ref: 00B9B0F1
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: MessageSendTimeout
                  • String ID:
                  • API String ID: 1599653421-0
                  • Opcode ID: 31f3dfaa5754b2fcaf8988a5e61d98ee2fa933503285d2ab3bf16cbc95591c90
                  • Instruction ID: b7b2cfbfab009f3cb4164754329e639ee08bc59672862d01604bc7401c25ffe5
                  • Opcode Fuzzy Hash: 31f3dfaa5754b2fcaf8988a5e61d98ee2fa933503285d2ab3bf16cbc95591c90
                  • Instruction Fuzzy Hash: 8821AF72401200AFEF218F51ED41FA6FBE8EF04714F1885AAEE455A691D375E808DBA5
                  APIs
                  • LoadLibraryA.KERNEL32(?,00000E24), ref: 05661683
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: LibraryLoad
                  • String ID:
                  • API String ID: 1029625771-0
                  • Opcode ID: b1f339912ef01cfd66e0166f657b003ab4217ea0a5e3b1adda3f4b83b16165ef
                  • Instruction ID: 783dde32fb34c18eb5ce47844b18ffaa0c214dc051ae903696a0b52bce07715b
                  • Opcode Fuzzy Hash: b1f339912ef01cfd66e0166f657b003ab4217ea0a5e3b1adda3f4b83b16165ef
                  • Instruction Fuzzy Hash: DA11D3714053406FE721CB11DC85FA6FFB8EF46720F08809AFA449B692D2B5A948CBA5
                  APIs
                  • RegSetValueExW.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9AD18
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: Value
                  • String ID:
                  • API String ID: 3702945584-0
                  • Opcode ID: 358421e04550973935ef746639fbd00f57aef612b14af80accf98a6409f3c82b
                  • Instruction ID: 27209ae6cff7dab8504c0afeba55e2d4538ac920a4ab2fb8d2d9eb8fce1bbc63
                  • Opcode Fuzzy Hash: 358421e04550973935ef746639fbd00f57aef612b14af80accf98a6409f3c82b
                  • Instruction Fuzzy Hash: A0119376500604AFEF218E11DC40FA7FBECEF04715F1885AAED459BA51D765E808CAB2
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: Initialize
                  • String ID:
                  • API String ID: 2538663250-0
                  • Opcode ID: acb943cb630149a40bf738c249098fbb4cc33f0bfaad0a9374c9f8126b772da7
                  • Instruction ID: e7624a972153a2a72c69db055488ac6328f04e1cf8a7b07dd2cdd4d4fd79db54
                  • Opcode Fuzzy Hash: acb943cb630149a40bf738c249098fbb4cc33f0bfaad0a9374c9f8126b772da7
                  • Instruction Fuzzy Hash: CE216D754093C09FDB128B25DC54692BFB4EF47314F0984DBD9848F2A3D2759908DBA2
                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 0566082C
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: df834dc47102a4e526ce63ca5bd1976efec84244802305ce9780ecfd94f78006
                  • Instruction ID: 7667174333d5a5483f57ee551741ef214d19466e83cebd1775adfd12e80d5cd6
                  • Opcode Fuzzy Hash: df834dc47102a4e526ce63ca5bd1976efec84244802305ce9780ecfd94f78006
                  • Instruction Fuzzy Hash: F511B172500600AFEB61CF51DC44FA6FBE8EF04624F08856AE9468BB52D364E808CAF1
                  APIs
                  • GetProcessTimes.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05661021
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ProcessTimes
                  • String ID:
                  • API String ID: 1995159646-0
                  • Opcode ID: be69ee7565f7cee0de0f066409bb8ebc4eb792656ebd2295e3f03da8c147da19
                  • Instruction ID: 6a912e21ee4b1249d7280a027b55e3652bfd2bf6d62c2fb4b60261258cb2cb7b
                  • Opcode Fuzzy Hash: be69ee7565f7cee0de0f066409bb8ebc4eb792656ebd2295e3f03da8c147da19
                  • Instruction Fuzzy Hash: 0911D072500244AFEB21CF51DC44FAABBA8EF04624F08C46AE9458BA51D775E808CBB1
                  APIs
                  • GetProcessWorkingSetSize.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05662ABF
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ProcessSizeWorking
                  • String ID:
                  • API String ID: 3584180929-0
                  • Opcode ID: e48c73f1f7b25671dbbfb377452bd7e3b2332eadf72605268e577144ce6b8cf5
                  • Instruction ID: e93ac10924e1e4adc4ec04be1c65e08bd4fe4c7a3a2bf80f04da68ba24bda28a
                  • Opcode Fuzzy Hash: e48c73f1f7b25671dbbfb377452bd7e3b2332eadf72605268e577144ce6b8cf5
                  • Instruction Fuzzy Hash: 8411C176500204AFEB21CF55DC84FAABBA8EF04324F08C96AED058B641D775E848CFB5
                  APIs
                  • SetProcessWorkingSetSize.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05662BA3
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ProcessSizeWorking
                  • String ID:
                  • API String ID: 3584180929-0
                  • Opcode ID: e48c73f1f7b25671dbbfb377452bd7e3b2332eadf72605268e577144ce6b8cf5
                  • Instruction ID: 118bdbd6bcccf5ca081cc10920ad6e0d6b141196469ac126a2414ec816950b5e
                  • Opcode Fuzzy Hash: e48c73f1f7b25671dbbfb377452bd7e3b2332eadf72605268e577144ce6b8cf5
                  • Instruction Fuzzy Hash: 5511C479500204AFEB21CF55DC44FAABBA8EF04324F08C4AAED458B641D775E808CBB5
                  APIs
                  • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 00B9B436
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: DuplicateHandle
                  • String ID:
                  • API String ID: 3793708945-0
                  • Opcode ID: 4b1fa24d8163a06c19546a86815716cbee25423d57003766e7a3c3eea5c84107
                  • Instruction ID: ac06ee8ab83f31ae1224721e266971265852e10f386a7915c4bdbbf6d63b0606
                  • Opcode Fuzzy Hash: 4b1fa24d8163a06c19546a86815716cbee25423d57003766e7a3c3eea5c84107
                  • Instruction Fuzzy Hash: 13117271409780AFDB228F51DC44A62FFF4EF4A310F0888DEE9858B663D375A818DB61
                  APIs
                  • GetExitCodeProcess.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 056629E0
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: CodeExitProcess
                  • String ID:
                  • API String ID: 3861947596-0
                  • Opcode ID: 574f0048df475169816a5574a7e91abf167666b7ec986305036d6e39b233723c
                  • Instruction ID: ee97919d2ed6e19b773c3870a240959c351dc0bb7aaf269c74fa73cbfa74fb81
                  • Opcode Fuzzy Hash: 574f0048df475169816a5574a7e91abf167666b7ec986305036d6e39b233723c
                  • Instruction Fuzzy Hash: 9C11E375501200AFEB21CF16DC44BAABBA8EF44224F08C56AED05CB641D775E808CAA5
                  APIs
                  • ReadFile.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05660161
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: FileRead
                  • String ID:
                  • API String ID: 2738559852-0
                  • Opcode ID: 2d7a6c3eead25b1579457cc4c7855375fe47bd66db112a59c0f885520f7dfeca
                  • Instruction ID: b2e699b25c7eafe15482f91f31cb4827f772c0e78d3ea157e1461f49181ef120
                  • Opcode Fuzzy Hash: 2d7a6c3eead25b1579457cc4c7855375fe47bd66db112a59c0f885520f7dfeca
                  • Instruction Fuzzy Hash: A0119176400204AFEB21CF91DC44FA6FBE8EF44724F08896AEA458BA51D375E409CBB5
                  APIs
                  • ioctlsocket.WS2_32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05662537
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: ioctlsocket
                  • String ID:
                  • API String ID: 3577187118-0
                  • Opcode ID: 2f4fc4ab409f0dc055e1f6801e08aafd3187e1f0ef21dbf70babac8e68bbb7d0
                  • Instruction ID: dae1a3c8cf2022b02d064c95a9c5aab5121c7c5d8e6a36ef9bb8b15a2e890f10
                  • Opcode Fuzzy Hash: 2f4fc4ab409f0dc055e1f6801e08aafd3187e1f0ef21dbf70babac8e68bbb7d0
                  • Instruction Fuzzy Hash: CE11A375400204AFEB21CF55DC44FA6FBA8EF44324F08C45AED459B641D375E509CBB5
                  APIs
                  • shutdown.WS2_32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 05660D50
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: shutdown
                  • String ID:
                  • API String ID: 2510479042-0
                  • Opcode ID: da8b3951977d11f3aac7460c050b7a73113c39fd21824e335e53d6c9b696b8b5
                  • Instruction ID: e8fae8e0975be88e6244b0a3432339a8fdc8a29cedcf24a5cedbb9255bec54ad
                  • Opcode Fuzzy Hash: da8b3951977d11f3aac7460c050b7a73113c39fd21824e335e53d6c9b696b8b5
                  • Instruction Fuzzy Hash: 5E11C275400204AFEB21CF55DC84FA6BBA8EF44324F08C5AAED448F641D375A409CBB5
                  APIs
                  • LoadLibraryA.KERNEL32(?,00000E24), ref: 05661683
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: LibraryLoad
                  • String ID:
                  • API String ID: 1029625771-0
                  • Opcode ID: 33b2518f9fb936fd7ce259d0bef3ca7d25d718bc54a3eddbf14f1587857cee73
                  • Instruction ID: c65eb1a7ba3d0d8ebead17e09c0a9baec00656b054dbed9c060a819d47c91029
                  • Opcode Fuzzy Hash: 33b2518f9fb936fd7ce259d0bef3ca7d25d718bc54a3eddbf14f1587857cee73
                  • Instruction Fuzzy Hash: 3D11CE75501200AEEB20DB11DC81FB6FBA8DF05724F08C19AEE458A781D6B9A948CAA5
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: select
                  • String ID:
                  • API String ID: 1274211008-0
                  • Opcode ID: 553a1f5c2b9cfe64ac121c4f02278dae0869bb4f0a305ca4ef53476cf83f3ba5
                  • Instruction ID: e9958350322baa1f320a8c4b0eaa0a8fd3eed6af4a259299fbc6695d555b75bd
                  • Opcode Fuzzy Hash: 553a1f5c2b9cfe64ac121c4f02278dae0869bb4f0a305ca4ef53476cf83f3ba5
                  • Instruction Fuzzy Hash: A9113A795042449FDB20CF55D894FA2FBE8EF04610F08C4AADD49CBA62D375E848DFA1
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: send
                  • String ID:
                  • API String ID: 2809346765-0
                  • Opcode ID: a40d9bd8d16ecb8468d8c6bb3bb813f04e18819b94ef7611b0c211d04c2eca29
                  • Instruction ID: 646b5dd22508680d06b9d1e90669e38ea81b999aad1dbba887fa49b496e22719
                  • Opcode Fuzzy Hash: a40d9bd8d16ecb8468d8c6bb3bb813f04e18819b94ef7611b0c211d04c2eca29
                  • Instruction Fuzzy Hash: 2C11BF75409380AFDB22CF11DC44B52FFF4EF46224F0888DAED849B552C275A808DBA2
                  APIs
                  • GetFileType.KERNEL32(?,00000E24,B43DCBD4,00000000,00000000,00000000,00000000), ref: 00B9BE69
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: FileType
                  • String ID:
                  • API String ID: 3081899298-0
                  • Opcode ID: dfa9804c81d186fe3582c58e93309bfd075ee2277e0cb6bf4e117936aa0106bc
                  • Instruction ID: e3fb1c7c46cd152b600a3fc969cad20405ed1bb3ae4b63b99e75f437147b6608
                  • Opcode Fuzzy Hash: dfa9804c81d186fe3582c58e93309bfd075ee2277e0cb6bf4e117936aa0106bc
                  • Instruction Fuzzy Hash: 5C01C471500604AEEB208B05ED84FA6BBECDF04724F18C4A6EE058B652D364E8088AA5
                  APIs
                  • WaitForInputIdle.USER32(?,?), ref: 00B9B2EF
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: IdleInputWait
                  • String ID:
                  • API String ID: 2200289081-0
                  • Opcode ID: 38277039287b60d586733f8af111bd638569242e81c01d279e1991f4a1b3b10a
                  • Instruction ID: 365e43f1174dc94fbf1d1d34a35936c9d3b0f5e5890a6681dde707e313d99260
                  • Opcode Fuzzy Hash: 38277039287b60d586733f8af111bd638569242e81c01d279e1991f4a1b3b10a
                  • Instruction Fuzzy Hash: AB115E754493809FDB11CF55DD84B56BFE8EF46220F0984EAED858B262D279A808CB62
                  APIs
                  • SetErrorMode.KERNEL32(?,B43DCBD4,00000000,?,?,?,?,?,?,?,?,6CF23C58), ref: 00B9AB50
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: ErrorMode
                  • String ID:
                  • API String ID: 2340568224-0
                  • Opcode ID: bdd9c4d253c36695b16f0334606d78718074ba9f73530146fe9def07b94aca6c
                  • Instruction ID: c9cbb5631470671d6b19b882fc49ec977c7424de806465c2422bf9c8ce296fcc
                  • Opcode Fuzzy Hash: bdd9c4d253c36695b16f0334606d78718074ba9f73530146fe9def07b94aca6c
                  • Instruction Fuzzy Hash: 96116171409384AFDB128B15DC44B62FFF8DF46724F0984DAED858B663D265A908CBB2
                  APIs
                  • WSAConnect.WS2_32(?,?,?,?,?,?,?), ref: 056612DA
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: Connect
                  • String ID:
                  • API String ID: 3144859779-0
                  • Opcode ID: 546a9ef867949167e46c3639c6dee23f035f244bcfc7d9ec4afa4ab0b6f4ee32
                  • Instruction ID: 94a75b018bd111f2131f460d764b2e826006599583cfb7e5a8d7fa84a98378ac
                  • Opcode Fuzzy Hash: 546a9ef867949167e46c3639c6dee23f035f244bcfc7d9ec4afa4ab0b6f4ee32
                  • Instruction Fuzzy Hash: 381182354006449FDB20CF55D884B66FBE5FF05310F08C59ADD468BA12D376E458DF61
                  APIs
                  • GetVolumeInformationA.KERNEL32(?,00000E24,?,?), ref: 056613FE
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: InformationVolume
                  • String ID:
                  • API String ID: 2039140958-0
                  • Opcode ID: f269130924d98d55a9829ecc4c8bac06d7737b31cc2d2b049e905cf6414dbac4
                  • Instruction ID: a64b022e0e757877174bee60f9d59fa6fe8b9bee06b453a1b6d7ea10e2c0ab6b
                  • Opcode Fuzzy Hash: f269130924d98d55a9829ecc4c8bac06d7737b31cc2d2b049e905cf6414dbac4
                  • Instruction Fuzzy Hash: 72017171500200ABD750DF16DC45B66FBE8EB88A20F14855AED099BB41D731F915CBE6
                  APIs
                  • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 00B9B436
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: DuplicateHandle
                  • String ID:
                  • API String ID: 3793708945-0
                  • Opcode ID: ed46f82d6dabce314bb95b6cf4a8fb94068c102d868b8fa840b4561531864c2d
                  • Instruction ID: 6c7d9e56263c3a7b22e94276f03adf66fec50bd5cb76963da4bf3821c2d9a1ce
                  • Opcode Fuzzy Hash: ed46f82d6dabce314bb95b6cf4a8fb94068c102d868b8fa840b4561531864c2d
                  • Instruction Fuzzy Hash: 16016132400600DFDB21CF55D944B56FBE0EF08714F08C9AADE854A752D376E418EF62
                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E24,?,?), ref: 0566031E
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757700578.0000000005660000.00000040.00000800.00020000.00000000.sdmp, Offset: 05660000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5660000_Fast Download.jbxd
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: 0946000430ba0d382b6bc60f46a5e96928f0a76e12967520e444b14775aee44d
                  • Instruction ID: 5085b06d0c4453e140300bd24b588c08b63c74a5968af6a33f3d83f86bd87ef2
                  • Opcode Fuzzy Hash: 0946000430ba0d382b6bc60f46a5e96928f0a76e12967520e444b14775aee44d
                  • Instruction Fuzzy Hash: 3401A271500200ABD250DF16CC46F66FBE8FB88A20F14815AED089BB41D771F915CBE6
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: send
                  • String ID:
                  • API String ID: 2809346765-0
                  • Opcode ID: 8e8f3bbc529e64cf22560f45b16fab27495941d08c0833150c125e4310084c83
                  • Instruction ID: 521c6092b45a6f41a4aba542f0a0e882f57f72623ee2f1e68961fe33e6d3d483
                  • Opcode Fuzzy Hash: 8e8f3bbc529e64cf22560f45b16fab27495941d08c0833150c125e4310084c83
                  • Instruction Fuzzy Hash: CA01BC364006409FDB20CF55D884B62FBE0EF05324F08C8AADE499B652D376E808DFA2
                  APIs
                  • WaitForInputIdle.USER32(?,?), ref: 00B9B2EF
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: IdleInputWait
                  • String ID:
                  • API String ID: 2200289081-0
                  • Opcode ID: 407e810f8b648f805196f368fdef4b79ffb3fa5a495676d881e39d6de20d5eae
                  • Instruction ID: c828c991cdc274e91535a7fe13e21ce6037ac1d2cd0e965936b828ec26568381
                  • Opcode Fuzzy Hash: 407e810f8b648f805196f368fdef4b79ffb3fa5a495676d881e39d6de20d5eae
                  • Instruction Fuzzy Hash: A6017C754042409FDB10CF56E984B65FBE4EF04320F08C4EADD498B652D37AE804DEA6
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: Initialize
                  • String ID:
                  • API String ID: 2538663250-0
                  • Opcode ID: f4e300338af52e3b1af22fa4d5e607e6b2474caacb45f18286265248d09e62fa
                  • Instruction ID: d37c26e62f4e9e419b4c102462959686757283da72d12bdc1988f08a4472def7
                  • Opcode Fuzzy Hash: f4e300338af52e3b1af22fa4d5e607e6b2474caacb45f18286265248d09e62fa
                  • Instruction Fuzzy Hash: 14018B759002409FEB10CF15D888761FBE4EF44320F08C4EADD498F742D27AE808DEA2
                  APIs
                  • SetErrorMode.KERNEL32(?,B43DCBD4,00000000,?,?,?,?,?,?,?,?,6CF23C58), ref: 00B9AB50
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: ErrorMode
                  • String ID:
                  • API String ID: 2340568224-0
                  • Opcode ID: 4246a363289a6e852baf7ae4b5d3eb98aba973905c56c566a22933bf455fc0b1
                  • Instruction ID: 93c249ed01dcd910ab5cc2b5ed5580970f74c628b55e60f0f1b9e9768bcac753
                  • Opcode Fuzzy Hash: 4246a363289a6e852baf7ae4b5d3eb98aba973905c56c566a22933bf455fc0b1
                  • Instruction Fuzzy Hash: 8AF0AF758042449FDB108F05D885761FBE4EF04324F08C0EADE494BB62D3B9E808CEE2
                  APIs
                  • CloseHandle.KERNEL32(?,B43DCBD4,00000000,?,?,?,?,?,?,?,?,6CF23C58), ref: 00B9A290
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: CloseHandle
                  • String ID:
                  • API String ID: 2962429428-0
                  • Opcode ID: b84f7cef3df71c6741eb393b262bb523058793741771457f403b141089ed59b7
                  • Instruction ID: b0e45544df9909cf10d29459a1cb7281303dda29b87daaae9145d7f934278566
                  • Opcode Fuzzy Hash: b84f7cef3df71c6741eb393b262bb523058793741771457f403b141089ed59b7
                  • Instruction Fuzzy Hash: 2911C275509380AFDB11CF55DC84B52BFE8EF42320F0884EBED858B652D275A808CBA2
                  APIs
                  • CloseHandle.KERNEL32(?,B43DCBD4,00000000,?,?,?,?,?,?,?,?,6CF23C58), ref: 00B9A290
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754839911.0000000000B9A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9A000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b9a000_Fast Download.jbxd
                  Similarity
                  • API ID: CloseHandle
                  • String ID:
                  • API String ID: 2962429428-0
                  • Opcode ID: 41f25518ddc1ee3d95bcb672e99cbab3e4c3fccc1014d9ab39e04583a91cbbdc
                  • Instruction ID: 248eb395fac75826fcc7edca98878f9a5fac3e431c6ab378fb76f549a1fbe77e
                  • Opcode Fuzzy Hash: 41f25518ddc1ee3d95bcb672e99cbab3e4c3fccc1014d9ab39e04583a91cbbdc
                  • Instruction Fuzzy Hash: 85018F755052409FDB10CF55D8857A6FBE4DF05320F08C4EBDD498FA52D27AE808DEA2
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756270883.00000000011F0000.00000040.00000020.00020000.00000000.sdmp, Offset: 011F0000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_11f0000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8971cc977d8f20bbffaea791e626e18a08618ccc22093095a7eb317ba2fda6ed
                  • Instruction ID: b981f14d5e8f572b34aad3b681f1d668da86d70023b4a4793957839ea4599b39
                  • Opcode Fuzzy Hash: 8971cc977d8f20bbffaea791e626e18a08618ccc22093095a7eb317ba2fda6ed
                  • Instruction Fuzzy Hash: D4213A31509780CFDB178B24D950B51BFB1AF4B318F1985EED4898FAA3C33A8846DB51
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757739906.0000000005700000.00000040.00000800.00020000.00000000.sdmp, Offset: 05700000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5700000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: dba3f305157a0ee93b242bd5c901caadf8d69400eb04db9ad9778406f813b4fc
                  • Instruction ID: b9127f73d20a7dbfcf23479888fc40c182fa81c4b91117781ae07dd3a45b1a69
                  • Opcode Fuzzy Hash: dba3f305157a0ee93b242bd5c901caadf8d69400eb04db9ad9778406f813b4fc
                  • Instruction Fuzzy Hash: 5511CCB5908341AFD350CF19D840A5BFBE4FB88664F04895EF998D7311D235E904CFA2
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756270883.00000000011F0000.00000040.00000020.00020000.00000000.sdmp, Offset: 011F0000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_11f0000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: cd3639e23ba91a538b3f05c50013a6f039f65d88d36c98b87e9ac197530b5483
                  • Instruction ID: c9c318ca7d12027f19bc917c40812657fc5cb9d67121dd92fade41d7abb6939e
                  • Opcode Fuzzy Hash: cd3639e23ba91a538b3f05c50013a6f039f65d88d36c98b87e9ac197530b5483
                  • Instruction Fuzzy Hash: 3A11D630A04640DFD719CB14D940B66BBE6AB8C708F24C9ACFA491B653C77BD813CA81
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754899951.0000000000BAA000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAA000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_baa000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 246e371e170eabdb067a90be14cb67a4d637852aec58cbedeb5c939f577882fc
                  • Instruction ID: a563fe96f7d4e93c1dc97ca0e043a0031cf93c66070ae14f54077691ff6c4ecd
                  • Opcode Fuzzy Hash: 246e371e170eabdb067a90be14cb67a4d637852aec58cbedeb5c939f577882fc
                  • Instruction Fuzzy Hash: 0311FAB5908301AFD350CF09DC40E5BFBE8EB88660F04891EF95997711D235E9088FA2
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757739906.0000000005700000.00000040.00000800.00020000.00000000.sdmp, Offset: 05700000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5700000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2af60d5e661976c6a2ac3702a610922bd01fcefbe750829a41f2e59523001b61
                  • Instruction ID: 49496f3bc014817a4fd6c7e21655c04d9b71bb99d0d728b2b70a8b85c88c6032
                  • Opcode Fuzzy Hash: 2af60d5e661976c6a2ac3702a610922bd01fcefbe750829a41f2e59523001b61
                  • Instruction Fuzzy Hash: 4411FAB5908301AFD350CF09DC80E5BFBE8EB88660F04881EF95997711D235E9088FA2
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756270883.00000000011F0000.00000040.00000020.00020000.00000000.sdmp, Offset: 011F0000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_11f0000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f2063c8a679a74efed290cc4fadc649b8d12f17fd456ba93c1be87d5fea4a862
                  • Instruction ID: c59f649cd0a17083631f574f2e2ac3e190ed69a7506fa6ae49f98c1dec3d0b61
                  • Opcode Fuzzy Hash: f2063c8a679a74efed290cc4fadc649b8d12f17fd456ba93c1be87d5fea4a862
                  • Instruction Fuzzy Hash: 48018B755097806FD7118F05AC50863FFF8DF8663070984DFE84987A52D225A808CB72
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756270883.00000000011F0000.00000040.00000020.00020000.00000000.sdmp, Offset: 011F0000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_11f0000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5b37cd60603e03a6a813dd205d6952d3fbcfb37318c7041c0da74c17324a107b
                  • Instruction ID: 56ef5be6a080e776b3b39287f916ce32bee1d45a47f08e1f1f95d571a3c76405
                  • Opcode Fuzzy Hash: 5b37cd60603e03a6a813dd205d6952d3fbcfb37318c7041c0da74c17324a107b
                  • Instruction Fuzzy Hash: 90F01D35504644DFC706CF04D580B15FBA2EB89718F24CAADE94917753C737D813DA81
                  Memory Dump Source
                  • Source File: 00000000.00000002.3756270883.00000000011F0000.00000040.00000020.00020000.00000000.sdmp, Offset: 011F0000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_11f0000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 936b7564390b6c36b1a4214a98863e3d7d31ab0f1fbdfd7e17768f420b35780d
                  • Instruction ID: efe8b116a655f5eabfb37122d471365a0c9365f42d45109cdfd72f389d6ae0a7
                  • Opcode Fuzzy Hash: 936b7564390b6c36b1a4214a98863e3d7d31ab0f1fbdfd7e17768f420b35780d
                  • Instruction Fuzzy Hash: EBE092B66006005BD650CF0AFC41452F7D8EB84630708C47FDC0D8BB01D275B508CEE5
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754899951.0000000000BAA000.00000040.00000800.00020000.00000000.sdmp, Offset: 00BAA000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_baa000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6c6eb3594e98f3bbc2425d3d6d9048ca75889f2cb7335462a46bf5f858259999
                  • Instruction ID: 1ba3a745e5982902d4dd2d2c2752619997c15cdac8237a585db7aecbf6922840
                  • Opcode Fuzzy Hash: 6c6eb3594e98f3bbc2425d3d6d9048ca75889f2cb7335462a46bf5f858259999
                  • Instruction Fuzzy Hash: 8FE0D8B254020467D2108E069C45F62FB98DB44A30F08C557ED095B701D176B9048EF5
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757739906.0000000005700000.00000040.00000800.00020000.00000000.sdmp, Offset: 05700000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5700000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: a211787877fc8d1e82d20a99c69a29c7082c72138b707f880b76b7e93a5720dc
                  • Instruction ID: 87e8e2f19f66f2c39864b7cf30ae4fee88775d674a9bfd994b4169ac880a1fd9
                  • Opcode Fuzzy Hash: a211787877fc8d1e82d20a99c69a29c7082c72138b707f880b76b7e93a5720dc
                  • Instruction Fuzzy Hash: 2DE0D8B254020067D2109E069C45F53FB98DB40A30F08C457ED091B701D176B514CEE6
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757739906.0000000005700000.00000040.00000800.00020000.00000000.sdmp, Offset: 05700000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5700000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: afce14e68ad0c0823fb03aba9e881d5ca9ff7281dbd59c0a4a14e107939e8eeb
                  • Instruction ID: fa44ca2ca342d7ef05f405e64a46f8f17ab93934749e4195467d9fdfc89440b8
                  • Opcode Fuzzy Hash: afce14e68ad0c0823fb03aba9e881d5ca9ff7281dbd59c0a4a14e107939e8eeb
                  • Instruction Fuzzy Hash: 69E0D8B254030467D2509E069C45F53FB98DB40A30F08C457ED091B702D176B5048EF6
                  Memory Dump Source
                  • Source File: 00000000.00000002.3757739906.0000000005700000.00000040.00000800.00020000.00000000.sdmp, Offset: 05700000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_5700000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1bfde21cdd32993bd29cd29df279be20cc207c230f9f3c7ed84a89964511f7ba
                  • Instruction ID: 8953099734a45afbaf3fde4537ae230b1dac5a399f536f597c648028529c648e
                  • Opcode Fuzzy Hash: 1bfde21cdd32993bd29cd29df279be20cc207c230f9f3c7ed84a89964511f7ba
                  • Instruction Fuzzy Hash: 09E0D8B254030067D3108E069C45F52FB98DB44A30F08C467ED085B741D176B5148EE6
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754820096.0000000000B92000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B92000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b92000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: ba3703b2e03c716bce5a3ad1187793b5843d492f7ba0d1ea40a0e7eace352813
                  • Instruction ID: 626a4ee155a86523d7bb9d3c3f848852d82fbf95b2b54c6677d1977002f242be
                  • Opcode Fuzzy Hash: ba3703b2e03c716bce5a3ad1187793b5843d492f7ba0d1ea40a0e7eace352813
                  • Instruction Fuzzy Hash: 8DD05E796056C15FD7169B1CC1A5F9537D4AB61718F4A84F9A8008B763C768D981D600
                  Memory Dump Source
                  • Source File: 00000000.00000002.3754820096.0000000000B92000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B92000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_b92000_Fast Download.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b902c5eed4629093a086bf34b1b37c51023b2515c200fad29551bd307aa09450
                  • Instruction ID: e76fbc0716c50c2f9b6aa92c3bc51783498c10250c59a501dddea02952f96788
                  • Opcode Fuzzy Hash: b902c5eed4629093a086bf34b1b37c51023b2515c200fad29551bd307aa09450
                  • Instruction Fuzzy Hash: 0DD05E346042814FCB25DB0CD2D4F593BD4EF40714F0644F8AC108B762C7A8D8C0CA00