Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
5556.rar.exe

Overview

General Information

Sample name:5556.rar.exe
Analysis ID:1575638
MD5:475813f4cabffe076aefbd618a982512
SHA1:e2febca085bd5f5ac9aa2313bab17b4565a4024b
SHA256:ef5c02c221b5cb992728758e29195115a8f5481cf9ca5072a0616f95d00a362c
Tags:exeNjRATuser-lontze7
Infos:

Detection

Njrat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Njrat
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to log keystrokes (.Net Source)
Creates autostart registry keys with suspicious names
Disables zone checking for all users
Drops PE files to the startup folder
Drops PE files with benign system names
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies the windows firewall
Protects its processes via BreakOnTermination flag
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Sigma detected: Windows Binaries Write Suspicious Extensions
Uses an obfuscated file name to hide its real file extension (double extension)
Uses netsh to modify the Windows network and firewall settings
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected TCP or UDP traffic on non-standard ports
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Startup Folder File Write
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • 5556.rar.exe (PID: 5496 cmdline: "C:\Users\user\Desktop\5556.rar.exe" MD5: 475813F4CABFFE076AEFBD618A982512)
    • lsass.exe (PID: 4904 cmdline: "C:\Users\user\AppData\Roaming\lsass.exe" MD5: 475813F4CABFFE076AEFBD618A982512)
      • netsh.exe (PID: 5432 cmdline: netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\lsass.exe" "lsass.exe" ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 5064 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • lsass.exe (PID: 5952 cmdline: "C:\Users\user\AppData\Roaming\lsass.exe" .. MD5: 475813F4CABFFE076AEFBD618A982512)
  • lsass.exe (PID: 4364 cmdline: "C:\Users\user\AppData\Roaming\lsass.exe" .. MD5: 475813F4CABFFE076AEFBD618A982512)
  • lsass.exe (PID: 280 cmdline: "C:\Users\user\AppData\Roaming\lsass.exe" .. MD5: 475813F4CABFFE076AEFBD618A982512)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
NjRATRedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
  • AQUATIC PANDA
  • Earth Lusca
  • Operation C-Major
  • The Gorgon Group
https://malpedia.caad.fkie.fraunhofer.de/details/win.njrat
{"Campaign ID": "", "Version": "0.7d", "Install Name": "lsass.exe", "Install Dir": "AppData", "Registry Value": "e67ceec44f16fc357df593d15ca3e96b", "Host": "188.212.158.75", "Port": "5556", "Network Seprator": "|'|'|", "Install Flag": "True"}
SourceRuleDescriptionAuthorStrings
5556.rar.exeJoeSecurity_NjratYara detected NjratJoe Security
    5556.rar.exeWindows_Trojan_Njrat_30f3c220unknownunknown
    • 0x3c9a:$a1: get_Registry
    • 0x4d4e:$a2: SEE_MASK_NOZONECHECKS
    • 0x4e4a:$a3: Download ERROR
    • 0x4d10:$a4: cmd.exe /c ping 0 -n 2 & del "
    • 0x4ca2:$a5: netsh firewall delete allowedprogram "
    5556.rar.exeCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
    • 0x4d10:$x1: cmd.exe /c ping 0 -n 2 & del "
    • 0x4e68:$s3: Executed As
    • 0x4e4a:$s6: Download ERROR
    5556.rar.exenjrat1Identify njRatBrian Wallace @botnet_hunter
    • 0x4d7e:$a1: netsh firewall add allowedprogram
    • 0x4d4e:$a2: SEE_MASK_NOZONECHECKS
    • 0x4ff8:$b1: [TAP]
    • 0x4d10:$c3: cmd.exe /c ping
    5556.rar.exeNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
    • 0x4d4e:$reg: SEE_MASK_NOZONECHECKS
    • 0x4e26:$msg: Execute ERROR
    • 0x4e82:$msg: Execute ERROR
    • 0x4d10:$ping: cmd.exe /c ping 0 -n 2 & del
    Click to see the 1 entries
    SourceRuleDescriptionAuthorStrings
    dump.pcapJoeSecurity_Njrat_1Yara detected NjratJoe Security
      SourceRuleDescriptionAuthorStrings
      C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeJoeSecurity_NjratYara detected NjratJoe Security
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeWindows_Trojan_Njrat_30f3c220unknownunknown
        • 0x3c9a:$a1: get_Registry
        • 0x4d4e:$a2: SEE_MASK_NOZONECHECKS
        • 0x4e4a:$a3: Download ERROR
        • 0x4d10:$a4: cmd.exe /c ping 0 -n 2 & del "
        • 0x4ca2:$a5: netsh firewall delete allowedprogram "
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
        • 0x4d10:$x1: cmd.exe /c ping 0 -n 2 & del "
        • 0x4e68:$s3: Executed As
        • 0x4e4a:$s6: Download ERROR
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exenjrat1Identify njRatBrian Wallace @botnet_hunter
        • 0x4d7e:$a1: netsh firewall add allowedprogram
        • 0x4d4e:$a2: SEE_MASK_NOZONECHECKS
        • 0x4ff8:$b1: [TAP]
        • 0x4d10:$c3: cmd.exe /c ping
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
        • 0x4d4e:$reg: SEE_MASK_NOZONECHECKS
        • 0x4e26:$msg: Execute ERROR
        • 0x4e82:$msg: Execute ERROR
        • 0x4d10:$ping: cmd.exe /c ping 0 -n 2 & del
        Click to see the 7 entries
        SourceRuleDescriptionAuthorStrings
        00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_NjratYara detected NjratJoe Security
          00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmpWindows_Trojan_Njrat_30f3c220unknownunknown
          • 0x26fee:$a1: get_Registry
          • 0x220b8:$a2: SEE_MASK_NOZONECHECKS
          • 0x280a2:$a2: SEE_MASK_NOZONECHECKS
          • 0x2819e:$a3: Download ERROR
          • 0x28064:$a4: cmd.exe /c ping 0 -n 2 & del "
          • 0x27ff6:$a5: netsh firewall delete allowedprogram "
          00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmpnjrat1Identify njRatBrian Wallace @botnet_hunter
          • 0x22108:$a1: netsh firewall add allowedprogram
          • 0x280d2:$a1: netsh firewall add allowedprogram
          • 0x220b8:$a2: SEE_MASK_NOZONECHECKS
          • 0x280a2:$a2: SEE_MASK_NOZONECHECKS
          • 0x2834c:$b1: [TAP]
          • 0x28064:$c3: cmd.exe /c ping
          00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmpNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
          • 0x220b8:$reg: SEE_MASK_NOZONECHECKS
          • 0x280a2:$reg: SEE_MASK_NOZONECHECKS
          • 0x2817a:$msg: Execute ERROR
          • 0x281d6:$msg: Execute ERROR
          • 0x28064:$ping: cmd.exe /c ping 0 -n 2 & del
          00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_NjratYara detected NjratJoe Security
            Click to see the 6 entries
            SourceRuleDescriptionAuthorStrings
            0.2.5556.rar.exe.2b64354.0.unpackJoeSecurity_NjratYara detected NjratJoe Security
              0.2.5556.rar.exe.2b64354.0.unpackWindows_Trojan_Njrat_30f3c220unknownunknown
              • 0x1e9a:$a1: get_Registry
              • 0x2f4e:$a2: SEE_MASK_NOZONECHECKS
              • 0x304a:$a3: Download ERROR
              • 0x2f10:$a4: cmd.exe /c ping 0 -n 2 & del "
              • 0x2ea2:$a5: netsh firewall delete allowedprogram "
              0.2.5556.rar.exe.2b64354.0.unpackCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
              • 0x2f10:$x1: cmd.exe /c ping 0 -n 2 & del "
              • 0x3068:$s3: Executed As
              • 0x304a:$s6: Download ERROR
              0.2.5556.rar.exe.2b64354.0.unpacknjrat1Identify njRatBrian Wallace @botnet_hunter
              • 0x2f7e:$a1: netsh firewall add allowedprogram
              • 0x2f4e:$a2: SEE_MASK_NOZONECHECKS
              • 0x31f8:$b1: [TAP]
              • 0x2f10:$c3: cmd.exe /c ping
              0.2.5556.rar.exe.2b64354.0.unpackNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
              • 0x2f4e:$reg: SEE_MASK_NOZONECHECKS
              • 0x3026:$msg: Execute ERROR
              • 0x3082:$msg: Execute ERROR
              • 0x2f10:$ping: cmd.exe /c ping 0 -n 2 & del
              Click to see the 13 entries

              System Summary

              barindex
              Source: File createdAuthor: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Users\user\Desktop\5556.rar.exe, ProcessId: 5496, TargetFilename: C:\Users\user\AppData\Roaming\lsass.exe
              Source: Process startedAuthor: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: Data: Command: "C:\Users\user\AppData\Roaming\lsass.exe" , CommandLine: "C:\Users\user\AppData\Roaming\lsass.exe" , CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\lsass.exe, NewProcessName: C:\Users\user\AppData\Roaming\lsass.exe, OriginalFileName: C:\Users\user\AppData\Roaming\lsass.exe, ParentCommandLine: "C:\Users\user\Desktop\5556.rar.exe", ParentImage: C:\Users\user\Desktop\5556.rar.exe, ParentProcessId: 5496, ParentProcessName: 5556.rar.exe, ProcessCommandLine: "C:\Users\user\AppData\Roaming\lsass.exe" , ProcessId: 4904, ProcessName: lsass.exe
              Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Users\user\AppData\Roaming\lsass.exe, ProcessId: 4904, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe
              Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Roaming\lsass.exe" .., EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Roaming\lsass.exe, ProcessId: 4904, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\e67ceec44f16fc357df593d15ca3e96b
              Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\AppData\Roaming\lsass.exe, ProcessId: 4904, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe
              Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Roaming\lsass.exe" .., EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Roaming\lsass.exe, ProcessId: 4904, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\e67ceec44f16fc357df593d15ca3e96b
              Source: Process startedAuthor: vburov: Data: Command: "C:\Users\user\AppData\Roaming\lsass.exe" , CommandLine: "C:\Users\user\AppData\Roaming\lsass.exe" , CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\lsass.exe, NewProcessName: C:\Users\user\AppData\Roaming\lsass.exe, OriginalFileName: C:\Users\user\AppData\Roaming\lsass.exe, ParentCommandLine: "C:\Users\user\Desktop\5556.rar.exe", ParentImage: C:\Users\user\Desktop\5556.rar.exe, ParentProcessId: 5496, ParentProcessName: 5556.rar.exe, ProcessCommandLine: "C:\Users\user\AppData\Roaming\lsass.exe" , ProcessId: 4904, ProcessName: lsass.exe
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-16T07:36:57.381892+010020211761Malware Command and Control Activity Detected192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:37:02.112650+010020211761Malware Command and Control Activity Detected192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:06.939751+010020211761Malware Command and Control Activity Detected192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:11.769051+010020211761Malware Command and Control Activity Detected192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:16.611963+010020211761Malware Command and Control Activity Detected192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:21.463298+010020211761Malware Command and Control Activity Detected192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:26.348189+010020211761Malware Command and Control Activity Detected192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:31.211676+010020211761Malware Command and Control Activity Detected192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:36.033958+010020211761Malware Command and Control Activity Detected192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:41.026002+010020211761Malware Command and Control Activity Detected192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:45.784966+010020211761Malware Command and Control Activity Detected192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:50.597895+010020211761Malware Command and Control Activity Detected192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:55.443438+010020211761Malware Command and Control Activity Detected192.168.2.449807188.212.158.755556TCP
              2024-12-16T07:38:00.269136+010020211761Malware Command and Control Activity Detected192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:05.115012+010020211761Malware Command and Control Activity Detected192.168.2.449832188.212.158.755556TCP
              2024-12-16T07:38:09.958841+010020211761Malware Command and Control Activity Detected192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:38:14.786492+010020211761Malware Command and Control Activity Detected192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:38:19.503639+010020211761Malware Command and Control Activity Detected192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:24.066446+010020211761Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:28.533722+010020211761Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:33.011762+010020211761Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:37.165582+010020211761Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:41.334137+010020211761Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:45.410279+010020211761Malware Command and Control Activity Detected192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:49.425443+010020211761Malware Command and Control Activity Detected192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:38:53.332543+010020211761Malware Command and Control Activity Detected192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:38:57.256016+010020211761Malware Command and Control Activity Detected192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:39:01.036484+010020211761Malware Command and Control Activity Detected192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:04.724434+010020211761Malware Command and Control Activity Detected192.168.2.449977188.212.158.755556TCP
              2024-12-16T07:39:08.381528+010020211761Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:11.974287+010020211761Malware Command and Control Activity Detected192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:15.503052+010020211761Malware Command and Control Activity Detected192.168.2.450004188.212.158.755556TCP
              2024-12-16T07:39:18.992362+010020211761Malware Command and Control Activity Detected192.168.2.450011188.212.158.755556TCP
              2024-12-16T07:39:22.458585+010020211761Malware Command and Control Activity Detected192.168.2.450022188.212.158.755556TCP
              2024-12-16T07:39:25.918148+010020211761Malware Command and Control Activity Detected192.168.2.450030188.212.158.755556TCP
              2024-12-16T07:39:29.337101+010020211761Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:32.650882+010020211761Malware Command and Control Activity Detected192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:35.973785+010020211761Malware Command and Control Activity Detected192.168.2.450043188.212.158.755556TCP
              2024-12-16T07:39:39.237172+010020211761Malware Command and Control Activity Detected192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:39:42.611090+010020211761Malware Command and Control Activity Detected192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:45.937510+010020211761Malware Command and Control Activity Detected192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:49.119580+010020211761Malware Command and Control Activity Detected192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:52.381069+010020211761Malware Command and Control Activity Detected192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:39:55.458893+010020211761Malware Command and Control Activity Detected192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:58.544307+010020211761Malware Command and Control Activity Detected192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:40:01.659044+010020211761Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:04.742331+010020211761Malware Command and Control Activity Detected192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:07.815544+010020211761Malware Command and Control Activity Detected192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:40:10.878173+010020211761Malware Command and Control Activity Detected192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:40:13.942109+010020211761Malware Command and Control Activity Detected192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:17.099776+010020211761Malware Command and Control Activity Detected192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:20.128602+010020211761Malware Command and Control Activity Detected192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:23.183069+010020211761Malware Command and Control Activity Detected192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:40:26.176634+010020211761Malware Command and Control Activity Detected192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:40:29.159134+010020211761Malware Command and Control Activity Detected192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:40:32.153283+010020211761Malware Command and Control Activity Detected192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:40:35.127258+010020211761Malware Command and Control Activity Detected192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:40:38.065383+010020211761Malware Command and Control Activity Detected192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:40:41.035015+010020211761Malware Command and Control Activity Detected192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:43.982639+010020211761Malware Command and Control Activity Detected192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:49.064248+010020211761Malware Command and Control Activity Detected192.168.2.450066188.212.158.755556TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-16T07:36:57.381892+010020331321Malware Command and Control Activity Detected192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:37:02.112650+010020331321Malware Command and Control Activity Detected192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:06.939751+010020331321Malware Command and Control Activity Detected192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:11.769051+010020331321Malware Command and Control Activity Detected192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:16.611963+010020331321Malware Command and Control Activity Detected192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:21.463298+010020331321Malware Command and Control Activity Detected192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:26.348189+010020331321Malware Command and Control Activity Detected192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:31.211676+010020331321Malware Command and Control Activity Detected192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:36.033958+010020331321Malware Command and Control Activity Detected192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:41.026002+010020331321Malware Command and Control Activity Detected192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:45.784966+010020331321Malware Command and Control Activity Detected192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:50.597895+010020331321Malware Command and Control Activity Detected192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:55.443438+010020331321Malware Command and Control Activity Detected192.168.2.449807188.212.158.755556TCP
              2024-12-16T07:38:00.269136+010020331321Malware Command and Control Activity Detected192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:05.115012+010020331321Malware Command and Control Activity Detected192.168.2.449832188.212.158.755556TCP
              2024-12-16T07:38:09.958841+010020331321Malware Command and Control Activity Detected192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:38:14.786492+010020331321Malware Command and Control Activity Detected192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:38:19.503639+010020331321Malware Command and Control Activity Detected192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:24.066446+010020331321Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:28.533722+010020331321Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:33.011762+010020331321Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:37.165582+010020331321Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:41.334137+010020331321Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:45.410279+010020331321Malware Command and Control Activity Detected192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:49.425443+010020331321Malware Command and Control Activity Detected192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:38:53.332543+010020331321Malware Command and Control Activity Detected192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:38:57.256016+010020331321Malware Command and Control Activity Detected192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:39:01.036484+010020331321Malware Command and Control Activity Detected192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:04.724434+010020331321Malware Command and Control Activity Detected192.168.2.449977188.212.158.755556TCP
              2024-12-16T07:39:08.381528+010020331321Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:11.974287+010020331321Malware Command and Control Activity Detected192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:15.503052+010020331321Malware Command and Control Activity Detected192.168.2.450004188.212.158.755556TCP
              2024-12-16T07:39:18.992362+010020331321Malware Command and Control Activity Detected192.168.2.450011188.212.158.755556TCP
              2024-12-16T07:39:22.458585+010020331321Malware Command and Control Activity Detected192.168.2.450022188.212.158.755556TCP
              2024-12-16T07:39:25.918148+010020331321Malware Command and Control Activity Detected192.168.2.450030188.212.158.755556TCP
              2024-12-16T07:39:29.337101+010020331321Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:32.650882+010020331321Malware Command and Control Activity Detected192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:35.973785+010020331321Malware Command and Control Activity Detected192.168.2.450043188.212.158.755556TCP
              2024-12-16T07:39:39.237172+010020331321Malware Command and Control Activity Detected192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:39:42.611090+010020331321Malware Command and Control Activity Detected192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:45.937510+010020331321Malware Command and Control Activity Detected192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:49.119580+010020331321Malware Command and Control Activity Detected192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:52.381069+010020331321Malware Command and Control Activity Detected192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:39:55.458893+010020331321Malware Command and Control Activity Detected192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:58.544307+010020331321Malware Command and Control Activity Detected192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:40:01.659044+010020331321Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:04.742331+010020331321Malware Command and Control Activity Detected192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:07.815544+010020331321Malware Command and Control Activity Detected192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:40:10.878173+010020331321Malware Command and Control Activity Detected192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:40:13.942109+010020331321Malware Command and Control Activity Detected192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:17.099776+010020331321Malware Command and Control Activity Detected192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:20.128602+010020331321Malware Command and Control Activity Detected192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:23.183069+010020331321Malware Command and Control Activity Detected192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:40:26.176634+010020331321Malware Command and Control Activity Detected192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:40:29.159134+010020331321Malware Command and Control Activity Detected192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:40:32.153283+010020331321Malware Command and Control Activity Detected192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:40:35.127258+010020331321Malware Command and Control Activity Detected192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:40:38.065383+010020331321Malware Command and Control Activity Detected192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:40:41.035015+010020331321Malware Command and Control Activity Detected192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:43.982639+010020331321Malware Command and Control Activity Detected192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:49.064248+010020331321Malware Command and Control Activity Detected192.168.2.450066188.212.158.755556TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-16T07:37:03.149331+010028255641Malware Command and Control Activity Detected192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:27.727197+010028255641Malware Command and Control Activity Detected192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:47.832737+010028255641Malware Command and Control Activity Detected192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:52.066852+010028255641Malware Command and Control Activity Detected192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:38:02.346343+010028255641Malware Command and Control Activity Detected192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:02.466183+010028255641Malware Command and Control Activity Detected192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:02.892474+010028255641Malware Command and Control Activity Detected192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:10.438381+010028255641Malware Command and Control Activity Detected192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:38:20.482561+010028255641Malware Command and Control Activity Detected192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:26.120517+010028255641Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.240851+010028255641Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.362260+010028255641Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.482401+010028255641Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:29.133178+010028255641Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:29.373202+010028255641Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:29.915061+010028255641Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:30.034869+010028255641Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:30.154956+010028255641Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:33.259516+010028255641Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:33.522180+010028255641Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:39.083579+010028255641Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.222919+010028255641Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.359974+010028255641Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.479988+010028255641Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.837455+010028255641Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:42.173741+010028255641Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.293566+010028255641Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.413835+010028255641Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.596077+010028255641Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:43.497040+010028255641Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:43.616847+010028255641Malware Command and Control Activity Detected192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:45.770989+010028255641Malware Command and Control Activity Detected192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:46.697150+010028255641Malware Command and Control Activity Detected192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:46.817072+010028255641Malware Command and Control Activity Detected192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:54.412719+010028255641Malware Command and Control Activity Detected192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:38:59.418114+010028255641Malware Command and Control Activity Detected192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:38:59.876877+010028255641Malware Command and Control Activity Detected192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:39:02.911265+010028255641Malware Command and Control Activity Detected192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:03.031493+010028255641Malware Command and Control Activity Detected192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:03.405249+010028255641Malware Command and Control Activity Detected192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:10.188500+010028255641Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.308484+010028255641Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.635447+010028255641Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.919836+010028255641Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:11.039657+010028255641Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:13.175123+010028255641Malware Command and Control Activity Detected192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:14.396951+010028255641Malware Command and Control Activity Detected192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:14.517444+010028255641Malware Command and Control Activity Detected192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:30.262005+010028255641Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:30.381773+010028255641Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:30.501591+010028255641Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:32.894886+010028255641Malware Command and Control Activity Detected192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:33.633586+010028255641Malware Command and Control Activity Detected192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:33.873290+010028255641Malware Command and Control Activity Detected192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:42.988374+010028255641Malware Command and Control Activity Detected192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:46.177903+010028255641Malware Command and Control Activity Detected192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:49.359163+010028255641Malware Command and Control Activity Detected192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:49.478874+010028255641Malware Command and Control Activity Detected192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:55.809667+010028255641Malware Command and Control Activity Detected192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:55.929432+010028255641Malware Command and Control Activity Detected192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:40:02.631336+010028255641Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:02.751324+010028255641Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:03.053909+010028255641Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:03.293744+010028255641Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:05.342915+010028255641Malware Command and Control Activity Detected192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:15.983104+010028255641Malware Command and Control Activity Detected192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:16.103206+010028255641Malware Command and Control Activity Detected192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:19.500780+010028255641Malware Command and Control Activity Detected192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:19.631565+010028255641Malware Command and Control Activity Detected192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:19.751452+010028255641Malware Command and Control Activity Detected192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:20.607656+010028255641Malware Command and Control Activity Detected192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:22.670805+010028255641Malware Command and Control Activity Detected192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:22.792173+010028255641Malware Command and Control Activity Detected192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:23.542755+010028255641Malware Command and Control Activity Detected192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:40:43.490589+010028255641Malware Command and Control Activity Detected192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:44.995573+010028255641Malware Command and Control Activity Detected192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:46.560451+010028255641Malware Command and Control Activity Detected192.168.2.450065188.212.158.755556TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-16T07:36:57.501651+010028255631Malware Command and Control Activity Detected192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:37:02.236564+010028255631Malware Command and Control Activity Detected192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:07.060148+010028255631Malware Command and Control Activity Detected192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:11.890182+010028255631Malware Command and Control Activity Detected192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:16.731831+010028255631Malware Command and Control Activity Detected192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:21.586920+010028255631Malware Command and Control Activity Detected192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:26.468513+010028255631Malware Command and Control Activity Detected192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:31.331698+010028255631Malware Command and Control Activity Detected192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:36.153963+010028255631Malware Command and Control Activity Detected192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:41.145856+010028255631Malware Command and Control Activity Detected192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:45.905041+010028255631Malware Command and Control Activity Detected192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:50.717794+010028255631Malware Command and Control Activity Detected192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:38:33.135012+010028255631Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:40:49.183984+010028255631Malware Command and Control Activity Detected192.168.2.450066188.212.158.755556TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450030188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450022188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449832188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450004188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449977188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450043188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450011188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:36:40.941155+010028148601Malware Command and Control Activity Detected192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:17.441745+010028148601Malware Command and Control Activity Detected192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:38:52.076554+010028148601Malware Command and Control Activity Detected192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:39:41.881192+010028148601Malware Command and Control Activity Detected192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:40:01.069760+010028148601Malware Command and Control Activity Detected192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:40:07.146451+010028148601Malware Command and Control Activity Detected192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:09.978364+010028148601Malware Command and Control Activity Detected192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:40:13.163563+010028148601Malware Command and Control Activity Detected192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:40:28.583243+010028148601Malware Command and Control Activity Detected192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:40:31.562850+010028148601Malware Command and Control Activity Detected192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:40:34.560161+010028148601Malware Command and Control Activity Detected192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:40:37.414042+010028148601Malware Command and Control Activity Detected192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:40:40.225036+010028148601Malware Command and Control Activity Detected192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:40:43.490589+010028148601Malware Command and Control Activity Detected192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:46.560451+010028148601Malware Command and Control Activity Detected192.168.2.450065188.212.158.755556TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-16T07:36:57.501651+010028384861Malware Command and Control Activity Detected192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:37:02.236564+010028384861Malware Command and Control Activity Detected192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:07.060148+010028384861Malware Command and Control Activity Detected192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:11.890182+010028384861Malware Command and Control Activity Detected192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:16.731831+010028384861Malware Command and Control Activity Detected192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:21.586920+010028384861Malware Command and Control Activity Detected192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:26.468513+010028384861Malware Command and Control Activity Detected192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:31.331698+010028384861Malware Command and Control Activity Detected192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:36.153963+010028384861Malware Command and Control Activity Detected192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:41.145856+010028384861Malware Command and Control Activity Detected192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:45.905041+010028384861Malware Command and Control Activity Detected192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:50.717794+010028384861Malware Command and Control Activity Detected192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:55.564618+010028384861Malware Command and Control Activity Detected192.168.2.449807188.212.158.755556TCP
              2024-12-16T07:38:33.135012+010028384861Malware Command and Control Activity Detected192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:39:29.457012+010028384861Malware Command and Control Activity Detected192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:42.730902+010028384861Malware Command and Control Activity Detected192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:46.058030+010028384861Malware Command and Control Activity Detected192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:49.239340+010028384861Malware Command and Control Activity Detected192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:52.500918+010028384861Malware Command and Control Activity Detected192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:39:55.578623+010028384861Malware Command and Control Activity Detected192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:40:49.183984+010028384861Malware Command and Control Activity Detected192.168.2.450066188.212.158.755556TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: 5556.rar.exeAvira: detected
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeAvira: detection malicious, Label: TR/Dropper.Gen7
              Source: C:\Users\user\AppData\Roaming\lsass.exeAvira: detection malicious, Label: TR/Dropper.Gen7
              Source: 0.0.5556.rar.exe.380000.0.unpackMalware Configuration Extractor: Njrat {"Campaign ID": "", "Version": "0.7d", "Install Name": "lsass.exe", "Install Dir": "AppData", "Registry Value": "e67ceec44f16fc357df593d15ca3e96b", "Host": "188.212.158.75", "Port": "5556", "Network Seprator": "|'|'|", "Install Flag": "True"}
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeReversingLabs: Detection: 94%
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeVirustotal: Detection: 87%Perma Link
              Source: C:\Users\user\AppData\Roaming\lsass.exeReversingLabs: Detection: 94%
              Source: C:\Users\user\AppData\Roaming\lsass.exeVirustotal: Detection: 87%Perma Link
              Source: 5556.rar.exeVirustotal: Detection: 87%Perma Link
              Source: 5556.rar.exeReversingLabs: Detection: 94%
              Source: Yara matchFile source: dump.pcap, type: PCAP
              Source: Yara matchFile source: 5556.rar.exe, type: SAMPLE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: 5556.rar.exe PID: 5496, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: lsass.exe PID: 4904, type: MEMORYSTR
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPED
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPED
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeJoe Sandbox ML: detected
              Source: C:\Users\user\AppData\Roaming\lsass.exeJoe Sandbox ML: detected
              Source: 5556.rar.exeJoe Sandbox ML: detected
              Source: 5556.rar.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: C:\Users\user\Desktop\5556.rar.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
              Source: 5556.rar.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49743 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49743 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49742 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49741 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49771 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49771 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49771 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49795 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49795 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49741 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49795 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49745 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49741 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49743 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49743 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49735 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49771 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49795 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49741 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49795 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49735 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49742 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49738 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49742 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49735 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49745 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49735 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49738 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49742 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49784 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49739 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49739 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49739 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49739 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49743 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49832 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49832 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49745 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49807 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49807 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49738 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49738 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49807 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49784 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49738 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49784 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49784 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49784 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49745 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49740 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49844 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49740 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49817 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49740 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49817 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49740 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49844 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49888 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49844 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49888 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49888 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49817 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49899 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49899 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49899 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49899 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49899 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49877 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49877 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49855 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49855 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49921 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49877 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49921 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49866 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49866 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49866 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49921 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49927 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49927 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49927 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49855 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49949 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49949 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49938 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49949 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49938 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49910 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49910 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49938 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49966 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49910 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49756 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49966 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49756 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:49756 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:49756 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49977 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49977 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49966 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49985 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49985 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49994 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49994 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:49957 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:49957 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49985 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49994 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50004 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50004 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50011 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50011 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50022 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50022 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50030 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50030 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50039 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50039 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50039 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50039 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50042 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50042 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50043 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50042 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50043 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50044 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50044 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50046 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50046 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50046 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50046 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50045 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50045 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50048 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50048 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50045 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50048 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50045 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50049 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50049 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50049 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50051 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50049 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50051 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50044 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50052 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50052 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50051 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50050 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50052 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50050 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:49957 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50054 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50053 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50054 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50053 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50055 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50055 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50056 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50056 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50058 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50058 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50052 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50058 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50059 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50059 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50060 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50060 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50057 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50057 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50057 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50054 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50055 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50062 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50062 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50056 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50059 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50060 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50053 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50065 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50064 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50065 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50064 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50061 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50061 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50065 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50062 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50064 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50064 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50065 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50061 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50063 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50063 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50047 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50047 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50063 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50047 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:50047 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:50066 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:50066 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2825563 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) : 192.168.2.4:50066 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2838486 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) : 192.168.2.4:50066 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50050 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50047 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50030 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50039 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50045 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50022 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49966 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49832 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50051 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49899 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50004 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49844 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50057 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50049 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49927 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49977 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50046 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50048 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49877 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50056 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49994 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50043 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49910 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50055 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49949 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50042 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49985 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50011 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49957 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49888 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:50058 -> 188.212.158.75:5556
              Source: Network trafficSuricata IDS: 2814860 - Severity 1 - ETPRO MALWARE njRAT/Bladabindi CnC Callback (act) : 192.168.2.4:49866 -> 188.212.158.75:5556
              Source: Malware configuration extractorIPs: 188.212.158.75
              Source: global trafficTCP traffic: 192.168.2.4:49735 -> 188.212.158.75:5556
              Source: Joe Sandbox ViewASN Name: DIALTELECOMRO DIALTELECOMRO
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75
              Source: unknownTCP traffic detected without corresponding DNS query: 188.212.158.75

              Key, Mouse, Clipboard, Microphone and Screen Capturing

              barindex
              Source: 5556.rar.exe, kl.cs.Net Code: VKCodeToUnicode
              Source: lsass.exe.0.dr, kl.cs.Net Code: VKCodeToUnicode
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, kl.cs.Net Code: VKCodeToUnicode
              Source: e67ceec44f16fc357df593d15ca3e96b.exe.1.dr, kl.cs.Net Code: VKCodeToUnicode

              E-Banking Fraud

              barindex
              Source: Yara matchFile source: dump.pcap, type: PCAP
              Source: Yara matchFile source: 5556.rar.exe, type: SAMPLE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: 5556.rar.exe PID: 5496, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: lsass.exe PID: 4904, type: MEMORYSTR
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPED
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPED

              Operating System Destruction

              barindex
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: 01 00 00 00 Jump to behavior

              System Summary

              barindex
              Source: 5556.rar.exe, type: SAMPLEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: 5556.rar.exe, type: SAMPLEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
              Source: 5556.rar.exe, type: SAMPLEMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: 5556.rar.exe, type: SAMPLEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: 5556.rar.exe, type: SAMPLEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
              Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: Identify njRat Author: Brian Wallace @botnet_hunter
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess Stats: CPU usage > 49%
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B5BBC6 NtSetInformationProcess,1_2_01B5BBC6
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B5BBA4 NtSetInformationProcess,1_2_01B5BBA4
              Source: 5556.rar.exe, 00000000.00000002.1837394364.00000000009EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemscorwks.dllT vs 5556.rar.exe
              Source: 5556.rar.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: 5556.rar.exe, type: SAMPLEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: 5556.rar.exe, type: SAMPLEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: 5556.rar.exe, type: SAMPLEMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: 5556.rar.exe, type: SAMPLEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: 5556.rar.exe, type: SAMPLEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
              Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
              Source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
              Source: classification engineClassification label: mal100.phis.troj.adwa.spyw.evad.winEXE@9/5@0/1
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B5B876 AdjustTokenPrivileges,1_2_01B5B876
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B5B83F AdjustTokenPrivileges,1_2_01B5B83F
              Source: C:\Users\user\Desktop\5556.rar.exeFile created: C:\Users\user\AppData\Roaming\lsass.exeJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMutant created: NULL
              Source: C:\Users\user\AppData\Roaming\lsass.exeMutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking
              Source: C:\Users\user\AppData\Roaming\lsass.exeMutant created: \Sessions\1\BaseNamedObjects\e67ceec44f16fc357df593d15ca3e96b
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5064:120:WilError_03
              Source: 5556.rar.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: 5556.rar.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.79%
              Source: C:\Users\user\Desktop\5556.rar.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: 5556.rar.exeVirustotal: Detection: 87%
              Source: 5556.rar.exeReversingLabs: Detection: 94%
              Source: C:\Users\user\Desktop\5556.rar.exeFile read: C:\Users\user\Desktop\5556.rar.exeJump to behavior
              Source: unknownProcess created: C:\Users\user\Desktop\5556.rar.exe "C:\Users\user\Desktop\5556.rar.exe"
              Source: C:\Users\user\Desktop\5556.rar.exeProcess created: C:\Users\user\AppData\Roaming\lsass.exe "C:\Users\user\AppData\Roaming\lsass.exe"
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\lsass.exe" "lsass.exe" ENABLE
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: unknownProcess created: C:\Users\user\AppData\Roaming\lsass.exe "C:\Users\user\AppData\Roaming\lsass.exe" ..
              Source: unknownProcess created: C:\Users\user\AppData\Roaming\lsass.exe "C:\Users\user\AppData\Roaming\lsass.exe" ..
              Source: unknownProcess created: C:\Users\user\AppData\Roaming\lsass.exe "C:\Users\user\AppData\Roaming\lsass.exe" ..
              Source: C:\Users\user\Desktop\5556.rar.exeProcess created: C:\Users\user\AppData\Roaming\lsass.exe "C:\Users\user\AppData\Roaming\lsass.exe" Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\lsass.exe" "lsass.exe" ENABLEJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: propsys.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: edputil.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: windows.staterepositoryps.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: appresolver.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: bcp47langs.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: slc.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: sppc.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: onecorecommonproxystub.dllJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: shfolder.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: wbemcomn.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: amsi.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: avicap32.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: msvfw32.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: winmm.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: winmm.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ifmon.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mprapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasmontr.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasapi32.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasman.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mfc42u.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: authfwcfg.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwpolicyiomgr.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: firewallapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwbase.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dhcpcmonitor.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dot3cfg.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dot3api.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: onex.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: eappcfg.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: eappprxy.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwcfg.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: hnetmon.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netshell.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nlaapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netsetupapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netiohlp.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dhcpcsvc.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshhttp.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: httpapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshipsec.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: activeds.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: polstore.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winipsec.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: adsldpc.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshwfp.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cabinet.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: p2pnetsh.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: p2p.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rpcnsh.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: whhelper.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wlancfg.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wlanapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wshelper.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wevtapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: peerdistsh.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wcmapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rmclient.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mobilenetworking.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: slc.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: sppc.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ktmw32.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mprmsg.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dllJump to behavior
              Source: 5556.rar.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
              Source: C:\Users\user\Desktop\5556.rar.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
              Source: 5556.rar.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

              Data Obfuscation

              barindex
              Source: 5556.rar.exe, OK.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
              Source: lsass.exe.0.dr, OK.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
              Source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, OK.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
              Source: e67ceec44f16fc357df593d15ca3e96b.exe.1.dr, OK.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
              Source: C:\Users\user\Desktop\5556.rar.exeCode function: 0_2_00962805 push edi; ret 0_2_00962806
              Source: C:\Users\user\Desktop\5556.rar.exeCode function: 0_2_0096284C push ecx; ret 0_2_0096284E
              Source: C:\Users\user\Desktop\5556.rar.exeCode function: 0_2_00962834 push edi; ret 0_2_00962842
              Source: C:\Users\user\Desktop\5556.rar.exeCode function: 0_2_00962979 push eax; ret 0_2_0096297A
              Source: C:\Users\user\Desktop\5556.rar.exeCode function: 0_2_009627A5 push edi; ret 0_2_009627A6
              Source: C:\Users\user\Desktop\5556.rar.exeCode function: 0_2_00962729 push edi; ret 0_2_0096272A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52834 push edi; ret 1_2_01B52842
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52FB1 push edi; ret 1_2_01B52FB2
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52E30 push eax; ret 1_2_01B52E32
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52979 push eax; ret 1_2_01B5297A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B527A5 push edi; ret 1_2_01B527A6
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52E60 push eax; ret 1_2_01B52E62
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52729 push edi; ret 1_2_01B5272A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52805 push edi; ret 1_2_01B52806
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B52DC7 push edi; ret 1_2_01B52DD2
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 1_2_01B5284C push ecx; ret 1_2_01B5284E
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 7_2_013E2979 push eax; ret 7_2_013E297A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 7_2_013E2834 push edi; ret 7_2_013E2842
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 7_2_013E2729 push edi; ret 7_2_013E272A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 7_2_013E27A5 push edi; ret 7_2_013E27A6
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 7_2_013E284C push ecx; ret 7_2_013E284E
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 7_2_013E2805 push edi; ret 7_2_013E2806
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 8_2_02EB2729 push edi; ret 8_2_02EB272A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 8_2_02EB27A5 push edi; ret 8_2_02EB27A6
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 8_2_02EB2979 push eax; ret 8_2_02EB297A
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 8_2_02EB2834 push edi; ret 8_2_02EB2842
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 8_2_02EB284C push ecx; ret 8_2_02EB284E
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 8_2_02EB2805 push edi; ret 8_2_02EB2806
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 9_2_030E284C push ecx; ret 9_2_030E284E
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 9_2_030E2805 push edi; ret 9_2_030E2806
              Source: C:\Users\user\AppData\Roaming\lsass.exeCode function: 9_2_030E2729 push edi; ret 9_2_030E272A

              Persistence and Installation Behavior

              barindex
              Source: C:\Users\user\Desktop\5556.rar.exeFile created: C:\Users\user\AppData\Roaming\lsass.exeJump to dropped file
              Source: C:\Users\user\Desktop\5556.rar.exeFile created: C:\Users\user\AppData\Roaming\lsass.exeJump to dropped file
              Source: C:\Users\user\AppData\Roaming\lsass.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeJump to dropped file

              Boot Survival

              barindex
              Source: C:\Users\user\AppData\Roaming\lsass.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96bJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeJump to dropped file
              Source: C:\Users\user\AppData\Roaming\lsass.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exeJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96bJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96bJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96bJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96bJump to behavior

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: Possible double extension: rar.exeStatic PE information: 5556.rar.exe
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeMemory allocated: D20000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeMemory allocated: 2B40000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeMemory allocated: D90000 memory commit | memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 1BF0000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 3C40000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 5C40000 memory commit | memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 2DE0000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 3480000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 5480000 memory commit | memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 2F50000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 3640000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 2F50000 memory commit | memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 3180000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 3840000 memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeMemory allocated: 5840000 memory commit | memory reserve | memory write watchJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeWindow / User API: threadDelayed 1617Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeWindow / User API: threadDelayed 3460Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeWindow / User API: threadDelayed 4096Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeWindow / User API: foregroundWindowGot 1755Jump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exe TID: 2992Thread sleep time: -922337203685477s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exe TID: 4124Thread sleep time: -1617000s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exe TID: 4124Thread sleep time: -4096000s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exe TID: 7080Thread sleep time: -922337203685477s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exe TID: 6064Thread sleep time: -922337203685477s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exe TID: 1748Thread sleep time: -922337203685477s >= -30000sJump to behavior
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Users\user\Desktop\5556.rar.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: lsass.exe, 00000001.00000002.4228259881.0000000001671000.00000004.00000020.00020000.00000000.sdmp, netsh.exe, 00000004.00000003.1908253640.0000000001182000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Desktop\5556.rar.exeMemory allocated: page read and write | page guardJump to behavior

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: 5556.rar.exe, kl.csReference to suspicious API methods: MapVirtualKey(a, 0u)
              Source: 5556.rar.exe, kl.csReference to suspicious API methods: GetAsyncKeyState(num2)
              Source: 5556.rar.exe, OK.csReference to suspicious API methods: capGetDriverDescriptionA(wDriver, ref lpszName, 100, ref lpszVer, 100)
              Source: C:\Users\user\Desktop\5556.rar.exeProcess created: C:\Users\user\AppData\Roaming\lsass.exe "C:\Users\user\AppData\Roaming\lsass.exe" Jump to behavior
              Source: lsass.exe, 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
              Source: lsass.exe, 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager@9
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Windows\SysWOW64\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

              Lowering of HIPS / PFW / Operating System Security Settings

              barindex
              Source: C:\Users\user\AppData\Roaming\lsass.exeRegistry value created: HKEY_CURRENT_USER\Environment SEE_MASK_NOZONECHECKSJump to behavior
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\lsass.exe" "lsass.exe" ENABLE
              Source: C:\Users\user\AppData\Roaming\lsass.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\lsass.exe" "lsass.exe" ENABLE

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: dump.pcap, type: PCAP
              Source: Yara matchFile source: 5556.rar.exe, type: SAMPLE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: 5556.rar.exe PID: 5496, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: lsass.exe PID: 4904, type: MEMORYSTR
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPED
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPED

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: dump.pcap, type: PCAP
              Source: Yara matchFile source: 5556.rar.exe, type: SAMPLE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.0.5556.rar.exe.380000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.5556.rar.exe.2b64354.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: 5556.rar.exe PID: 5496, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: lsass.exe PID: 4904, type: MEMORYSTR
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, type: DROPPED
              Source: Yara matchFile source: C:\Users\user\AppData\Roaming\lsass.exe, type: DROPPED
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
              Native API
              221
              Registry Run Keys / Startup Folder
              1
              Access Token Manipulation
              21
              Masquerading
              1
              Input Capture
              11
              Security Software Discovery
              Remote Services1
              Input Capture
              1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/Job1
              DLL Side-Loading
              12
              Process Injection
              31
              Disable or Modify Tools
              LSASS Memory1
              Process Discovery
              Remote Desktop ProtocolData from Removable Media1
              Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)221
              Registry Run Keys / Startup Folder
              31
              Virtualization/Sandbox Evasion
              Security Account Manager31
              Virtualization/Sandbox Evasion
              SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
              DLL Side-Loading
              1
              Access Token Manipulation
              NTDS1
              Application Window Discovery
              Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script12
              Process Injection
              LSA Secrets1
              File and Directory Discovery
              SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts11
              Obfuscated Files or Information
              Cached Domain Credentials12
              System Information Discovery
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
              Software Packing
              DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
              DLL Side-Loading
              Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 signatures2 2 Behavior Graph ID: 1575638 Sample: 5556.rar.exe Startdate: 16/12/2024 Architecture: WINDOWS Score: 100 35 Suricata IDS alerts for network traffic 2->35 37 Found malware configuration 2->37 39 Malicious sample detected (through community Yara rule) 2->39 41 16 other signatures 2->41 8 5556.rar.exe 1 5 2->8         started        12 lsass.exe 2 2->12         started        14 lsass.exe 3 2->14         started        16 lsass.exe 2 2->16         started        process3 file4 29 C:\Users\user\AppData\Roaming\lsass.exe, PE32 8->29 dropped 31 C:\Users\user\AppData\...\5556.rar.exe.log, ASCII 8->31 dropped 51 Drops PE files with benign system names 8->51 18 lsass.exe 4 5 8->18         started        signatures5 process6 dnsIp7 33 188.212.158.75, 49735, 49738, 49739 DIALTELECOMRO Romania 18->33 27 C:\...\e67ceec44f16fc357df593d15ca3e96b.exe, PE32 18->27 dropped 43 Antivirus detection for dropped file 18->43 45 Multi AV Scanner detection for dropped file 18->45 47 Protects its processes via BreakOnTermination flag 18->47 49 6 other signatures 18->49 23 netsh.exe 2 18->23         started        file8 signatures9 process10 process11 25 conhost.exe 23->25         started       

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              5556.rar.exe88%VirustotalBrowse
              5556.rar.exe95%ReversingLabsByteCode-MSIL.Backdoor.njRAT
              5556.rar.exe100%AviraTR/Dropper.Gen7
              5556.rar.exe100%Joe Sandbox ML
              SourceDetectionScannerLabelLink
              C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe100%AviraTR/Dropper.Gen7
              C:\Users\user\AppData\Roaming\lsass.exe100%AviraTR/Dropper.Gen7
              C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Roaming\lsass.exe100%Joe Sandbox ML
              C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe95%ReversingLabsByteCode-MSIL.Backdoor.njRAT
              C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe88%VirustotalBrowse
              C:\Users\user\AppData\Roaming\lsass.exe95%ReversingLabsByteCode-MSIL.Backdoor.njRAT
              C:\Users\user\AppData\Roaming\lsass.exe88%VirustotalBrowse
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              No contacted domains info
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              188.212.158.75
              unknownRomania
              6910DIALTELECOMROtrue
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1575638
              Start date and time:2024-12-16 07:35:39 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 7m 42s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:11
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:5556.rar.exe
              Detection:MAL
              Classification:mal100.phis.troj.adwa.spyw.evad.winEXE@9/5@0/1
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 99%
              • Number of executed functions: 161
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Override analysis time to 240000 for current running targets taking high CPU consumption
              • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
              • Excluded IPs from analysis (whitelisted): 4.245.163.56, 13.107.246.63
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size exceeded maximum capacity and may have missing behavior information.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              TimeTypeDescription
              01:37:26API Interceptor412064x Sleep call for process: lsass.exe modified
              06:36:57AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96b "C:\Users\user\AppData\Roaming\lsass.exe" ..
              06:37:05AutostartRun: HKLM\Software\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96b "C:\Users\user\AppData\Roaming\lsass.exe" ..
              06:37:13AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run e67ceec44f16fc357df593d15ca3e96b "C:\Users\user\AppData\Roaming\lsass.exe" ..
              06:37:21AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe
              No context
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              DIALTELECOMROhax.sh4.elfGet hashmaliciousMiraiBrowse
              • 93.118.210.183
              rendel#U00e9s_1023200000000000305.exeGet hashmaliciousAgentTesla, GuLoaderBrowse
              • 86.107.36.93
              meerkat.arm5.elfGet hashmaliciousMiraiBrowse
              • 89.47.221.99
              Objedn#U00e1vka_20248481119000903.imgGet hashmaliciousAgentTesla, GuLoaderBrowse
              • 86.107.36.93
              mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
              • 188.240.230.166
              mpsl.elfGet hashmaliciousMiraiBrowse
              • 93.114.246.9
              #U00c1raj#U00e1nlat k#U00e9r#U00e9s MOL093478524#U00b7docx.exeGet hashmaliciousDBatLoader, FormBookBrowse
              • 92.114.2.230
              Amalgamers.exeGet hashmaliciousAgentTeslaBrowse
              • 86.107.36.93
              #U00c1raj#U00e1nlat k#U00e9r#U00e9s 06.11.2024.cmdGet hashmaliciousDBatLoader, FormBookBrowse
              • 92.114.2.230
              FLITTIGL.EXE.exeGet hashmaliciousAgentTesla, GuLoaderBrowse
              • 86.107.36.93
              No context
              No context
              Process:C:\Users\user\Desktop\5556.rar.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):525
              Entropy (8bit):5.259753436570609
              Encrypted:false
              SSDEEP:12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve
              MD5:260E01CC001F9C4643CA7A62F395D747
              SHA1:492AD0ACE3A9C8736909866EEA168962D418BE5A
              SHA-256:4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030
              SHA-512:01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4
              Malicious:true
              Reputation:moderate, very likely benign file
              Preview:1,"fusion","GAC",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System\bec14584c93014efbc76285c35d1e891\System.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7d443c6c007fe8696f9aa6ff1da53ef7\Microsoft.VisualBasic.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2cdaeaf53e3d49038cf7cb0ce9d805d3\System.Drawing.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d0e5535854cce87ea7f2d69d0594b7a8\System.Windows.Forms.ni.dll",0..
              Process:C:\Users\user\AppData\Roaming\lsass.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):525
              Entropy (8bit):5.259753436570609
              Encrypted:false
              SSDEEP:12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve
              MD5:260E01CC001F9C4643CA7A62F395D747
              SHA1:492AD0ACE3A9C8736909866EEA168962D418BE5A
              SHA-256:4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030
              SHA-512:01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4
              Malicious:false
              Reputation:moderate, very likely benign file
              Preview:1,"fusion","GAC",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System\bec14584c93014efbc76285c35d1e891\System.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7d443c6c007fe8696f9aa6ff1da53ef7\Microsoft.VisualBasic.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2cdaeaf53e3d49038cf7cb0ce9d805d3\System.Drawing.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d0e5535854cce87ea7f2d69d0594b7a8\System.Windows.Forms.ni.dll",0..
              Process:C:\Users\user\AppData\Roaming\lsass.exe
              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
              Category:dropped
              Size (bytes):24064
              Entropy (8bit):5.511658847706215
              Encrypted:false
              SSDEEP:384:hFHuitNFzA0yUVky2n0Yxga06agwXh/+f1mRvR6JZlbw8hqIusZzZZa:a6F2RNnB+Rpcnuj
              MD5:475813F4CABFFE076AEFBD618A982512
              SHA1:E2FEBCA085BD5F5AC9AA2313BAB17B4565A4024B
              SHA-256:EF5C02C221B5CB992728758E29195115A8F5481CF9CA5072A0616F95D00A362C
              SHA-512:5B253580F9147CA689C076B8F044E26AE37D5A2575C3FD02EC8E67C12CD273EBCC2C31C5631608340AE2D78F1DBE17F128909D4354118B4EF74BA27660C9CA76
              Malicious:true
              Yara Hits:
              • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, Author: Joe Security
              • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, Author: unknown
              • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, Author: Florian Roth
              • Rule: njrat1, Description: Identify njRat, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, Author: Brian Wallace @botnet_hunter
              • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, Author: JPCERT/CC Incident Response Group
              • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e67ceec44f16fc357df593d15ca3e96b.exe, Author: ditekSHen
              Antivirus:
              • Antivirus: Avira, Detection: 100%
              • Antivirus: Joe Sandbox ML, Detection: 100%
              • Antivirus: ReversingLabs, Detection: 95%
              • Antivirus: Virustotal, Detection: 88%, Browse
              Reputation:low
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.f.................V..........nt... ........@.. ....................................@..................................t..W.......@............................................................................ ............... ..H............text...tT... ...V.................. ..`.rsrc...@............X..............@..@.reloc...............\..............@..B................Pt......H.......,K...(....../....................................................0..........r...p.....r...p...........r...p.....r!..p.....r1..p.....rs..p.....r...p.....r...p.....r...p(.........r...p(.........r...p(.........r...p(.........(....o....s.........s.....................r...p...........s......... ..............r...p...........*...0..;.......~....o....o....r...p~....(.....o.....o......%(.....(......*.........,,.......0..D.......~....o....o....r...p~....(....o......(....o.....
              Process:C:\Users\user\Desktop\5556.rar.exe
              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
              Category:dropped
              Size (bytes):24064
              Entropy (8bit):5.511658847706215
              Encrypted:false
              SSDEEP:384:hFHuitNFzA0yUVky2n0Yxga06agwXh/+f1mRvR6JZlbw8hqIusZzZZa:a6F2RNnB+Rpcnuj
              MD5:475813F4CABFFE076AEFBD618A982512
              SHA1:E2FEBCA085BD5F5AC9AA2313BAB17B4565A4024B
              SHA-256:EF5C02C221B5CB992728758E29195115A8F5481CF9CA5072A0616F95D00A362C
              SHA-512:5B253580F9147CA689C076B8F044E26AE37D5A2575C3FD02EC8E67C12CD273EBCC2C31C5631608340AE2D78F1DBE17F128909D4354118B4EF74BA27660C9CA76
              Malicious:true
              Yara Hits:
              • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: Joe Security
              • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: unknown
              • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: Florian Roth
              • Rule: njrat1, Description: Identify njRat, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: Brian Wallace @botnet_hunter
              • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: JPCERT/CC Incident Response Group
              • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: ditekSHen
              Antivirus:
              • Antivirus: Avira, Detection: 100%
              • Antivirus: Joe Sandbox ML, Detection: 100%
              • Antivirus: ReversingLabs, Detection: 95%
              • Antivirus: Virustotal, Detection: 88%, Browse
              Reputation:low
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.f.................V..........nt... ........@.. ....................................@..................................t..W.......@............................................................................ ............... ..H............text...tT... ...V.................. ..`.rsrc...@............X..............@..@.reloc...............\..............@..B................Pt......H.......,K...(....../....................................................0..........r...p.....r...p...........r...p.....r!..p.....r1..p.....rs..p.....r...p.....r...p.....r...p(.........r...p(.........r...p(.........r...p(.........(....o....s.........s.....................r...p...........s......... ..............r...p...........*...0..;.......~....o....o....r...p~....(.....o.....o......%(.....(......*.........,,.......0..D.......~....o....o....r...p~....(....o......(....o.....
              Process:C:\Windows\SysWOW64\netsh.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):313
              Entropy (8bit):4.971939296804078
              Encrypted:false
              SSDEEP:6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha
              MD5:689E2126A85BF55121488295EE068FA1
              SHA1:09BAAA253A49D80C18326DFBCA106551EBF22DD6
              SHA-256:D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25
              SHA-512:C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C
              Malicious:false
              Preview:..IMPORTANT: Command executed successfully...However, "netsh firewall" is deprecated;..use "netsh advfirewall firewall" instead...For more information on using "netsh advfirewall firewall" commands..instead of "netsh firewall", see KB article 947709..at https://go.microsoft.com/fwlink/?linkid=121488 .....Ok.....
              File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
              Entropy (8bit):5.511658847706215
              TrID:
              • Win32 Executable (generic) Net Framework (10011505/4) 49.79%
              • Win32 Executable (generic) a (10002005/4) 49.75%
              • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
              • Windows Screen Saver (13104/52) 0.07%
              • Win16/32 Executable Delphi generic (2074/23) 0.01%
              File name:5556.rar.exe
              File size:24'064 bytes
              MD5:475813f4cabffe076aefbd618a982512
              SHA1:e2febca085bd5f5ac9aa2313bab17b4565a4024b
              SHA256:ef5c02c221b5cb992728758e29195115a8f5481cf9ca5072a0616f95d00a362c
              SHA512:5b253580f9147ca689c076b8f044e26ae37d5a2575c3fd02ec8e67c12cd273ebcc2c31c5631608340ae2d78f1dbe17f128909d4354118b4ef74ba27660c9ca76
              SSDEEP:384:hFHuitNFzA0yUVky2n0Yxga06agwXh/+f1mRvR6JZlbw8hqIusZzZZa:a6F2RNnB+Rpcnuj
              TLSH:C3B2190E3F698856C5BC167486B5965003B5D1870413EE2FCDC960CBAFB3AD92D8CAF9
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.f.................V..........nt... ........@.. ....................................@................................
              Icon Hash:90cececece8e8eb0
              Entrypoint:0x40746e
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
              Time Stamp:0x66AB7299 [Thu Aug 1 11:33:45 2024 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:4
              OS Version Minor:0
              File Version Major:4
              File Version Minor:0
              Subsystem Version Major:4
              Subsystem Version Minor:0
              Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
              Instruction
              jmp dword ptr [00402000h]
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x74140x57.text
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x80000x240.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0xa0000xc.reloc
              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x20000x54740x5600910a9d1ca4988cde5ad9426d1d5e7864False0.48846293604651164data5.558424897842657IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rsrc0x80000x2400x4000243c9a7f8755f2c2b18037cdad6cc91False0.310546875data4.966081339698093IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .reloc0xa0000xc0x200244385a828c8a3fb5ce307bb566c042aFalse0.044921875data0.07763316234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              RT_MANIFEST0x80580x1e7XML 1.0 document, ASCII text, with CRLF line terminators0.5338809034907598
              DLLImport
              mscoree.dll_CorExeMain
              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450030188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450022188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449832188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450004188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449977188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450043188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450011188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:36:40.941155+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:36:57.381892+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:36:57.381892+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:36:57.501651+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:36:57.501651+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449735188.212.158.755556TCP
              2024-12-16T07:37:02.112650+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:02.112650+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:02.236564+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:02.236564+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:03.149331+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449738188.212.158.755556TCP
              2024-12-16T07:37:06.939751+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:06.939751+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:07.060148+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:07.060148+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449739188.212.158.755556TCP
              2024-12-16T07:37:11.769051+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:11.769051+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:11.890182+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:11.890182+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449740188.212.158.755556TCP
              2024-12-16T07:37:16.611963+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:16.611963+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:16.731831+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:16.731831+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449741188.212.158.755556TCP
              2024-12-16T07:37:21.463298+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:21.463298+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:21.586920+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:21.586920+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449742188.212.158.755556TCP
              2024-12-16T07:37:26.348189+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:26.348189+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:26.468513+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:26.468513+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:27.727197+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449743188.212.158.755556TCP
              2024-12-16T07:37:31.211676+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:31.211676+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:31.331698+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:31.331698+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449745188.212.158.755556TCP
              2024-12-16T07:37:36.033958+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:36.033958+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:36.153963+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:36.153963+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449756188.212.158.755556TCP
              2024-12-16T07:37:41.026002+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:41.026002+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:41.145856+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:41.145856+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449771188.212.158.755556TCP
              2024-12-16T07:37:45.784966+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:45.784966+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:45.905041+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:45.905041+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:47.832737+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449784188.212.158.755556TCP
              2024-12-16T07:37:50.597895+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:50.597895+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:50.717794+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:50.717794+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:52.066852+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449795188.212.158.755556TCP
              2024-12-16T07:37:55.443438+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449807188.212.158.755556TCP
              2024-12-16T07:37:55.443438+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449807188.212.158.755556TCP
              2024-12-16T07:37:55.564618+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449807188.212.158.755556TCP
              2024-12-16T07:38:00.269136+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:00.269136+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:02.346343+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:02.466183+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:02.892474+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449817188.212.158.755556TCP
              2024-12-16T07:38:05.115012+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449832188.212.158.755556TCP
              2024-12-16T07:38:05.115012+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449832188.212.158.755556TCP
              2024-12-16T07:38:09.958841+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:38:09.958841+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:38:10.438381+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449844188.212.158.755556TCP
              2024-12-16T07:38:14.786492+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:38:14.786492+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:38:17.441745+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449855188.212.158.755556TCP
              2024-12-16T07:38:19.503639+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:19.503639+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:20.482561+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449866188.212.158.755556TCP
              2024-12-16T07:38:24.066446+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:24.066446+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.120517+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.240851+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.362260+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:26.482401+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449877188.212.158.755556TCP
              2024-12-16T07:38:28.533722+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:28.533722+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:29.133178+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:29.373202+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:29.915061+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:30.034869+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:30.154956+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449888188.212.158.755556TCP
              2024-12-16T07:38:33.011762+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:33.011762+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:33.135012+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:33.135012+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:33.259516+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:33.522180+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449899188.212.158.755556TCP
              2024-12-16T07:38:37.165582+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:37.165582+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.083579+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.222919+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.359974+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.479988+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:39.837455+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449910188.212.158.755556TCP
              2024-12-16T07:38:41.334137+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:41.334137+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.173741+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.293566+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.413835+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:42.596077+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:43.497040+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:43.616847+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449921188.212.158.755556TCP
              2024-12-16T07:38:45.410279+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:45.410279+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:45.770989+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:46.697150+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:46.817072+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449927188.212.158.755556TCP
              2024-12-16T07:38:49.425443+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:38:49.425443+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:38:52.076554+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.449938188.212.158.755556TCP
              2024-12-16T07:38:53.332543+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:38:53.332543+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:38:54.412719+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449949188.212.158.755556TCP
              2024-12-16T07:38:57.256016+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:38:57.256016+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:38:59.418114+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:38:59.876877+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449957188.212.158.755556TCP
              2024-12-16T07:39:01.036484+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:01.036484+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:02.911265+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:03.031493+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:03.405249+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449966188.212.158.755556TCP
              2024-12-16T07:39:04.724434+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449977188.212.158.755556TCP
              2024-12-16T07:39:04.724434+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449977188.212.158.755556TCP
              2024-12-16T07:39:08.381528+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:08.381528+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.188500+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.308484+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.635447+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:10.919836+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:11.039657+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449985188.212.158.755556TCP
              2024-12-16T07:39:11.974287+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:11.974287+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:13.175123+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:14.396951+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:14.517444+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.449994188.212.158.755556TCP
              2024-12-16T07:39:15.503052+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450004188.212.158.755556TCP
              2024-12-16T07:39:15.503052+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450004188.212.158.755556TCP
              2024-12-16T07:39:18.992362+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450011188.212.158.755556TCP
              2024-12-16T07:39:18.992362+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450011188.212.158.755556TCP
              2024-12-16T07:39:22.458585+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450022188.212.158.755556TCP
              2024-12-16T07:39:22.458585+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450022188.212.158.755556TCP
              2024-12-16T07:39:25.918148+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450030188.212.158.755556TCP
              2024-12-16T07:39:25.918148+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450030188.212.158.755556TCP
              2024-12-16T07:39:29.337101+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:29.337101+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:29.457012+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:30.262005+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:30.381773+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:30.501591+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450039188.212.158.755556TCP
              2024-12-16T07:39:32.650882+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:32.650882+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:32.894886+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:33.633586+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:33.873290+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450042188.212.158.755556TCP
              2024-12-16T07:39:35.973785+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450043188.212.158.755556TCP
              2024-12-16T07:39:35.973785+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450043188.212.158.755556TCP
              2024-12-16T07:39:39.237172+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:39:39.237172+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:39:41.881192+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450044188.212.158.755556TCP
              2024-12-16T07:39:42.611090+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:42.611090+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:42.730902+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:42.988374+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450045188.212.158.755556TCP
              2024-12-16T07:39:45.937510+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:45.937510+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:46.058030+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:46.177903+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450046188.212.158.755556TCP
              2024-12-16T07:39:49.119580+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:49.119580+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:49.239340+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:49.359163+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:49.478874+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450047188.212.158.755556TCP
              2024-12-16T07:39:52.381069+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:39:52.381069+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:39:52.500918+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450048188.212.158.755556TCP
              2024-12-16T07:39:55.458893+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:55.458893+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:55.578623+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:55.809667+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:55.929432+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450049188.212.158.755556TCP
              2024-12-16T07:39:58.544307+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:39:58.544307+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:40:01.069760+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450050188.212.158.755556TCP
              2024-12-16T07:40:01.659044+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:01.659044+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:02.631336+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:02.751324+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:03.053909+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:03.293744+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450051188.212.158.755556TCP
              2024-12-16T07:40:04.742331+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:04.742331+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:05.342915+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:07.146451+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450052188.212.158.755556TCP
              2024-12-16T07:40:07.815544+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:40:07.815544+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:40:09.978364+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450053188.212.158.755556TCP
              2024-12-16T07:40:10.878173+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:40:10.878173+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:40:13.163563+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450054188.212.158.755556TCP
              2024-12-16T07:40:13.942109+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:13.942109+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:15.983104+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:16.103206+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450055188.212.158.755556TCP
              2024-12-16T07:40:17.099776+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:17.099776+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:19.500780+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:19.631565+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:19.751452+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450056188.212.158.755556TCP
              2024-12-16T07:40:20.128602+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:20.128602+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:20.607656+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:22.670805+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:22.792173+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450057188.212.158.755556TCP
              2024-12-16T07:40:23.183069+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:40:23.183069+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:40:23.542755+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450058188.212.158.755556TCP
              2024-12-16T07:40:26.176634+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:40:26.176634+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:40:28.583243+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450059188.212.158.755556TCP
              2024-12-16T07:40:29.159134+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:40:29.159134+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:40:31.562850+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450060188.212.158.755556TCP
              2024-12-16T07:40:32.153283+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:40:32.153283+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:40:34.560161+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450061188.212.158.755556TCP
              2024-12-16T07:40:35.127258+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:40:35.127258+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:40:37.414042+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450062188.212.158.755556TCP
              2024-12-16T07:40:38.065383+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:40:38.065383+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:40:40.225036+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450063188.212.158.755556TCP
              2024-12-16T07:40:41.035015+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:41.035015+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:43.490589+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:43.490589+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450064188.212.158.755556TCP
              2024-12-16T07:40:43.982639+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:43.982639+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:44.995573+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:46.560451+01002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:46.560451+01002814860ETPRO MALWARE njRAT/Bladabindi CnC Callback (act)1192.168.2.450065188.212.158.755556TCP
              2024-12-16T07:40:49.064248+01002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.450066188.212.158.755556TCP
              2024-12-16T07:40:49.064248+01002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.450066188.212.158.755556TCP
              2024-12-16T07:40:49.183984+01002825563ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf)1192.168.2.450066188.212.158.755556TCP
              2024-12-16T07:40:49.183984+01002838486ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf)1192.168.2.450066188.212.158.755556TCP
              TimestampSource PortDest PortSource IPDest IP
              Dec 16, 2024 07:36:57.154419899 CET497355556192.168.2.4188.212.158.75
              Dec 16, 2024 07:36:57.274142981 CET555649735188.212.158.75192.168.2.4
              Dec 16, 2024 07:36:57.274216890 CET497355556192.168.2.4188.212.158.75
              Dec 16, 2024 07:36:57.381891966 CET497355556192.168.2.4188.212.158.75
              Dec 16, 2024 07:36:57.501600027 CET555649735188.212.158.75192.168.2.4
              Dec 16, 2024 07:36:57.501651049 CET497355556192.168.2.4188.212.158.75
              Dec 16, 2024 07:36:57.621334076 CET555649735188.212.158.75192.168.2.4
              Dec 16, 2024 07:36:59.980710030 CET555649735188.212.158.75192.168.2.4
              Dec 16, 2024 07:36:59.980784893 CET497355556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:01.988898039 CET497355556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:01.989402056 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:02.108752012 CET555649735188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:02.109163046 CET555649738188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:02.109323025 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:02.112649918 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:02.233254910 CET555649738188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:02.236563921 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:02.356415033 CET555649738188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:03.149331093 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:03.269165993 CET555649738188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:04.806638956 CET555649738188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:04.806747913 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:06.816827059 CET497385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:06.817195892 CET497395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:06.936522007 CET555649738188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:06.936834097 CET555649739188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:06.936908007 CET497395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:06.939750910 CET497395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:07.060039043 CET555649739188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:07.060148001 CET497395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:07.179846048 CET555649739188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:09.635133982 CET555649739188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:09.635210991 CET497395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:11.644534111 CET497395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:11.646143913 CET497405556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:11.764324903 CET555649739188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:11.765876055 CET555649740188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:11.765984058 CET497405556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:11.769051075 CET497405556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:11.890069962 CET555649740188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:11.890182018 CET497405556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:12.010195971 CET555649740188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:14.482635975 CET555649740188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:14.482753992 CET497405556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:16.488221884 CET497405556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:16.488723040 CET497415556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:16.607938051 CET555649740188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:16.608504057 CET555649741188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:16.608566046 CET497415556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:16.611963034 CET497415556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:16.731662989 CET555649741188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:16.731831074 CET497415556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:16.851573944 CET555649741188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:19.307292938 CET555649741188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:19.307362080 CET497415556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:21.316498041 CET497415556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:21.316847086 CET497425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:21.436438084 CET555649741188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:21.436623096 CET555649742188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:21.438858032 CET497425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:21.463298082 CET497425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:21.583026886 CET555649742188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:21.586920023 CET497425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:21.706903934 CET555649742188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:24.219496012 CET555649742188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:24.219786882 CET497425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:26.222644091 CET497425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:26.223081112 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:26.342425108 CET555649742188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:26.342808008 CET555649743188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:26.344542027 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:26.348189116 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:26.467967987 CET555649743188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:26.468513012 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:26.588300943 CET555649743188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:27.727196932 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:27.846951008 CET555649743188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:29.061152935 CET555649743188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:29.064589977 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:31.067276001 CET497435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:31.074990988 CET497455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:31.187228918 CET555649743188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:31.194803953 CET555649745188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:31.194886923 CET497455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:31.211675882 CET497455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:31.331542015 CET555649745188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:31.331697941 CET497455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:31.451631069 CET555649745188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:33.905601025 CET555649745188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:33.908601046 CET497455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:35.910085917 CET497455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:35.910660028 CET497565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:36.029948950 CET555649745188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:36.030391932 CET555649756188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:36.030724049 CET497565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:36.033957958 CET497565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:36.153784990 CET555649756188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:36.153963089 CET497565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:36.273746014 CET555649756188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:38.749104023 CET555649756188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:38.749188900 CET497565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:40.844474077 CET497565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:40.845138073 CET497715556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:40.964185953 CET555649756188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:40.964806080 CET555649771188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:40.964920044 CET497715556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:41.026001930 CET497715556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:41.145755053 CET555649771188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:41.145855904 CET497715556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:41.265692949 CET555649771188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:43.654051065 CET555649771188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:43.654179096 CET497715556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:45.660161972 CET497715556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:45.660847902 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:45.780128002 CET555649771188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:45.780531883 CET555649784188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:45.780632973 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:45.784965992 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:45.904876947 CET555649784188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:45.905040979 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:46.024983883 CET555649784188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:47.832736969 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:47.953032970 CET555649784188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:48.465754032 CET555649784188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:48.465898037 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:50.472719908 CET497845556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:50.473350048 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:50.593462944 CET555649784188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:50.593513012 CET555649795188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:50.593636036 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:50.597894907 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:50.717689037 CET555649795188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:50.717793941 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:50.839057922 CET555649795188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:52.066852093 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:52.186877966 CET555649795188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:53.312402964 CET555649795188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:53.312478065 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:55.316966057 CET497955556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:55.317598104 CET498075556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:55.436610937 CET555649795188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:55.437314034 CET555649807188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:55.437433004 CET498075556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:55.443438053 CET498075556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:55.563369036 CET555649807188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:55.564618111 CET498075556192.168.2.4188.212.158.75
              Dec 16, 2024 07:37:55.684483051 CET555649807188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:58.138092995 CET555649807188.212.158.75192.168.2.4
              Dec 16, 2024 07:37:58.138288975 CET498075556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.144481897 CET498075556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.145035028 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.264303923 CET555649807188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.264725924 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.264880896 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.269135952 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.390549898 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.392261982 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.512183905 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.512408972 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.632213116 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.632493973 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.752444983 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.752768993 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.874567986 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.874640942 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:00.994455099 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:00.994623899 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.114834070 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.114990950 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.234730959 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.236991882 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.357784033 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.357862949 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.477659941 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.479290962 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.599203110 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.599340916 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.719724894 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.719856977 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.839766979 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:01.840074062 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:01.960206985 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:02.346343040 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:02.466095924 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:02.466182947 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:02.585851908 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:02.892473936 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:02.984473944 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:02.984568119 CET498175556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:03.012128115 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:03.104379892 CET555649817188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:04.991030931 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.110999107 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.111099958 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.115011930 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.234719038 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.234833956 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.354545116 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.354754925 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.474416971 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.474507093 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.594201088 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.594260931 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.713920116 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.714051962 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.833730936 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.833959103 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:05.954420090 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:05.954492092 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.074331999 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.074712992 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.194593906 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.194670916 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.314526081 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.314620018 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.434724092 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.434993982 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.554824114 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.554960966 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.674741983 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.674880981 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.794539928 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.794627905 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:06.914294958 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:06.914359093 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.034135103 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.034203053 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.153955936 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.154016972 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.273823023 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.273911953 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.393659115 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.393755913 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.513592958 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.513876915 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.633745909 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.633832932 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.753851891 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.753978014 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.828423977 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.828509092 CET498325556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:07.873703003 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:07.948448896 CET555649832188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:09.832899094 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:09.952723980 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:09.952852011 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:09.958841085 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.078686953 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.078795910 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.198560953 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.198683977 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.318491936 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.318559885 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.438318968 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.438380957 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.558051109 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.558171988 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.677920103 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.678117037 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.797952890 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.798032045 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:10.917792082 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:10.917977095 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.037758112 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.037828922 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.157560110 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.157763004 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.277482033 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.277610064 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.397347927 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.397438049 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.517342091 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.517409086 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.637186050 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.637377977 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.757333994 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.757428885 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.877315044 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.877531052 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:11.997359991 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:11.997493982 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.117424011 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.119137049 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.239257097 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.243236065 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.363296986 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.364775896 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.484536886 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.486033916 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.605741978 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.605839968 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.658523083 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.659013033 CET498445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:12.725572109 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:12.778863907 CET555649844188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:14.660871983 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:14.780590057 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:14.783371925 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:14.786492109 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:14.906260967 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:14.906693935 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.026612043 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.030713081 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.150470972 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.150554895 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.270355940 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.270432949 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.390384912 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.390640974 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.510617018 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.510742903 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.630527020 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.630649090 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.750324965 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.750432014 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.870124102 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.870194912 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:15.990082979 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:15.990149975 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.110011101 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.111728907 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.231494904 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.236608982 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.356698990 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.359381914 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.479243040 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.479731083 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.599540949 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.600610971 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.720339060 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.720746994 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.840538979 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.841629982 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:16.961426973 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:16.961515903 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:17.081362009 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:17.082170963 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:17.201901913 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:17.202121973 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:17.321856022 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:17.321932077 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:17.441668034 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:17.441745043 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:17.502490044 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:17.502594948 CET498555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:17.561403036 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:17.622337103 CET555649855188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:19.380896091 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:19.500699043 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:19.500804901 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:19.503638983 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:19.623334885 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:19.623404026 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:19.743097067 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:20.482561111 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:20.716156006 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:20.716270924 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:20.838459969 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:20.838591099 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:20.958323956 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:20.958405018 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.078227997 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.078318119 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.198009014 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.199773073 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.319643021 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.323184013 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.442972898 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.444591999 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.564349890 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.564446926 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.684199095 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.684269905 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.804020882 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.807068110 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:21.927623987 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:21.928206921 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:22.047883987 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:22.048844099 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:22.168618917 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:22.168697119 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:22.187664032 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:22.187809944 CET498665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:22.288450003 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:22.308037043 CET555649866188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:23.942905903 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.062840939 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.062984943 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.066446066 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.186193943 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.186841011 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.306711912 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.307501078 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.427272081 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.427659988 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.547405958 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.547996044 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.667800903 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.667907953 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.788212061 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.789681911 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:24.910201073 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:24.910269976 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.030689955 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.031996965 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.151820898 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.151912928 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.271826029 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.275382996 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.395246029 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.396693945 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.516462088 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.516678095 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.636328936 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.638919115 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.758897066 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.760798931 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:25.880661011 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:25.880728006 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:26.000566959 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.000669003 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:26.120429993 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.120517015 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:26.240792990 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.240850925 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:26.361951113 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.362260103 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:26.482310057 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.482400894 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:26.602205992 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.768372059 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:26.768459082 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.410244942 CET498775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.411179066 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.529987097 CET555649877188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:28.530877113 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:28.531028986 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.533721924 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.653413057 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:28.653548956 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.773407936 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:28.773590088 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:28.893312931 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:28.893450022 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:29.013187885 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:29.013281107 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:29.133017063 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:29.133177996 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:29.253185987 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:29.253273964 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:29.373059034 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:29.373202085 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:29.492993116 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:29.915060997 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.034785986 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.034868956 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.154633045 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.154956102 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.274705887 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.274888992 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.394604921 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.394725084 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.514462948 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.514624119 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.634368896 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.634649038 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.754503012 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.754632950 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.874430895 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.874644041 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:30.994541883 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:30.994626999 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:31.114729881 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:31.118968010 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:31.237116098 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:31.238754034 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:31.238842010 CET498885556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:31.358681917 CET555649888188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:32.786178112 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:32.905843019 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:32.905946970 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.011761904 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.134938002 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:33.135011911 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.259438038 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:33.259516001 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.522119999 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:33.522180080 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.643502951 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:33.643563986 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.763540030 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:33.763623953 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:33.883455038 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:33.883569956 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.003395081 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.003501892 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.124012947 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.125751972 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.245825052 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.245922089 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.365722895 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.366624117 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.486844063 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.486983061 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.606781006 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.606864929 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.726608992 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.726707935 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.846446991 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.846625090 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:34.966387033 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:34.968357086 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.088159084 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.088598013 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.208362103 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.208446026 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.328237057 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.328299046 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.447993040 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.448079109 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.568300009 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.568375111 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.610110044 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.610228062 CET498995556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:35.688035965 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:35.729974985 CET555649899188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.039434910 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.159198999 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.159341097 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.165581942 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.285263062 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.285366058 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.405055046 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.405214071 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.524981022 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.525064945 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.644818068 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.644933939 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.764741898 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.764834881 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:37.884644985 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:37.884773016 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.004561901 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.004647970 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.124600887 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.124804020 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.244489908 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.244642019 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.364433050 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.364500046 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.484256983 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.484330893 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.604156017 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.604355097 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.724124908 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.724265099 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.843977928 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.844044924 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:38.963713884 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:38.963793993 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.083493948 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.083579063 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.203413010 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.222918987 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.342794895 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.359973907 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.479907036 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.479988098 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.599759102 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.837455034 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.878283024 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.878350973 CET499105556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:39.957627058 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:39.998150110 CET555649910188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.210437059 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.330116987 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.330250025 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.334136963 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.453799963 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.453883886 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.573585033 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.573674917 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.693432093 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.693694115 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.813486099 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.813566923 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:41.933208942 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:41.933310032 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:42.053934097 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:42.053999901 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:42.173675060 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:42.173741102 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:42.293422937 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:42.293565989 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:42.413763046 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:42.413835049 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:42.533529997 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:42.596076965 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:42.715821028 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:43.497040033 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:43.616770983 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:43.616847038 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:43.925976992 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:43.948519945 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:43.948684931 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:44.045720100 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:44.045838118 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:44.049815893 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:44.049880028 CET499215556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:44.068440914 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:44.165632010 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:44.169564962 CET555649921188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:45.285650015 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:45.405606031 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:45.407113075 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:45.410279036 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:45.529998064 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:45.531006098 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:45.650695086 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:45.650784016 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:45.770504951 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:45.770988941 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:45.890830994 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:46.697149992 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:46.816885948 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:46.817071915 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:46.936971903 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:46.937052011 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.056914091 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.057004929 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.176883936 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.178850889 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.298789978 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.298865080 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.418792963 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.419015884 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.538947105 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.539954901 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.659709930 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.660475016 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.780497074 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.780647039 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:47.900300980 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:47.900413990 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:48.020176888 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:48.020385027 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:48.140173912 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:48.140657902 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:48.143824100 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:48.143912077 CET499275556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:48.260520935 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:48.263674974 CET555649927188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:49.302418947 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:49.422295094 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:49.422424078 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:49.425442934 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:49.545253992 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:49.545320034 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:49.665003061 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:49.665128946 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:49.784878016 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:49.785166979 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:49.904891014 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:49.905090094 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.024797916 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.024908066 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.148320913 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.148503065 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.269911051 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.270071030 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.389853001 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.392667055 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.512454987 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.512643099 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.632384062 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.632663012 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.752455950 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.752564907 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.872386932 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.872695923 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:50.992671967 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:50.996684074 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.116456032 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.116635084 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.236381054 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.236511946 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.356187105 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.356302023 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.476200104 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.476495028 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.596492052 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.596612930 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.716402054 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.716532946 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.836318016 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.836539984 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:51.956357956 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:51.956469059 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:52.076340914 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:52.076554060 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:52.125992060 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:52.126085997 CET499385556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:52.196839094 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:52.245857000 CET555649938188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.207940102 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.327877998 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.328027010 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.332542896 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.452280998 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.452421904 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.572346926 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.572459936 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.692267895 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.692383051 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.812207937 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.812302113 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:53.932148933 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:53.932220936 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.051935911 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.052059889 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.171917915 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.172811985 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.292646885 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.292879105 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.412622929 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.412719011 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.532464027 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.532788992 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.654922009 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.656631947 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.776456118 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.776647091 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:54.896408081 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:54.896545887 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.016273022 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.016745090 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.136395931 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.136790037 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.256576061 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.256663084 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.376439095 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.376521111 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.496386051 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.496579885 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.616683960 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.617260933 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.737072945 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.737176895 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.856887102 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.856977940 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:55.976783037 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:55.976861000 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:56.018210888 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:56.018280983 CET499495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:56.096707106 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:56.138015032 CET555649949188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.035762072 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.252775908 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.252856016 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.256016016 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.375827074 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.375896931 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.495603085 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.495671034 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.615360975 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.615417004 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.735131979 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.735199928 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.854892969 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.854967117 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:57.974654913 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:57.974723101 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.094527960 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.094654083 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.214507103 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.214960098 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.334791899 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.335700989 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.455472946 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.455631971 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.575439930 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.575521946 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.695343971 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.695712090 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.815392971 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.816345930 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:58.936067104 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:58.936645985 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.056469917 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:59.056730986 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.176640034 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:59.178051949 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.298119068 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:59.298209906 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.418025970 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:59.418113947 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.537964106 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:59.876877069 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.956000090 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:38:59.956063032 CET499575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:38:59.996786118 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:00.075823069 CET555649957188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:00.912967920 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.033269882 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.033627033 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.036484003 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.156672955 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.157008886 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.276844978 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.280822039 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.401667118 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.401768923 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.521646976 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.521749973 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.641592979 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.644705057 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.764543056 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.764637947 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:01.884474039 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:01.884629011 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.004535913 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.004743099 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.124453068 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.124872923 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.244612932 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.244807005 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.366254091 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.366337061 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.486583948 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.486705065 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.607212067 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.607405901 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:02.727220058 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:02.911264896 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:03.031291962 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:03.031492949 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:03.151397943 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:03.405249119 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:03.525223970 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:03.525300980 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:03.645029068 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:03.645092010 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:03.721070051 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:03.721136093 CET499665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:03.764817953 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:03.840873003 CET555649966188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:04.598639965 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:04.718550920 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:04.720678091 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:04.724433899 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:04.844125032 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:04.844624996 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:04.964792967 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:04.965742111 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.085591078 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.087532043 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.207880020 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.208129883 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.329659939 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.329869986 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.454215050 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.454360008 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.576776028 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.576919079 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.699697971 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.699893951 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.820554018 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.820723057 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:05.940383911 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:05.940872908 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.060617924 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.060769081 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.180701017 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.180852890 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.300570965 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.300966024 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.420902967 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.421030045 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.540750027 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.541579008 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.661320925 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.661478996 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.781167030 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.784668922 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:06.904383898 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:06.904679060 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:07.024818897 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:07.025058985 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:07.144814014 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:07.145709991 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:07.266854048 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:07.266999006 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:07.386823893 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:07.386941910 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:07.426835060 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:07.426912069 CET499775556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:07.507533073 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:07.546680927 CET555649977188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.254452944 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.374202967 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.376737118 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.381527901 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.501368046 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.501460075 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.621243954 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.622395992 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.742902040 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.742983103 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.862787008 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.864662886 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:08.984386921 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:08.984659910 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.104490042 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.104651928 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.224447012 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.224514008 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.344424009 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.344527960 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.468187094 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.468261003 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.588035107 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.588112116 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.708702087 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.708795071 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.828500986 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.828571081 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:09.948563099 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:09.948668003 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:10.068429947 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:10.068588018 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:10.188404083 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:10.188499928 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:10.308427095 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:10.308484077 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:10.428253889 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:10.635447025 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:10.755481958 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:10.919836044 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:11.039593935 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:11.039657116 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:11.083780050 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:11.083841085 CET499855556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:11.159653902 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:11.203509092 CET555649985188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:11.848228931 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:11.967984915 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:11.971050024 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:11.974287033 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.094140053 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.095035076 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.214754105 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.214821100 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.334557056 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.334642887 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.454440117 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.454516888 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.574301004 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.574400902 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.694494009 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.694616079 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.814574957 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.814764023 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:12.934969902 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:12.935071945 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:13.055155993 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:13.055233955 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:13.175040007 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:13.175122976 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:13.295233965 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:13.296716928 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:13.416735888 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:13.418695927 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:13.538513899 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:14.396950960 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:14.517376900 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:14.517443895 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:14.637461901 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:14.637523890 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:14.661755085 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:14.661825895 CET499945556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:14.757276058 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:14.781536102 CET555649994188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:15.379518032 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:15.499290943 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:15.499427080 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:15.503051996 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:15.622777939 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:15.624653101 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:15.745918989 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:15.748684883 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:15.870011091 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:15.872668982 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:15.992477894 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:15.995170116 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.114844084 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.116631985 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.236327887 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.236443996 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.356895924 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.357021093 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.476731062 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.476802111 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.596506119 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.596587896 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.716336966 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.716417074 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.836278915 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.836513996 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:16.956243992 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:16.956382990 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.076096058 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.076180935 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.195890903 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.195976019 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.315793037 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.315865040 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.435619116 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.435741901 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.555510044 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.555587053 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.675357103 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.675417900 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.795140982 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.795207024 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:17.914999008 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:17.915086985 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:18.034861088 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:18.034977913 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:18.154671907 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:18.154759884 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:18.190960884 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:18.191056967 CET500045556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:18.274715900 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:18.310826063 CET555650004188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:18.864491940 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:18.984411955 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:18.988507986 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:18.992362022 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.112212896 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.114855051 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.234729052 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.234805107 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.355022907 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.355125904 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.475001097 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.475087881 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.595107079 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.595252991 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.715276003 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.715364933 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.835185051 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.835268974 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:19.955089092 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:19.955173969 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.075073957 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.075185061 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.195081949 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.195219040 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.315074921 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.315340996 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.435182095 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.435332060 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.555172920 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.555525064 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.675438881 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.675616026 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.795492887 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.795654058 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:20.916398048 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:20.916579008 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.037086964 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.037329912 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.157215118 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.157298088 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.277769089 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.277873993 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.397607088 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.397746086 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.517545938 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.517613888 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.638905048 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.638994932 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.707149029 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.707223892 CET500115556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:21.759052992 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:21.826946020 CET555650011188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:22.333082914 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:22.452845097 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:22.452965975 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:22.458585024 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:22.578485966 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:22.578562021 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:22.698359966 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:22.698451042 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:22.818233967 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:22.818319082 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:22.938038111 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:22.938158035 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.059606075 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.059731960 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.179433107 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.179529905 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.299282074 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.300652981 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.420408010 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.420689106 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.540433884 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.540514946 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.660398960 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.660512924 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.780348063 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.780448914 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:23.900214911 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:23.900289059 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.020087957 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.024666071 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.144722939 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.147703886 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.267587900 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.267676115 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.387516975 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.387614965 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.507474899 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.507549047 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.627370119 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.627449989 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.747523069 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.747612000 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.867675066 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.867759943 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:24.987879038 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:24.988081932 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:25.108143091 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:25.108221054 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:25.177824974 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:25.177903891 CET500225556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:25.227955103 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:25.297739029 CET555650022188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:25.789031982 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:25.908972025 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:25.912697077 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:25.918148041 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.037996054 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.039557934 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.159523010 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.160902023 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.280781031 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.281013966 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.400934935 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.401026011 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.520886898 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.520987034 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.640719891 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.640791893 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.760545015 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.760708094 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:26.880697966 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:26.881077051 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.000895023 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.000998020 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.120672941 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.120881081 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.240617990 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.242021084 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.361753941 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.361920118 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.481630087 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.481755972 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.601470947 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.601538897 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.721190929 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.721265078 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.840984106 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.841053009 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:27.961224079 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:27.961333990 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.081235886 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.081394911 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.201288939 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.201374054 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.321250916 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.321418047 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.441472054 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.441553116 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.562175989 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.562238932 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.651907921 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.651978970 CET500305556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:28.681982994 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:28.771713018 CET555650030188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:29.193635941 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:29.313863993 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:29.315186024 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:29.337100983 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:29.456857920 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:29.457011938 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:29.577037096 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.262005091 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:30.381699085 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.381772995 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:30.501480103 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.501590967 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:30.621238947 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.621309996 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:30.741906881 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.742028952 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:30.861849070 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.862030983 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:30.981785059 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:30.981849909 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.101622105 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.101701021 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.221462965 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.221568108 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.341378927 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.344717026 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.464518070 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.464639902 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.584916115 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.584985971 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.704628944 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.707633018 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.827435970 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.828674078 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:31.948482037 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:31.948666096 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:32.003801107 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:32.004452944 CET500395556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:32.068373919 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:32.127055883 CET555650039188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:32.525743961 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:32.645482063 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:32.645579100 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:32.650882006 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:32.773860931 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:32.773930073 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:32.894659996 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:32.894886017 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:33.014637947 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:33.633585930 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:33.753319025 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:33.753403902 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:33.873198032 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:33.873290062 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:33.994149923 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:33.994257927 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.114505053 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.115228891 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.234982967 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.236881971 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.356719017 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.356933117 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.476804972 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.476917982 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.596832037 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.596944094 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.716737032 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.716824055 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:34.907257080 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:34.907352924 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.028080940 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.028156996 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.148334026 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.148525953 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.269025087 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.269098043 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.375423908 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.375510931 CET500425556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.388787985 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.495539904 CET555650042188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.851440907 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.971343994 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:35.971419096 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:35.973784924 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.093688965 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.093851089 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.213609934 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.213696957 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.334111929 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.334181070 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.453922987 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.454081059 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.573770046 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.573838949 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.693664074 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.693758965 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.813477039 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.813556910 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:36.933257103 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:36.933348894 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.053210974 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.053303957 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.174065113 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.174139023 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.293916941 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.293999910 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.413764954 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.414165974 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.534071922 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.534338951 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.654017925 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.654126883 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.773962021 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.774048090 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:37.893737078 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:37.893908024 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.013727903 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.013966084 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.133721113 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.133795977 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.253549099 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.253638029 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.373337030 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.373413086 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.493273973 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.493376017 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.613172054 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.613270998 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.660176039 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.660250902 CET500435556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:38.733223915 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:38.780237913 CET555650043188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.113919020 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.233840942 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.233956099 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.237171888 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.356980085 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.357050896 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.476835966 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.480715036 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.600442886 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.600547075 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.720247984 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.720484972 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.840173960 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.840248108 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:39.959928989 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:39.960779905 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.080600023 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.080694914 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.200423002 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.201800108 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.321574926 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.321666956 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.441334009 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.441422939 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.561094999 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.561167955 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.680874109 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.680947065 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.801145077 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.801338911 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:40.920948029 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:40.921144009 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.040868998 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.040961981 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.160598040 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.160676003 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.280647993 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.280848026 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.400592089 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.400757074 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.520483017 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.520553112 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.640259027 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.640324116 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.760143042 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.760332108 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:41.881124973 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:41.881191969 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.000999928 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.001065969 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.005105972 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.005167007 CET500445556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.120764971 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.124876022 CET555650044188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.436999083 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.558228016 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.558502913 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.611089945 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.730823994 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.730901957 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:42.850615978 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:42.988373995 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.108207941 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.108273029 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.228101969 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.228168011 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.347852945 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.347910881 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.467562914 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.467628956 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.587260962 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.587394953 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.707133055 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.707209110 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.826942921 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.827049971 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:43.946795940 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:43.946953058 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.066728115 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.066816092 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.186585903 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.186707973 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.306519985 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.308675051 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.428384066 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.428740025 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.548485994 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.548677921 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.668365955 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.668682098 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.788469076 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.788655996 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:44.908363104 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:44.908442020 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:45.028103113 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:45.028681040 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:45.148446083 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:45.148547888 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:45.254234076 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:45.254347086 CET500455556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:45.268395901 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:45.374043941 CET555650045188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:45.703744888 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:45.823698997 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:45.823803902 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:45.937510014 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.057948112 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.058029890 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.177839041 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.177902937 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.297781944 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.297842026 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.417571068 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.417732000 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.537384033 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.537480116 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.657413006 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.657485008 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.777206898 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.777298927 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:46.896956921 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:46.897077084 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.016813040 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.017026901 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.136986017 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.137079000 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.256859064 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.256928921 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.376579046 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.376681089 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.496362925 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.496588945 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.616312027 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.616389990 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.736151934 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.736238003 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.855921984 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.856000900 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:47.975680113 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:47.975764036 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:48.112085104 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.112216949 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:48.232116938 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.232376099 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:48.352195024 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.352272987 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:48.472064018 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.472150087 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:48.519884109 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.519958973 CET500465556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:48.591869116 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.639674902 CET555650046188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:48.882478952 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.002207041 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.002329111 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.119580030 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.239264011 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.239340067 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.359105110 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.359163046 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.478820086 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.478873968 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.598613977 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.598695993 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.718400002 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.718503952 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.838627100 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.838705063 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:49.958803892 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:49.958883047 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.078632116 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.078814030 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.198582888 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.198694944 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.318619013 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.318739891 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.438740015 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.438823938 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.558485031 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.558588982 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.678899050 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.678973913 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.798702002 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.800461054 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:50.920161963 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:50.922688007 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.042363882 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.042762995 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.162542105 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.162633896 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.282464027 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.282543898 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.402482033 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.402549982 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.522233009 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.522319078 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.642095089 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.642278910 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.725935936 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.726033926 CET500475556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:51.761970997 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:51.845743895 CET555650047188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.067241907 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.206617117 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.206717968 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.381068945 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.500850916 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.500917912 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.620649099 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.620735884 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.740473986 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.740556002 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.860338926 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.860637903 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:52.980458975 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:52.980778933 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.100660086 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.100888968 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.220729113 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.220819950 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.340579987 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.340712070 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.460478067 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.464812994 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.584580898 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.588473082 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.708209038 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.708314896 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.828222036 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.828804016 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:53.948633909 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:53.952827930 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.074455023 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.076880932 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.196978092 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.200792074 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.320715904 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.320805073 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.441530943 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.441629887 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.563370943 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.563441992 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.683373928 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.683456898 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.803360939 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.803467989 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.911669970 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:54.911761045 CET500485556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:54.923221111 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:55.031582117 CET555650048188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:55.243757010 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:55.363689899 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:55.363789082 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:55.458893061 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:55.578553915 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:55.578623056 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:55.698262930 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:55.809667110 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:55.929378986 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:55.929431915 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.049143076 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.049262047 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.169015884 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.169116020 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.288892984 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.289150953 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.408987999 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.409318924 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.529593945 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.529773951 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.649466991 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.649538994 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.769269943 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.769412994 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:56.889319897 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:56.889414072 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.009202003 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.009361982 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.129136086 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.129277945 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.249275923 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.249480009 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.369338989 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.369561911 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.489379883 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.489480019 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.610766888 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.610903978 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.730633974 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.730714083 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.850621939 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.850697994 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:57.970474005 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:57.970621109 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.090662956 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.090739965 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.104624987 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.104696035 CET500495556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.210433006 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.224566936 CET555650049188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.421196938 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.540970087 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.541229963 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.544306993 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.670568943 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.670731068 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.790416002 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.790486097 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:58.910176992 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:58.910269022 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.029970884 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.030050993 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.149799109 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.149981976 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.269798040 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.269952059 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.390141964 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.390290976 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.510056019 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.510155916 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.629968882 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.630105019 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.749954939 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.750137091 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.870038033 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.870132923 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:39:59.990000963 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:39:59.990086079 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.110322952 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.110404968 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.230325937 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.230403900 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.350122929 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.350183964 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.469933033 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.470010042 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.589771032 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.589899063 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.709661961 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.709888935 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.829653025 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.829782963 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:00.949740887 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:00.949858904 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.069605112 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.069760084 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.189497948 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.189567089 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.259876013 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.259993076 CET500505556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.309931993 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.379707098 CET555650050188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.535995007 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.655982018 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.656126022 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.659044027 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.778851986 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.778939962 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:01.898845911 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:01.899002075 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:02.018940926 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:02.019195080 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:02.139036894 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:02.139256001 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:02.259450912 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:02.259722948 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:02.380436897 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:02.631335974 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:02.751250029 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:02.751323938 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:02.871155024 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.053909063 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.173887968 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.173954964 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.293678999 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.293744087 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.413579941 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.413819075 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.533689976 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.533987045 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.653851032 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.653943062 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.773736000 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.773802042 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:03.893569946 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:03.893672943 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.015430927 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.015676975 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.136318922 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.136559963 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.257436991 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.257586956 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.350842953 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.351031065 CET500515556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.377620935 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.470886946 CET555650051188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.615297079 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.735111952 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.735378981 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.742331028 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.862166882 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.862412930 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:04.982239008 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:04.982338905 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.102148056 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.102350950 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.222075939 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.222162008 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.342796087 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.342915058 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.462718010 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.462905884 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.582763910 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.583014011 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.702744007 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.702960968 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.822714090 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.822958946 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:05.942833900 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:05.942943096 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.062856913 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.063098907 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.183568954 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.183830023 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.303977966 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.304058075 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.423841000 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.423918009 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.543677092 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.543759108 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.663523912 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.663758039 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.783582926 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.783715010 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:06.903655052 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:06.903858900 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.026344061 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.026520967 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.146358013 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.146450996 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.266292095 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.266586065 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.386456013 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.386534929 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.451169968 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.451231003 CET500525556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.506263018 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.571363926 CET555650052188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.692305088 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.812685966 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.812942028 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.815543890 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:07.935250998 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:07.935450077 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.055267096 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.055382013 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.175189018 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.175394058 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.296291113 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.296406031 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.535394907 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.535597086 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.656095982 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.656181097 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.775867939 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.776016951 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:08.895785093 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:08.895879984 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.015600920 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.015714884 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.135432959 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.135560036 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.255300999 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.255398035 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.375518084 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.375628948 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.495862961 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.495953083 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.615746021 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.615853071 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.736458063 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.736543894 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.857304096 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.857399940 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:09.978234053 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:09.978363991 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.100886106 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.100986958 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.223035097 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.223258972 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.342961073 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.343142033 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.463294983 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.463399887 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.524930000 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.525053024 CET500535556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.583395004 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.644691944 CET555650053188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.754487038 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.875207901 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.875298977 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.878173113 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:10.997948885 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:10.998044014 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.117885113 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.117990017 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.237741947 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.237863064 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.360554934 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.360738993 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.480654001 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.480829954 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.600610018 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.600743055 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.720526934 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.720669031 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.841326952 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.841417074 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:11.961178064 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:11.961340904 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.081150055 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.081280947 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.201122046 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.201291084 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.321079969 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.321377039 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.442399025 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.442514896 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.562263012 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.562463999 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.682243109 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.682403088 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.803405046 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.803514957 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:12.923329115 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:12.923631907 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.043510914 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.043603897 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.163466930 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.163563013 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.283389091 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.283601046 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.403536081 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.403708935 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.523838043 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.523963928 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.604804993 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.604932070 CET500545556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.643827915 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.724653006 CET555650054188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.817728996 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.937611103 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:13.937706947 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:13.942109108 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.061830997 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.061990976 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.182478905 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.182599068 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.302484989 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.302561998 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.422308922 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.422379971 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.542125940 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.542191029 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.663439035 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.663535118 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.783457994 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.783567905 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:14.903274059 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:14.903388977 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.023228884 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.023293972 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.143076897 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.143269062 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.263142109 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.263358116 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.383233070 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.383467913 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.503344059 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.503504038 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.623248100 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.623334885 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.743083954 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.743199110 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.863029957 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.863130093 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:15.982979059 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:15.983103991 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:16.103054047 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:16.103205919 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:16.223366976 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:16.631910086 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:16.631964922 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:16.975897074 CET500555556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:16.976994038 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.095690012 CET555650055188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.096719980 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.096797943 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.099776030 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.219784975 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.220228910 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.340015888 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.340215921 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.459994078 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.460093021 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.579893112 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.580219984 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.700053930 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.700124979 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.819914103 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.820271015 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:17.940078974 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:17.940515995 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.060319901 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.060429096 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.180248022 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.180517912 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.300862074 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.300920010 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.420665026 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.420737028 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.540458918 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.540514946 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.660197020 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.660604000 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.780435085 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.780607939 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:18.900803089 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:18.900893927 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.020657063 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.020731926 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.140682936 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.140753984 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.260612011 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.260716915 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.380588055 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.380784988 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.500593901 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.500780106 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.620698929 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.631565094 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.751311064 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.751451969 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.788748980 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.788805962 CET500565556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:19.871408939 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.908834934 CET555650056188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:19.988945961 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.108871937 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.108952999 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.128602028 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.248322964 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.248384953 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.368052006 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.368124008 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.487816095 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.487881899 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.607597113 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.607656002 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.727320910 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.727451086 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.847147942 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.847259045 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:20.967128038 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:20.967319965 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.087161064 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.087232113 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.207164049 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.207245111 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.327025890 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.327142954 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.447101116 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.447325945 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.567281961 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.568099022 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.687746048 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.690844059 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.810683966 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.812829971 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:21.932691097 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:21.933446884 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.053319931 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.053711891 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.173655987 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.173835993 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.293699026 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.294764042 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.414546013 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.414654970 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.534439087 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.534734964 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.654712915 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.670804977 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.792118073 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.792172909 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.856636047 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.856777906 CET500575556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:22.911920071 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:22.976519108 CET555650057188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.048568964 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.168595076 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.169641972 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.183068991 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.302874088 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.302932024 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.422780991 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.422862053 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.542682886 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.542754889 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.662699938 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.662868977 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.782954931 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.783205986 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:23.903067112 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:23.903300047 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.023282051 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.023459911 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.143357992 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.143436909 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.263341904 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.263521910 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.383379936 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.383670092 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.545922041 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.548863888 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.720669031 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.724905968 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.845470905 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.848922014 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:24.968662977 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:24.968756914 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.088635921 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.092802048 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.212666035 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.217099905 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.337029934 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.340961933 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.460949898 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.461045980 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.580931902 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.581144094 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.701066017 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.701268911 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.821264982 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.821403027 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.885442019 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:25.885674000 CET500585556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:25.941284895 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.005511999 CET555650058188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.053553104 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.173415899 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.173557997 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.176634073 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.296493053 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.296689987 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.416821957 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.417212963 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.537188053 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.537477970 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.657294989 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.657496929 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.779472113 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.779551983 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:26.899394035 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:26.899940968 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.019818068 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.019969940 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.140696049 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.141977072 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.262043953 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.262162924 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.382796049 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.382942915 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.502938032 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.503175974 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.623375893 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.623447895 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.743424892 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.743608952 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.863511086 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.863653898 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:27.983403921 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:27.983488083 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.103368044 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.103442907 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.223256111 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.223337889 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.343126059 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.343334913 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.463149071 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.463351965 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.583117962 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.583242893 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.703105927 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.703299999 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.823105097 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.823291063 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.886981010 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:28.887082100 CET500595556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:28.943033934 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.006854057 CET555650059188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.036127090 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.155996084 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.156196117 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.159133911 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.278898954 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.278983116 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.398933887 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.399039030 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.518802881 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.518964052 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.638859034 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.639070988 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.758979082 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.759232044 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.879196882 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.879333019 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:29.999171019 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:29.999247074 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.119302988 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.119407892 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.239206076 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.239409924 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.359384060 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.359540939 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.479351044 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.479424000 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.599225044 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.599330902 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.719156981 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.719324112 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.839138031 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.839359999 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:30.959309101 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:30.959433079 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.079287052 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.079354048 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.199333906 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.199407101 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.319294930 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.319360971 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.439228058 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.439865112 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.560517073 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.562849998 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.682758093 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.683363914 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.803198099 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.803291082 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.870235920 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.870302916 CET500605556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:31.923031092 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:31.990045071 CET555650060188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.020174980 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.140295029 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.144779921 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.153283119 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.273102999 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.275791883 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.395692110 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.395852089 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.515697956 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.515894890 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.635693073 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.635835886 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.755573988 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.755666018 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.875371933 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.875453949 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:32.995213985 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:32.995300055 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.115284920 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.115370035 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.235445023 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.235641003 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.355463982 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.355643988 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.475435019 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.475703001 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.595760107 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.595977068 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.715759993 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.715840101 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.835591078 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.835747957 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:33.955537081 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:33.955666065 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.075643063 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.075728893 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.195657015 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.195734024 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.316164970 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.316380024 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.436350107 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.436589956 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.559871912 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.560161114 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.679934025 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.680038929 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.799788952 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.800112009 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.869893074 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.870045900 CET500615556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:34.919753075 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:34.989816904 CET555650061188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.004549980 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.124408007 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.124526978 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.127258062 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.247411966 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.247474909 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.369338989 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.369455099 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.489097118 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.489178896 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.609503984 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.609625101 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.731273890 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.731374979 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.851149082 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.851371050 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:35.971304893 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:35.971550941 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.091345072 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.091413021 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.211190939 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.211558104 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.331382990 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.331465006 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.452186108 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.452259064 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.573193073 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.573407888 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.693593979 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.693671942 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.813477039 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.813676119 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:36.933466911 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:36.933650970 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.053725004 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.053885937 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.173912048 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.174037933 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.293946981 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.294019938 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.413916111 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.414041996 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.533787012 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.533863068 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.653594971 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.653804064 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.773572922 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.773711920 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.820579052 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.820841074 CET500625556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:37.893491030 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.940694094 CET555650062188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:37.942096949 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.061996937 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.062165022 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.065382957 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.185241938 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.185343981 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.305737972 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.305969954 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.425795078 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.425888062 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.545646906 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.545805931 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.665697098 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.665775061 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.785547018 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.785677910 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:38.905445099 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:38.905575991 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.025422096 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.025522947 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.145318985 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.145550013 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.265240908 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.265561104 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.385262966 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.385411024 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.505215883 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.505413055 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.625108957 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.625181913 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.744941950 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.745028019 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.864758015 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.864835978 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:39.984592915 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:39.984777927 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.104844093 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.104932070 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.224946976 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.225035906 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.344851017 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.345124960 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.464931965 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.465182066 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.584944010 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.585020065 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.704747915 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.704981089 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.784461975 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.784529924 CET500635556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:40.824750900 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.904908895 CET555650063188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:40.912004948 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.031740904 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.031862974 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.035015106 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.154669046 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.154867887 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.274765015 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.274966002 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.394712925 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.394782066 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.514513969 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.514594078 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.634251118 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.634330034 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.755012989 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.755170107 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.876236916 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.876333952 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:41.996167898 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:41.996247053 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.116149902 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.116276979 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.236054897 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.236155033 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.355907917 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.356075048 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.475927114 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.476097107 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.596090078 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.596304893 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.716308117 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.716376066 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.836278915 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.836426973 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:42.956146955 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:42.956258059 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.076127052 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.076239109 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.196012974 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.196146011 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.315972090 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.316076040 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.435838938 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.490588903 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.610373974 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.611350060 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.729444027 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.731074095 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.731102943 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.847865105 CET500645556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.848287106 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.850775003 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.967664003 CET555650064188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.967979908 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:43.968116999 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:43.982639074 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.102370024 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.102477074 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.222296953 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.222410917 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.342092991 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.345412016 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.465200901 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.468853951 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.588841915 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.592787981 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.712467909 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.712909937 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.832600117 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.832798004 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:44.952537060 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:44.995573044 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.115714073 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.116827965 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.236543894 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.236681938 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.356347084 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.358330011 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.478032112 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.478288889 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.598057985 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.598411083 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.718269110 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.718435049 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.838140011 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.838263035 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:45.958051920 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:45.959348917 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:46.079205990 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.079336882 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:46.199202061 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.199286938 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:46.319164991 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.319338083 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:46.439239025 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.439351082 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:46.560357094 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.560451031 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:46.680250883 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.699876070 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:46.700114965 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:48.941826105 CET500655556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:48.942513943 CET500665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:49.061605930 CET555650065188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:49.062189102 CET555650066188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:49.062339067 CET500665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:49.064248085 CET500665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:49.183932066 CET555650066188.212.158.75192.168.2.4
              Dec 16, 2024 07:40:49.183984041 CET500665556192.168.2.4188.212.158.75
              Dec 16, 2024 07:40:49.303745985 CET555650066188.212.158.75192.168.2.4

              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:0
              Start time:01:36:39
              Start date:16/12/2024
              Path:C:\Users\user\Desktop\5556.rar.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\5556.rar.exe"
              Imagebase:0x380000
              File size:24'064 bytes
              MD5 hash:475813F4CABFFE076AEFBD618A982512
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
              • Rule: njrat1, Description: Identify njRat, Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, Author: Brian Wallace @botnet_hunter
              • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000002.1837863185.0000000002B41000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
              • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, Author: unknown
              • Rule: njrat1, Description: Identify njRat, Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, Author: Brian Wallace @botnet_hunter
              • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000000.1770794894.0000000000382000.00000002.00000001.01000000.00000003.sdmp, Author: JPCERT/CC Incident Response Group
              Reputation:low
              Has exited:true

              Target ID:1
              Start time:01:36:46
              Start date:16/12/2024
              Path:C:\Users\user\AppData\Roaming\lsass.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Roaming\lsass.exe"
              Imagebase:0xf40000
              File size:24'064 bytes
              MD5 hash:475813F4CABFFE076AEFBD618A982512
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000001.00000002.4229641773.0000000003C41000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: Joe Security
              • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: unknown
              • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: Florian Roth
              • Rule: njrat1, Description: Identify njRat, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: Brian Wallace @botnet_hunter
              • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: JPCERT/CC Incident Response Group
              • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\lsass.exe, Author: ditekSHen
              Antivirus matches:
              • Detection: 100%, Avira
              • Detection: 100%, Joe Sandbox ML
              • Detection: 95%, ReversingLabs
              • Detection: 88%, Virustotal, Browse
              Reputation:low
              Has exited:false

              Target ID:4
              Start time:01:36:52
              Start date:16/12/2024
              Path:C:\Windows\SysWOW64\netsh.exe
              Wow64 process (32bit):true
              Commandline:netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\lsass.exe" "lsass.exe" ENABLE
              Imagebase:0x1560000
              File size:82'432 bytes
              MD5 hash:4E89A1A088BE715D6C946E55AB07C7DF
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:5
              Start time:01:36:52
              Start date:16/12/2024
              Path:C:\Windows\System32\conhost.exe
              Wow64 process (32bit):false
              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Imagebase:0x7ff7699e0000
              File size:862'208 bytes
              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:7
              Start time:01:37:05
              Start date:16/12/2024
              Path:C:\Users\user\AppData\Roaming\lsass.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Roaming\lsass.exe" ..
              Imagebase:0x7d0000
              File size:24'064 bytes
              MD5 hash:475813F4CABFFE076AEFBD618A982512
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:8
              Start time:01:37:13
              Start date:16/12/2024
              Path:C:\Users\user\AppData\Roaming\lsass.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Roaming\lsass.exe" ..
              Imagebase:0x900000
              File size:24'064 bytes
              MD5 hash:475813F4CABFFE076AEFBD618A982512
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:9
              Start time:01:37:21
              Start date:16/12/2024
              Path:C:\Users\user\AppData\Roaming\lsass.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Roaming\lsass.exe" ..
              Imagebase:0xb30000
              File size:24'064 bytes
              MD5 hash:475813F4CABFFE076AEFBD618A982512
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Reset < >

                Execution Graph

                Execution Coverage:11.7%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:47
                Total number of Limit Nodes:2
                execution_graph 1374 96ae52 1375 96ae78 ShellExecuteExW 1374->1375 1377 96ae94 1375->1377 1406 96a612 1407 96a646 CreateMutexW 1406->1407 1409 96a6c1 1407->1409 1422 96a2d2 1423 96a2d6 SetErrorMode 1422->1423 1425 96a33f 1423->1425 1410 96a710 1412 96a720 CloseHandle 1410->1412 1413 96a788 1412->1413 1418 96ae30 1420 96ae52 ShellExecuteExW 1418->1420 1421 96ae94 1420->1421 1382 96a2fe 1383 96a32a SetErrorMode 1382->1383 1385 96a353 1382->1385 1384 96a33f 1383->1384 1385->1383 1426 96aa5c 1427 96aa9e GetFileType 1426->1427 1429 96ab00 1427->1429 1386 96a986 1387 96a9be CreateFileW 1386->1387 1389 96aa0d 1387->1389 1394 96a646 1396 96a67e CreateMutexW 1394->1396 1397 96a6c1 1396->1397 1434 96a462 1435 96a486 RegSetValueExW 1434->1435 1437 96a507 1435->1437 1438 96a361 1439 96a392 RegQueryValueExW 1438->1439 1441 96a41b 1439->1441 1398 96ac2e 1400 96ac63 WriteFile 1398->1400 1401 96ac95 1400->1401 1402 96a74e 1403 96a77a CloseHandle 1402->1403 1404 96a7b9 1402->1404 1405 96a788 1403->1405 1404->1403 1414 96ac0e 1416 96ac2e WriteFile 1414->1416 1417 96ac95 1416->1417 1430 96a94f 1432 96a986 CreateFileW 1430->1432 1433 96aa0d 1432->1433

                Callgraph

                • Executed
                • Not Executed
                • Opacity -> Relevance
                • Disassembly available
                callgraph 0 Function_00962194 1 Function_00962895 2 Function_0096A392 3 Function_00E608E2 4 Function_00D805DF 5 Function_00E603E1 6 Function_0096AA9E 7 Function_00962A9F 8 Function_0096A09A 9 Function_00962098 10 Function_0096A486 11 Function_0096A986 12 Function_0096AD80 13 Function_00D805CF 14 Function_00962681 15 Function_00E609F8 16 Function_009622B4 17 Function_009623BC 18 Function_0096A8A4 19 Function_009627A5 20 Function_00E606D1 21 Function_0096ADAA 22 Function_0096ACD7 23 Function_00E602A5 23->4 23->20 95 Function_00D80606 23->95 24 Function_0096A2D2 25 Function_0096AED3 26 Function_009620D0 27 Function_009628D1 28 Function_0096A8C6 29 Function_0096A7C7 30 Function_00E608B7 31 Function_009628C5 32 Function_00E605BE 33 Function_0096A1F4 34 Function_009623F4 35 Function_00D804BC 36 Function_009621F0 37 Function_00E60080 38 Function_00E60980 39 Function_00D805BF 40 Function_0096A2FE 41 Function_009626FC 42 Function_00E60498 43 Function_0096A215 44 Function_0096AD12 45 Function_0096A612 46 Function_00E60A63 47 Function_0096A710 48 Function_00962511 49 Function_0096A81E 50 Function_00D80051 51 Function_0096AE1D 52 Function_0096AF06 53 Function_00962006 54 Function_00D80649 68 Function_00D8066A 54->68 55 Function_0096AC04 56 Function_0096A005 57 Function_00962805 58 Function_0096AC0E 59 Function_00D80740 60 Function_00962834 61 Function_0096AE30 62 Function_00962430 63 Function_00D8067F 64 Function_0096A23C 65 Function_0096213C 66 Function_00D80074 67 Function_00E60249 67->4 67->20 67->95 69 Function_00962624 70 Function_00D8026D 71 Function_0096A120 72 Function_0096A02E 73 Function_0096AC2E 74 Function_0096AB2C 75 Function_00E60258 75->4 75->20 75->95 76 Function_00962729 77 Function_0096AE52 78 Function_00E60B20 79 Function_0096A25E 80 Function_0096AB5E 81 Function_00D80710 82 Function_0096A45C 83 Function_0096AA5C 84 Function_00962458 85 Function_0096A646 86 Function_00D8000C 87 Function_0096A540 88 Function_00E60B30 89 Function_0096A74E 90 Function_00D80000 91 Function_0096A94F 92 Function_0096284C 93 Function_0096A14D 94 Function_00E6043D 96 Function_00E60006 97 Function_0096A172 98 Function_00E60B03 99 Function_0096257F 100 Function_0096A078 101 Function_00962979 102 Function_00962264 103 Function_00962364 104 Function_0096A462 105 Function_0096A361 106 Function_0096A56E

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 e60258-e60279 2 e602c0-e602f8 0->2 3 e6027b-e602a3 0->3 10 e602ff 2->10 11 e602fa 2->11 8 e602b6 3->8 8->2 85 e602ff call e606d1 10->85 86 e602ff call d805df 10->86 87 e602ff call d80606 10->87 11->10 12 e60305-e6030c 13 e60343-e60407 12->13 14 e6030e-e60338 12->14 33 e6044e-e6045f 13->33 34 e60409-e6043b 13->34 14->13 37 e60461-e60467 33->37 38 e6046a-e60475 33->38 34->33 37->38 42 e606b4-e606ca 38->42 43 e6047b-e60481 38->43 42->33 44 e60483-e60496 43->44 45 e604a9-e604ad 43->45 44->45 47 e604af-e604ca 45->47 48 e604e9-e604f0 45->48 47->48 59 e604cc-e604e1 47->59 48->33 51 e604f6-e60562 48->51 66 e60564-e605bc 51->66 67 e605cf-e6063b 51->67 59->48 66->67 67->33 79 e60641-e60699 67->79 79->33 85->12 86->12 87->12
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1837763934.0000000000E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_e60000_5556.jbxd
                Similarity
                • API ID:
                • String ID: -\k^$2k$2k$=\k^$M\k^
                • API String ID: 0-243541282
                • Opcode ID: fbc19c5aaac57c1a691716149acde80d707519b16ba8ec362bf555047df393d6
                • Instruction ID: 35ecaa7369ec03023d580d23520f092007a60856e5219b558968c780f5e9fe60
                • Opcode Fuzzy Hash: fbc19c5aaac57c1a691716149acde80d707519b16ba8ec362bf555047df393d6
                • Instruction Fuzzy Hash: 75B1BF38B003008FC714EB39E65566D77E3BB8935CB108429D8069B799EF3A9C86DB65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 88 e60249-e60279 90 e602c0-e602f8 88->90 91 e6027b-e602a3 88->91 98 e602ff 90->98 99 e602fa 90->99 96 e602b6 91->96 96->90 173 e602ff call e606d1 98->173 174 e602ff call d805df 98->174 175 e602ff call d80606 98->175 99->98 100 e60305-e6030c 101 e60343-e60407 100->101 102 e6030e-e60338 100->102 121 e6044e-e6045f 101->121 122 e60409-e6043b 101->122 102->101 125 e60461-e60467 121->125 126 e6046a-e60475 121->126 122->121 125->126 130 e606b4-e606ca 126->130 131 e6047b-e60481 126->131 130->121 132 e60483-e60496 131->132 133 e604a9-e604ad 131->133 132->133 135 e604af-e604ca 133->135 136 e604e9-e604f0 133->136 135->136 147 e604cc-e604e1 135->147 136->121 139 e604f6-e60562 136->139 154 e60564-e605bc 139->154 155 e605cf-e6063b 139->155 147->136 154->155 155->121 167 e60641-e60699 155->167 167->121 173->100 174->100 175->100
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1837763934.0000000000E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_e60000_5556.jbxd
                Similarity
                • API ID:
                • String ID: -\k^$2k$2k$=\k^$M\k^
                • API String ID: 0-243541282
                • Opcode ID: 026b95c0e8974a4aff20ee4d52ab6355621f6939581b5987eb5308d5f28a01a8
                • Instruction ID: 30263e60660536ce690064e8d607ae255a59b4f6e7b364f8cf7f328fb30cc325
                • Opcode Fuzzy Hash: 026b95c0e8974a4aff20ee4d52ab6355621f6939581b5987eb5308d5f28a01a8
                • Instruction Fuzzy Hash: A1B1B138B003008FC715EB38E65566D77E3BF8931CB108469D8069B799EF3A9C86DB65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 176 e602a5-e602f8 184 e602ff 176->184 185 e602fa 176->185 259 e602ff call e606d1 184->259 260 e602ff call d805df 184->260 261 e602ff call d80606 184->261 185->184 186 e60305-e6030c 187 e60343-e60407 186->187 188 e6030e-e60338 186->188 207 e6044e-e6045f 187->207 208 e60409-e6043b 187->208 188->187 211 e60461-e60467 207->211 212 e6046a-e60475 207->212 208->207 211->212 216 e606b4-e606ca 212->216 217 e6047b-e60481 212->217 216->207 218 e60483-e60496 217->218 219 e604a9-e604ad 217->219 218->219 221 e604af-e604ca 219->221 222 e604e9-e604f0 219->222 221->222 233 e604cc-e604e1 221->233 222->207 225 e604f6-e60562 222->225 240 e60564-e605bc 225->240 241 e605cf-e6063b 225->241 233->222 240->241 241->207 253 e60641-e60699 241->253 253->207 259->186 260->186 261->186
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1837763934.0000000000E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_e60000_5556.jbxd
                Similarity
                • API ID:
                • String ID: -\k^$2k$2k$=\k^$M\k^
                • API String ID: 0-243541282
                • Opcode ID: 6ed2202b457d9171ebe1c77d1a2af7b7b3043481f2bacc5104eb801dbee96fc5
                • Instruction ID: dc1c642641da65c667e8e85b170d21edb263b5dda3536a82c88b2070defa1eb5
                • Opcode Fuzzy Hash: 6ed2202b457d9171ebe1c77d1a2af7b7b3043481f2bacc5104eb801dbee96fc5
                • Instruction Fuzzy Hash: 97A1B138B003008FC715EB38E65566D77E3BB8931CB108429D8069B7A9EF369C86DB65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 262 96a94f-96a9de 266 96a9e3-96a9ef 262->266 267 96a9e0 262->267 268 96a9f4-96a9fd 266->268 269 96a9f1 266->269 267->266 270 96aa4e-96aa53 268->270 271 96a9ff-96aa23 CreateFileW 268->271 269->268 270->271 274 96aa55-96aa5a 271->274 275 96aa25-96aa4b 271->275 274->275
                APIs
                • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 0096AA05
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: CreateFile
                • String ID:
                • API String ID: 823142352-0
                • Opcode ID: f8ebe81fc59cf561ec23643deca8e11fb5424dec51edbc8e9a224cc4e8944892
                • Instruction ID: 65f99830edce42f6516399ae0bda8938402bff3f21b765ffbe5c71cba8af23b4
                • Opcode Fuzzy Hash: f8ebe81fc59cf561ec23643deca8e11fb5424dec51edbc8e9a224cc4e8944892
                • Instruction Fuzzy Hash: 9931B0B1504380AFE722CF25DD44B66BFF8EF06314F08849AE9849B262D375E909CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 278 96a612-96a695 282 96a697 278->282 283 96a69a-96a6a3 278->283 282->283 284 96a6a5 283->284 285 96a6a8-96a6b1 283->285 284->285 286 96a702-96a707 285->286 287 96a6b3-96a6d7 CreateMutexW 285->287 286->287 290 96a709-96a70e 287->290 291 96a6d9-96a6ff 287->291 290->291
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 0096A6B9
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: f46839f61e50c11dabe6ce51ed3117a9b62a442343646bae1dba1fe49d0bcfa5
                • Instruction ID: 025cbf85800b3ed62db15958b916148e177de14b312f98127af320ae71535c8b
                • Opcode Fuzzy Hash: f46839f61e50c11dabe6ce51ed3117a9b62a442343646bae1dba1fe49d0bcfa5
                • Instruction Fuzzy Hash: D13193B55093845FE712CB25DD85B96BFF8EF06310F08849AE984CB292D375E909CB72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 294 96a361-96a3cf 297 96a3d4-96a3dd 294->297 298 96a3d1 294->298 299 96a3e2-96a3e8 297->299 300 96a3df 297->300 298->297 301 96a3ed-96a404 299->301 302 96a3ea 299->302 300->299 304 96a406-96a419 RegQueryValueExW 301->304 305 96a43b-96a440 301->305 302->301 306 96a442-96a447 304->306 307 96a41b-96a438 304->307 305->304 306->307
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096A40C
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: a2ec6d8cb7dddfc2525be6edfc40b924b798c1c026e740560993d2b5c5260100
                • Instruction ID: afb6ffdf5ec27b698e5e9b6cc91aeb30f50c5836f03e36fd2749a6a307fe2100
                • Opcode Fuzzy Hash: a2ec6d8cb7dddfc2525be6edfc40b924b798c1c026e740560993d2b5c5260100
                • Instruction Fuzzy Hash: 77318E75504784AFE722CF15CC84F96BBFCEF06310F08849AE9459B2A2D364E909CB72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 311 96aa5c-96aae9 315 96ab1e-96ab23 311->315 316 96aaeb-96aafe GetFileType 311->316 315->316 317 96ab25-96ab2a 316->317 318 96ab00-96ab1d 316->318 317->318
                APIs
                • GetFileType.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096AAF1
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: FileType
                • String ID:
                • API String ID: 3081899298-0
                • Opcode ID: 4063774ee35b8e500f8c02ad4bd73303e46cea9df4560af9c30a735463e5ccbf
                • Instruction ID: 8ca5344057148a82b013ac7e19b188bbebcc4992574e1d454adddc3277c3b3fc
                • Opcode Fuzzy Hash: 4063774ee35b8e500f8c02ad4bd73303e46cea9df4560af9c30a735463e5ccbf
                • Instruction Fuzzy Hash: 1021F8B54053846FE7128F25DC81BA6BFBCEF07324F0985D6E9448B2A3D264AD09CB75

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 322 96a462-96a4c3 325 96a4c5 322->325 326 96a4c8-96a4d4 322->326 325->326 327 96a4d6 326->327 328 96a4d9-96a4f0 326->328 327->328 330 96a527-96a52c 328->330 331 96a4f2-96a505 RegSetValueExW 328->331 330->331 332 96a507-96a524 331->332 333 96a52e-96a533 331->333 333->332
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096A4F8
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: 4939d14f424a90892abcc93990d6a32c8df21d9c13e26ecf3203b77a916bfb27
                • Instruction ID: 559158b245d9284af202f457e59351c08fce62645f17e3bbcc5b13dd128a6ce1
                • Opcode Fuzzy Hash: 4939d14f424a90892abcc93990d6a32c8df21d9c13e26ecf3203b77a916bfb27
                • Instruction Fuzzy Hash: C02190765043846FD722CF15DC44FA7BFBCEF46220F08849AE985DB652D264E948CB72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 337 96a986-96a9de 340 96a9e3-96a9ef 337->340 341 96a9e0 337->341 342 96a9f4-96a9fd 340->342 343 96a9f1 340->343 341->340 344 96aa4e-96aa53 342->344 345 96a9ff-96aa07 CreateFileW 342->345 343->342 344->345 347 96aa0d-96aa23 345->347 348 96aa55-96aa5a 347->348 349 96aa25-96aa4b 347->349 348->349
                APIs
                • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 0096AA05
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: CreateFile
                • String ID:
                • API String ID: 823142352-0
                • Opcode ID: 309065b5537470faf15bdc7ca84be5f096bdabb743746b17becae930e43b0a9b
                • Instruction ID: 507cba3e2ec8dcfa063443daf6e4b74a19ecd802979a1f580fdda2e264cb34c7
                • Opcode Fuzzy Hash: 309065b5537470faf15bdc7ca84be5f096bdabb743746b17becae930e43b0a9b
                • Instruction Fuzzy Hash: 0B21A171500304AFE720CF65DD45B66FBE8EF04320F18886AE9459B652D375E808CB72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 352 96a646-96a695 355 96a697 352->355 356 96a69a-96a6a3 352->356 355->356 357 96a6a5 356->357 358 96a6a8-96a6b1 356->358 357->358 359 96a702-96a707 358->359 360 96a6b3-96a6bb CreateMutexW 358->360 359->360 362 96a6c1-96a6d7 360->362 363 96a709-96a70e 362->363 364 96a6d9-96a6ff 362->364 363->364
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 0096A6B9
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: c194703f15d6bb6fe4976b2d87bca02fecd52bb08b30a17095bddb8285038167
                • Instruction ID: f693f5023beb21b52b0368b9df3e2c93311c731eef6f18f91987f3e98e80cca1
                • Opcode Fuzzy Hash: c194703f15d6bb6fe4976b2d87bca02fecd52bb08b30a17095bddb8285038167
                • Instruction Fuzzy Hash: 1121F2756002409FE720CF25DD85BA6FBE8EF04320F08886AE9489B741D374E808CA72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 367 96ac0e-96ac85 371 96ac87-96aca7 WriteFile 367->371 372 96acc9-96acce 367->372 375 96acd0-96acd5 371->375 376 96aca9-96acc6 371->376 372->371 375->376
                APIs
                • WriteFile.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096AC8D
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: FileWrite
                • String ID:
                • API String ID: 3934441357-0
                • Opcode ID: 24cbeb26ef5cc057a9c2e98676c106d30fb461ec6619d7c87f6a0141b74c7191
                • Instruction ID: 49712540136bbf92cfc3c1da095b1aec06314a0e8fab2d1cb543cc5d775aef6e
                • Opcode Fuzzy Hash: 24cbeb26ef5cc057a9c2e98676c106d30fb461ec6619d7c87f6a0141b74c7191
                • Instruction Fuzzy Hash: 3C21D472404384AFD722CF55DC44F97BFB8EF45310F08889AE9859B552C239A908CB72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 379 96a392-96a3cf 381 96a3d4-96a3dd 379->381 382 96a3d1 379->382 383 96a3e2-96a3e8 381->383 384 96a3df 381->384 382->381 385 96a3ed-96a404 383->385 386 96a3ea 383->386 384->383 388 96a406-96a419 RegQueryValueExW 385->388 389 96a43b-96a440 385->389 386->385 390 96a442-96a447 388->390 391 96a41b-96a438 388->391 389->388 390->391
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096A40C
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: e0765ee9b4c7e60249c217bc78f3e66089a6cc64b114662fbd24363a458f77c9
                • Instruction ID: 3c1e8697c3abc88d6b3ade9314cf3670af7e8df047d630921fb192c1a8409bec
                • Opcode Fuzzy Hash: e0765ee9b4c7e60249c217bc78f3e66089a6cc64b114662fbd24363a458f77c9
                • Instruction Fuzzy Hash: 99218E766007049FE721CF15CD88FA6B7ECEF04720F0484AAE9459B751D774E909CA72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 395 96a486-96a4c3 397 96a4c5 395->397 398 96a4c8-96a4d4 395->398 397->398 399 96a4d6 398->399 400 96a4d9-96a4f0 398->400 399->400 402 96a527-96a52c 400->402 403 96a4f2-96a505 RegSetValueExW 400->403 402->403 404 96a507-96a524 403->404 405 96a52e-96a533 403->405 405->404
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096A4F8
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: 8d113d0d712dbdac37656d2574401a4772c5a7e00821d8bb0d70a25737058fc6
                • Instruction ID: 294304a178c84d436f27fa4281a7cbb329b0715da46815fe2fa23ab4102ba7fb
                • Opcode Fuzzy Hash: 8d113d0d712dbdac37656d2574401a4772c5a7e00821d8bb0d70a25737058fc6
                • Instruction Fuzzy Hash: F911BE76500304AFEB21CF15DD45FAABBECEF04724F04845AED4A9A651D774E808CAB2

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 409 96a2d2-96a2d4 410 96a2d6-96a2dd 409->410 411 96a2de-96a328 409->411 410->411 413 96a353-96a358 411->413 414 96a32a-96a33d SetErrorMode 411->414 413->414 415 96a33f-96a352 414->415 416 96a35a-96a35f 414->416 416->415
                APIs
                • SetErrorMode.KERNELBASE(?), ref: 0096A330
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: ErrorMode
                • String ID:
                • API String ID: 2340568224-0
                • Opcode ID: d4653c5bcfabed5c7bf9e2f8214c8f08e8cc6c564e89504c431f3f330139c0f2
                • Instruction ID: 9d1641c31ec804683b55d186a7b7888eb7aa3a58de04d5c577d1b5f9850bfd2a
                • Opcode Fuzzy Hash: d4653c5bcfabed5c7bf9e2f8214c8f08e8cc6c564e89504c431f3f330139c0f2
                • Instruction Fuzzy Hash: 5421297540E3C09FD7138B25DC54A62BFB49F07224F0980DBED848F2A3D269A808DB72
                APIs
                • ShellExecuteExW.SHELL32(?), ref: 0096AE8C
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: ExecuteShell
                • String ID:
                • API String ID: 587946157-0
                • Opcode ID: 0175f9a3b1fde20405c70170e00a8a50486f96fad9211b5b87cd5dafde407cb7
                • Instruction ID: 9ad012db5bde407a01d510e6761ca0ba5aaa5aa7c3e11f8ecd554d3c0961960a
                • Opcode Fuzzy Hash: 0175f9a3b1fde20405c70170e00a8a50486f96fad9211b5b87cd5dafde407cb7
                • Instruction Fuzzy Hash: 351163755093805FD712CF25DC94B52BFB8DF46220F0884EAED49CB252D275E908CB62

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 419 96ac2e-96ac85 422 96ac87-96ac8f WriteFile 419->422 423 96acc9-96acce 419->423 425 96ac95-96aca7 422->425 423->422 426 96acd0-96acd5 425->426 427 96aca9-96acc6 425->427 426->427
                APIs
                • WriteFile.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096AC8D
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: FileWrite
                • String ID:
                • API String ID: 3934441357-0
                • Opcode ID: 0626039db956d56bd9ccdc1bb957b9e8bfcf2ae88d70e33c10ae7a2f2343bcaf
                • Instruction ID: e08011f8fa995f33443a249557d8cf64fb606095d87d2dc2d25010de28b565f7
                • Opcode Fuzzy Hash: 0626039db956d56bd9ccdc1bb957b9e8bfcf2ae88d70e33c10ae7a2f2343bcaf
                • Instruction Fuzzy Hash: C011C472500304AFEB21CF55DD44FAAFBE8EF44324F14886AE9459B651D379A508CBB2
                APIs
                • GetFileType.KERNELBASE(?,00000E24,9BDEDD94,00000000,00000000,00000000,00000000), ref: 0096AAF1
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: FileType
                • String ID:
                • API String ID: 3081899298-0
                • Opcode ID: 62199b4463df9340d003e488d7d5e537ed8a3a85a8ecb56a473a0cda068279a5
                • Instruction ID: 23698e52dcfd5d4dc0e1eac144e2b12332b8b250367232f83b35bcf67dd4be44
                • Opcode Fuzzy Hash: 62199b4463df9340d003e488d7d5e537ed8a3a85a8ecb56a473a0cda068279a5
                • Instruction Fuzzy Hash: 4401C475500304AEE7218F15DD89BAAB79CDF44724F14C496ED049B741D378A908CAB6
                APIs
                • ShellExecuteExW.SHELL32(?), ref: 0096AE8C
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: ExecuteShell
                • String ID:
                • API String ID: 587946157-0
                • Opcode ID: d529a5f68e65856ea2b0755cb4066180b7af8666b7fd3ac506b0583ec8d4608a
                • Instruction ID: d988721150d7683cba75005ce9f78f175ef14620904180fbafaa718b8d30b007
                • Opcode Fuzzy Hash: d529a5f68e65856ea2b0755cb4066180b7af8666b7fd3ac506b0583ec8d4608a
                • Instruction Fuzzy Hash: 4C0192756002408FEB11CF15D988766FBE8EF44320F08C4AADD09DB642D779E808CF62
                APIs
                • SetErrorMode.KERNELBASE(?), ref: 0096A330
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: ErrorMode
                • String ID:
                • API String ID: 2340568224-0
                • Opcode ID: 6e7ac7ff39478ba69be2590d2677a0e05ca6f0456ccf5971c8288b206aba8de3
                • Instruction ID: 52dab4c05de93cfd79e836bac8d43ebd8e6eeecdc664e208ce23da75b13f2abe
                • Opcode Fuzzy Hash: 6e7ac7ff39478ba69be2590d2677a0e05ca6f0456ccf5971c8288b206aba8de3
                • Instruction Fuzzy Hash: 55F0AF35904240CFDB108F09D988B61FBE4EF44324F08C09ADD495B752D3B9E808DEA2
                APIs
                • CloseHandle.KERNELBASE(?), ref: 0096A780
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 9cf015b0bfaa3006adadc8498f0936a7a0c46266752627878d95418df8f388cd
                • Instruction ID: 9fdf8793784e16054b957a3968824ef0a7da0c70562890e93dc3bb83fc2ade78
                • Opcode Fuzzy Hash: 9cf015b0bfaa3006adadc8498f0936a7a0c46266752627878d95418df8f388cd
                • Instruction Fuzzy Hash: AE21D5B55043809FD7128F15DC85752BFB8EF12320F0984DBED458B293D2359909CB62
                APIs
                • CloseHandle.KERNELBASE(?), ref: 0096A780
                Memory Dump Source
                • Source File: 00000000.00000002.1837232265.000000000096A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0096A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_96a000_5556.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 41cffb3cf1b7f13d61117f19c4269bfeaecfc238e6c31412ff0a2506346dbf7c
                • Instruction ID: 2c4323a65a27c2759f78d9b056d5cc796cbe9a31575a3e4dd8d1d406e3e58e10
                • Opcode Fuzzy Hash: 41cffb3cf1b7f13d61117f19c4269bfeaecfc238e6c31412ff0a2506346dbf7c
                • Instruction Fuzzy Hash: 000184759002408FEB108F15D989765FBE4EF44320F08C4ABDD499B756D279E808CEA2
                Memory Dump Source
                • Source File: 00000000.00000002.1837763934.0000000000E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_e60000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 831ad862c4636e3679bba671c02beb54c99e3783498e4b478c3f1104846749b4
                • Instruction ID: e48007d185cfec3c01d4bfa71eeee926a9b627da41750426fb83c4f1a9d2b395
                • Opcode Fuzzy Hash: 831ad862c4636e3679bba671c02beb54c99e3783498e4b478c3f1104846749b4
                • Instruction Fuzzy Hash: A9A17138B043008FC719EB78D655B6D3BE3BB8930CB204069D5069B7A9EF399C42DB55
                Memory Dump Source
                • Source File: 00000000.00000002.1837763934.0000000000E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_e60000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 4476cdff7273235e2ab214c1047d96bd83c88752089ea1d89549b3ec6d559788
                • Instruction ID: ecdd22d6d2c19d5dcef57f725b6f782d885ebc4eb674ed17becf77f71ef7039c
                • Opcode Fuzzy Hash: 4476cdff7273235e2ab214c1047d96bd83c88752089ea1d89549b3ec6d559788
                • Instruction Fuzzy Hash: FF414478A05242CFC704FB38E759889B7E2BF8420C741C929E0444BB6DDB346D8ADB96
                Memory Dump Source
                • Source File: 00000000.00000002.1837677648.0000000000D80000.00000040.00000020.00020000.00000000.sdmp, Offset: 00D80000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_d80000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b67e1bf7851ec46e8a5d2ac121638ad85baf99bc7ef3415f3131185af47f53bf
                • Instruction ID: 8f27fcc3a7132c9048076a39d35d02ce319f641c4b3a08f7a066b50ace936d91
                • Opcode Fuzzy Hash: b67e1bf7851ec46e8a5d2ac121638ad85baf99bc7ef3415f3131185af47f53bf
                • Instruction Fuzzy Hash: C001DB765093805FD7128F05AC44862FFF8EF4663070984AFEC4D8B653D2697909CB71
                Memory Dump Source
                • Source File: 00000000.00000002.1837763934.0000000000E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_e60000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: ca4d6470de1392b72ad5e4ad37cda093810ff4fccf7d16c6f10f7f1cbb4ec317
                • Instruction ID: 4d75257768eb13cdcdd2879df909ac730f559b906de695251d329006d4b243f5
                • Opcode Fuzzy Hash: ca4d6470de1392b72ad5e4ad37cda093810ff4fccf7d16c6f10f7f1cbb4ec317
                • Instruction Fuzzy Hash: 2D013F5595E3D15FE34387711C64294BFB16E43614B4E82C7C494CB5B3E34C491E9BA3
                Memory Dump Source
                • Source File: 00000000.00000002.1837677648.0000000000D80000.00000040.00000020.00020000.00000000.sdmp, Offset: 00D80000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_d80000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9581d6d1d867ed20c39986b66172473329c46f64ec558ea0889d181aca1f094d
                • Instruction ID: e6a0cfc9fdc2adec4a3e1471cc9f3d711403eeb50a973bf5287905a7d8f17989
                • Opcode Fuzzy Hash: 9581d6d1d867ed20c39986b66172473329c46f64ec558ea0889d181aca1f094d
                • Instruction Fuzzy Hash: F2E092B66007444B9650CF0AEC85452F7D8EB88630708C07FDC0D8B701E67AB508CAB5
                Memory Dump Source
                • Source File: 00000000.00000002.1837217080.0000000000962000.00000040.00000800.00020000.00000000.sdmp, Offset: 00962000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_962000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 0b99e7bc57e7322deb38c6a1c9fed2d099dec6d2d34ba364d3c866d0d43d09d9
                • Instruction ID: 482617ccd98a679209baab1e73a6176177d1ab6848adf48ba915e6071b20faa7
                • Opcode Fuzzy Hash: 0b99e7bc57e7322deb38c6a1c9fed2d099dec6d2d34ba364d3c866d0d43d09d9
                • Instruction Fuzzy Hash: 80D05E79209AD14FD3269F1CC6A8BA537D8BF51714F4A44F9A800CBB73CB68D985D601
                Memory Dump Source
                • Source File: 00000000.00000002.1837217080.0000000000962000.00000040.00000800.00020000.00000000.sdmp, Offset: 00962000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_962000_5556.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 5ffb0e7d8bda8434d89af9fc414babb4c161a26b3c83d11b6f423bc9057021ae
                • Instruction ID: 5ff34d3b28964f64564e4929091eac9e29fc21a3d8af69829aded6f7298a292e
                • Opcode Fuzzy Hash: 5ffb0e7d8bda8434d89af9fc414babb4c161a26b3c83d11b6f423bc9057021ae
                • Instruction Fuzzy Hash: 3ED05E343406814BC725DF0CC6D4F5937D8AF40B15F0648E9AC108B762C7A8D9C0DA00

                Execution Graph

                Execution Coverage:17.2%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:6.8%
                Total number of Nodes:147
                Total number of Limit Nodes:7
                execution_graph 6082 1b5b876 6083 1b5b8a5 AdjustTokenPrivileges 6082->6083 6085 1b5b8c7 6083->6085 6029 5df0cd8 KiUserExceptionDispatcher 6030 5df0d0c 6029->6030 6086 5df1296 6087 5df0f7a 6086->6087 6092 5df12c8 6087->6092 6097 5df1350 6087->6097 6102 5df1332 6087->6102 6107 5df1363 6087->6107 6093 5df1303 6092->6093 6094 5df142c 6093->6094 6112 5df16e0 6093->6112 6116 5df16d1 6093->6116 6094->6094 6098 5df1357 6097->6098 6099 5df142c 6098->6099 6100 5df16d1 2 API calls 6098->6100 6101 5df16e0 2 API calls 6098->6101 6100->6099 6101->6099 6103 5df1339 6102->6103 6104 5df16d1 2 API calls 6103->6104 6105 5df16e0 2 API calls 6103->6105 6106 5df142c 6103->6106 6104->6106 6105->6106 6108 5df136a 6107->6108 6109 5df142c 6108->6109 6110 5df16d1 2 API calls 6108->6110 6111 5df16e0 2 API calls 6108->6111 6109->6109 6110->6109 6111->6109 6113 5df170b 6112->6113 6114 5df174c 6113->6114 6120 5df1c80 6113->6120 6114->6094 6117 5df16e0 6116->6117 6118 5df174c 6117->6118 6119 5df1c80 2 API calls 6117->6119 6118->6094 6119->6118 6121 5df1cb5 6120->6121 6125 5e61806 6121->6125 6128 5e61796 6121->6128 6122 5df1cf0 6122->6114 6126 5e61856 GetVolumeInformationA 6125->6126 6127 5e6185e 6126->6127 6127->6122 6129 5e61806 GetVolumeInformationA 6128->6129 6131 5e6185e 6129->6131 6131->6122 6132 1b5a2fe 6133 1b5a32a SetErrorMode 6132->6133 6135 1b5a353 6132->6135 6134 1b5a33f 6133->6134 6135->6133 6031 5e6136a 6032 5e6139f shutdown 6031->6032 6034 5e613c8 6032->6034 6035 5e60aea 6036 5e60b22 WSASocketW 6035->6036 6038 5e60b5e 6036->6038 6039 1b5acba 6040 1b5ace6 OleInitialize 6039->6040 6041 1b5ad1c 6039->6041 6042 1b5acf4 6040->6042 6041->6040 6140 5e62db6 6142 5e62deb GetProcessWorkingSetSize 6140->6142 6143 5e62e17 6142->6143 6144 5e62a32 6145 5e62a5b select 6144->6145 6147 5e62a90 6145->6147 6043 1b5ae22 6046 1b5ae4b CopyFileW 6043->6046 6045 1b5ae72 6046->6045 6047 5e619fa 6048 5e61a52 6047->6048 6049 5e61a29 CoGetObjectContext 6047->6049 6048->6049 6050 5e61a3e 6049->6050 6148 5e6153a 6150 5e6156f GetProcessTimes 6148->6150 6151 5e615a1 6150->6151 6051 1b5bdaa 6052 1b5be20 6051->6052 6053 1b5bde8 DuplicateHandle 6051->6053 6052->6053 6054 1b5bdf6 6053->6054 6152 1b5aeea 6154 1b5af22 CreateFileW 6152->6154 6155 1b5af71 6154->6155 6156 1b5baea 6158 1b5bb1f GetExitCodeProcess 6156->6158 6159 1b5bb48 6158->6159 6055 5e610c6 6056 5e610fe MapViewOfFile 6055->6056 6058 5e6114d 6056->6058 6160 5e62786 6161 5e627be RegCreateKeyExW 6160->6161 6163 5e62830 6161->6163 6164 5e60882 6165 5e608b7 ReadFile 6164->6165 6167 5e608e9 6165->6167 6059 1b5a392 6061 1b5a3c7 RegQueryValueExW 6059->6061 6062 1b5a41b 6061->6062 6168 5e6170a 6169 5e6173f WSAConnect 6168->6169 6171 5e6175e 6169->6171 6066 1b5a09a 6067 1b5a107 6066->6067 6068 1b5a0cf send 6066->6068 6067->6068 6069 1b5a0dd 6068->6069 6172 1b5b65a 6174 1b5b683 LookupPrivilegeValueW 6172->6174 6175 1b5b6aa 6174->6175 6070 5e62956 6072 5e6298b ioctlsocket 6070->6072 6073 5e629b7 6072->6073 6176 5e60f16 6178 5e60f4e ConvertStringSecurityDescriptorToSecurityDescriptorW 6176->6178 6179 5e60f8f 6178->6179 6074 1b5a486 6075 1b5a4bb RegSetValueExW 6074->6075 6077 1b5a507 6075->6077 6180 1b5a8c6 6181 1b5a8fe RegOpenKeyExW 6180->6181 6183 1b5a954 6181->6183 6188 1b5a646 6189 1b5a67e CreateMutexW 6188->6189 6191 1b5a6c1 6189->6191 6192 5e61a92 6194 5e61acd LoadLibraryA 6192->6194 6195 5e61b0a 6194->6195 6078 1b5b002 6081 1b5b037 GetFileType 6078->6081 6080 1b5b064 6081->6080 6196 5df02a5 6197 5df02ac 6196->6197 6198 5df043b 6197->6198 6200 5df0ee1 6197->6200 6201 5df0f14 6200->6201 6204 5df0f31 6201->6204 6205 1b5bba4 6201->6205 6209 1b5bbc6 6201->6209 6204->6198 6208 1b5bbc6 NtSetInformationProcess 6205->6208 6207 1b5bc10 6207->6204 6208->6207 6210 1b5bc26 6209->6210 6211 1b5bbfb NtSetInformationProcess 6209->6211 6210->6211 6212 1b5bc10 6211->6212 6212->6204 6213 1b5a74e 6214 1b5a7b9 6213->6214 6215 1b5a77a CloseHandle 6213->6215 6214->6215 6216 1b5a788 6215->6216 6217 1b5a9ce 6219 1b5aa09 SendMessageTimeoutA 6217->6219 6220 1b5aa51 6219->6220 6221 5e62e9a 6222 5e62ecf SetProcessWorkingSetSize 6221->6222 6224 5e62efb 6222->6224
                APIs
                • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 01B5B8BF
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: AdjustPrivilegesToken
                • String ID:
                • API String ID: 2874748243-0
                • Opcode ID: 1d0564dbf9716cd11aa3c12ca7fa1a11e8ee05636cbfcb318c5c575cfa400a99
                • Instruction ID: ee66d3ce8db65719320d508649a32fe5fe4e8bdab86e7385f60b76d0a8185bd6
                • Opcode Fuzzy Hash: 1d0564dbf9716cd11aa3c12ca7fa1a11e8ee05636cbfcb318c5c575cfa400a99
                • Instruction Fuzzy Hash: B721D1765093849FEB238F25DD44B52BFF4EF06310F0884DAE9858B163D375A908CB62
                APIs
                • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 01B5B8BF
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: AdjustPrivilegesToken
                • String ID:
                • API String ID: 2874748243-0
                • Opcode ID: 859f2559d8d31bc7ce2374b670d87f7d5843c82b0d7fbd4675f3aa26a2efddca
                • Instruction ID: c558b7e7265016581000f423d64e53ffd7d4f6ec1d69d87d0b86748993169dd1
                • Opcode Fuzzy Hash: 859f2559d8d31bc7ce2374b670d87f7d5843c82b0d7fbd4675f3aa26a2efddca
                • Instruction Fuzzy Hash: 9811A0366002049FEB21CF19DA44B62FBE5EF04220F08C4AAED458B652D335E418CB61
                APIs
                • NtSetInformationProcess.NTDLL ref: 01B5BC01
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: InformationProcess
                • String ID:
                • API String ID: 1801817001-0
                • Opcode ID: 838a144d84b5c66d64b6bddc066acbb84c95779649d2f7ec3e1c043b216f3f57
                • Instruction ID: 5fffa270468feee5eb337b9e6a1a90bcb00bca33984fadadc68f6c7b24f9cbea
                • Opcode Fuzzy Hash: 838a144d84b5c66d64b6bddc066acbb84c95779649d2f7ec3e1c043b216f3f57
                • Instruction Fuzzy Hash: 4011AC71408380AFDB228F15DD45A62FFB4EF06220F09C49AEE844B663D275A918CB62
                APIs
                • NtSetInformationProcess.NTDLL ref: 01B5BC01
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: InformationProcess
                • String ID:
                • API String ID: 1801817001-0
                • Opcode ID: d68be085d3661109e503dad230e3f95ee21fada529e94de7f6d13ab97118763b
                • Instruction ID: b9b996b5ac7dbe0f07e7a08b80a72b4a97912bdea845e583e7204bd966ed9060
                • Opcode Fuzzy Hash: d68be085d3661109e503dad230e3f95ee21fada529e94de7f6d13ab97118763b
                • Instruction Fuzzy Hash: EB018F754002449FDB618F09DA88B61FBE5EF44320F08C49ADD854B652D775E458CBA2

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 292 5df0cd8-5df0d16 KiUserExceptionDispatcher 295 5df0d19-5df0d1f 292->295 296 5df0e1d-5df0e3a 295->296 297 5df0d25-5df0d28 295->297 298 5df0d2a 297->298 326 5df0d2c call 360104a 298->326 327 5df0d2c call 360106e 298->327 300 5df0d31-5df0d5e 305 5df0da5-5df0da8 300->305 306 5df0d60-5df0d62 300->306 305->296 308 5df0daa-5df0db0 305->308 328 5df0d64 call 360104a 306->328 329 5df0d64 call 360106e 306->329 330 5df0d64 call 5df2070 306->330 308->298 309 5df0db6-5df0dbd 308->309 311 5df0dbf-5df0dd5 309->311 312 5df0e0e 309->312 310 5df0d6a-5df0d71 313 5df0d73-5df0d9a 310->313 314 5df0da2 310->314 311->296 318 5df0dd7-5df0ddf 311->318 315 5df0e18 312->315 313->314 314->305 315->295 319 5df0de1-5df0dec 318->319 320 5df0e00-5df0e08 call 5df2397 318->320 319->296 322 5df0dee-5df0df8 319->322 320->312 322->320 326->300 327->300 328->310 329->310 330->310
                APIs
                • KiUserExceptionDispatcher.NTDLL ref: 05DF0CFF
                Memory Dump Source
                • Source File: 00000001.00000002.4231124043.0000000005DF0000.00000040.00000800.00020000.00000000.sdmp, Offset: 05DF0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5df0000_lsass.jbxd
                Similarity
                • API ID: DispatcherExceptionUser
                • String ID:
                • API String ID: 6842923-0
                • Opcode ID: 028f74079791b933c23473a0dd81a6121764119380651e075116c48287024072
                • Instruction ID: a811e982b37b61e3be87dc09f322a6ad3248b927e30816431a84500ad411942e
                • Opcode Fuzzy Hash: 028f74079791b933c23473a0dd81a6121764119380651e075116c48287024072
                • Instruction Fuzzy Hash: 30415135A002048FCB08DF79D9885ADB7F2EF88214F15847AD909DB35ADB39DD45CBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 332 5df0cc9-5df0cd4 333 5df0d19-5df0d1f 332->333 334 5df0cd6 332->334 336 5df0e1d-5df0e3a 333->336 337 5df0d25-5df0d28 333->337 335 5df0cd8-5df0d05 KiUserExceptionDispatcher 334->335 340 5df0d0c-5df0d16 335->340 338 5df0d2a 337->338 368 5df0d2c call 360104a 338->368 369 5df0d2c call 360106e 338->369 340->333 341 5df0d31-5df0d5e 347 5df0da5-5df0da8 341->347 348 5df0d60-5df0d62 341->348 347->336 350 5df0daa-5df0db0 347->350 370 5df0d64 call 360104a 348->370 371 5df0d64 call 360106e 348->371 372 5df0d64 call 5df2070 348->372 350->338 351 5df0db6-5df0dbd 350->351 353 5df0dbf-5df0dd5 351->353 354 5df0e0e 351->354 352 5df0d6a-5df0d71 355 5df0d73-5df0d9a 352->355 356 5df0da2 352->356 353->336 360 5df0dd7-5df0ddf 353->360 357 5df0e18 354->357 355->356 356->347 357->333 361 5df0de1-5df0dec 360->361 362 5df0e00-5df0e08 call 5df2397 360->362 361->336 364 5df0dee-5df0df8 361->364 362->354 364->362 368->341 369->341 370->352 371->352 372->352
                APIs
                • KiUserExceptionDispatcher.NTDLL ref: 05DF0CFF
                Memory Dump Source
                • Source File: 00000001.00000002.4231124043.0000000005DF0000.00000040.00000800.00020000.00000000.sdmp, Offset: 05DF0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5df0000_lsass.jbxd
                Similarity
                • API ID: DispatcherExceptionUser
                • String ID:
                • API String ID: 6842923-0
                • Opcode ID: 912743489939bfab20f110128a849b1c88f03ce7847fb5def5491654f50d66c8
                • Instruction ID: 6c342daf426d26de312d07f3b8e35d25f5f7e52418c0913f8c262e8165c11673
                • Opcode Fuzzy Hash: 912743489939bfab20f110128a849b1c88f03ce7847fb5def5491654f50d66c8
                • Instruction Fuzzy Hash: D2416234A002058FCB54DF79C988699B7F2EF88204F15847AD90AEB35AEB35DD45CBA0

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 374 5e6275a-5e627de 378 5e627e3-5e627ef 374->378 379 5e627e0 374->379 380 5e627f4-5e627fd 378->380 381 5e627f1 378->381 379->378 382 5e62802-5e62819 380->382 383 5e627ff 380->383 381->380 385 5e6285b-5e62860 382->385 386 5e6281b-5e6282e RegCreateKeyExW 382->386 383->382 385->386 387 5e62862-5e62867 386->387 388 5e62830-5e62858 386->388 387->388
                APIs
                • RegCreateKeyExW.KERNELBASE(?,00000E24), ref: 05E62821
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: Create
                • String ID:
                • API String ID: 2289755597-0
                • Opcode ID: b95e05c7df2f9c7dedb6fbc962793939462d40542b7ba9f484c0f11301ad98c6
                • Instruction ID: 7174345b712eeded6716d81bf794f227b7e8bc1248695e04fa6d7e658e68415d
                • Opcode Fuzzy Hash: b95e05c7df2f9c7dedb6fbc962793939462d40542b7ba9f484c0f11301ad98c6
                • Instruction Fuzzy Hash: 09318F76504344AFE721CB65CD84FA7BBFCEF05214F08899AE9859B662D324E908CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 393 5e609d7-5e609f7 394 5e60a19-5e60a4b 393->394 395 5e609f9-5e60a18 393->395 399 5e60a4e-5e60aa6 RegQueryValueExW 394->399 395->394 401 5e60aac-5e60ac2 399->401
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,?,?), ref: 05E60A9E
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: ba5493d3d234edcc4d2de20c3fab8a34ea79ea11826a23579ca30147a4a851d1
                • Instruction ID: c44eaf29512370c5f2744cd24f7a9ba4714b96db3f50d7181f5a5fe6a87e856a
                • Opcode Fuzzy Hash: ba5493d3d234edcc4d2de20c3fab8a34ea79ea11826a23579ca30147a4a851d1
                • Instruction Fuzzy Hash: 4A318B7510E3C06FD3138B258C65A61BFB4EF47614F0E85CBD8C48B6A3D629A909C7B2

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 402 5e61796-5e61858 GetVolumeInformationA 405 5e6185e-5e61887 402->405
                APIs
                • GetVolumeInformationA.KERNELBASE(?,00000E24,?,?), ref: 05E61856
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: InformationVolume
                • String ID:
                • API String ID: 2039140958-0
                • Opcode ID: b2182c02f6a80378fe83b0f9d1c1a76710275bb25ec65f65fbd760f26e256aeb
                • Instruction ID: 45f44de85ccb4b6580c25e2baf42c066f75dda5d3c8e32a14ca5d66413097e2e
                • Opcode Fuzzy Hash: b2182c02f6a80378fe83b0f9d1c1a76710275bb25ec65f65fbd760f26e256aeb
                • Instruction Fuzzy Hash: 01318E7150D3C16FD3138B358C61AA2BFB8AF47210F1984DBD8C4DF5A3D225A959C7A2

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 407 1b5a612-1b5a695 411 1b5a697 407->411 412 1b5a69a-1b5a6a3 407->412 411->412 413 1b5a6a5 412->413 414 1b5a6a8-1b5a6b1 412->414 413->414 415 1b5a6b3-1b5a6d7 CreateMutexW 414->415 416 1b5a702-1b5a707 414->416 419 1b5a709-1b5a70e 415->419 420 1b5a6d9-1b5a6ff 415->420 416->415 419->420
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 01B5A6B9
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: df03b18e79ad3df57f4a0ef03ade2c3fbee6ab5d68ec2378164bb8196e1bee5c
                • Instruction ID: 9ef45a0d6ac3abbbcd0af649fc3f0ab2c935ce2856da9d4f25f94a1832bd9629
                • Opcode Fuzzy Hash: df03b18e79ad3df57f4a0ef03ade2c3fbee6ab5d68ec2378164bb8196e1bee5c
                • Instruction Fuzzy Hash: 5931B3755093805FE712CB25DD85B96BFF8EF06210F08849AE984DB293D374E909CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 423 5e60ef0-5e60f71 427 5e60f76-5e60f7f 423->427 428 5e60f73 423->428 429 5e60fd7-5e60fdc 427->429 430 5e60f81-5e60f89 ConvertStringSecurityDescriptorToSecurityDescriptorW 427->430 428->427 429->430 432 5e60f8f-5e60fa1 430->432 433 5e60fa3-5e60fd4 432->433 434 5e60fde-5e60fe3 432->434 434->433
                APIs
                • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000E24), ref: 05E60F87
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: DescriptorSecurity$ConvertString
                • String ID:
                • API String ID: 3907675253-0
                • Opcode ID: 488b5c079fcccd0ef8786c4b440ff008b4ac95f84bb302a6093fc7a76b8efd4c
                • Instruction ID: 5e90ace598cbe7a34e3deec18e1e11f2473343fd6fda53526668a615ab61dc23
                • Opcode Fuzzy Hash: 488b5c079fcccd0ef8786c4b440ff008b4ac95f84bb302a6093fc7a76b8efd4c
                • Instruction Fuzzy Hash: 9431B172504385AFE721CB64DC45FA7BFE8EF05214F0888AAE984DB652D334A908CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 438 1b5a8a4-1b5a8f8 440 1b5a8fe-1b5a90f 438->440 441 1b5a915-1b5a921 440->441 442 1b5a926-1b5a93d 441->442 443 1b5a923 441->443 445 1b5a97f-1b5a984 442->445 446 1b5a93f-1b5a952 RegOpenKeyExW 442->446 443->442 445->446 447 1b5a954-1b5a97c 446->447 448 1b5a986-1b5a98b 446->448 448->447
                APIs
                • RegOpenKeyExW.KERNELBASE(?,00000E24), ref: 01B5A945
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: Open
                • String ID:
                • API String ID: 71445658-0
                • Opcode ID: d63ee38fe314808234ed9d41823922dd55d2cc9a02fc0bcabe5afae45cb6d0f1
                • Instruction ID: 8af578176b0c8daa14a36f28248aa870bb1febb10bc3cdb1933d0bf4c8a97ec2
                • Opcode Fuzzy Hash: d63ee38fe314808234ed9d41823922dd55d2cc9a02fc0bcabe5afae45cb6d0f1
                • Instruction Fuzzy Hash: 7A21D272404344AFE7228B55CC44FA7BFFCEF05210F0489AAE9849B652D374E909CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 481 1b5baac-1b5bb38 485 1b5bb83-1b5bb88 481->485 486 1b5bb3a-1b5bb42 GetExitCodeProcess 481->486 485->486 488 1b5bb48-1b5bb5a 486->488 489 1b5bb5c-1b5bb82 488->489 490 1b5bb8a-1b5bb8f 488->490 490->489
                APIs
                • GetExitCodeProcess.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5BB40
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CodeExitProcess
                • String ID:
                • API String ID: 3861947596-0
                • Opcode ID: f412d59983c8687d97cdb8d683eff42326e59ab2ddc2d2d001edd897e6e0cc9e
                • Instruction ID: 0ef9872b6959d016ba93b13de5f7a1995057d41495f49396328c9ab2e3370914
                • Opcode Fuzzy Hash: f412d59983c8687d97cdb8d683eff42326e59ab2ddc2d2d001edd897e6e0cc9e
                • Instruction Fuzzy Hash: 5021F6B25093805FE7128B25DD45BA6BFB8EF06324F0884DBE844CF193D264AA09CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 453 1b5a98d-1b5aa41 457 1b5aa85-1b5aa8a 453->457 458 1b5aa43-1b5aa4b SendMessageTimeoutA 453->458 457->458 460 1b5aa51-1b5aa63 458->460 461 1b5aa65-1b5aa82 460->461 462 1b5aa8c-1b5aa91 460->462 462->461
                APIs
                • SendMessageTimeoutA.USER32(?,00000E24), ref: 01B5AA49
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: MessageSendTimeout
                • String ID:
                • API String ID: 1599653421-0
                • Opcode ID: 5679576fc36391d3f10ae776b2baf2e4b72924264d59a7df84e11c443c166f5f
                • Instruction ID: 352bffe2351c3d98cf368ade93007f6e14b5b279220357c86042a2d4d80ac906
                • Opcode Fuzzy Hash: 5679576fc36391d3f10ae776b2baf2e4b72924264d59a7df84e11c443c166f5f
                • Instruction Fuzzy Hash: C231D471005384AFEB22CF60CD45FA6FFB8EF06324F18889AE9849B553D275A509CB75

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 465 1b5aec5-1b5af42 469 1b5af44 465->469 470 1b5af47-1b5af53 465->470 469->470 471 1b5af55 470->471 472 1b5af58-1b5af61 470->472 471->472 473 1b5af63-1b5af87 CreateFileW 472->473 474 1b5afb2-1b5afb7 472->474 477 1b5afb9-1b5afbe 473->477 478 1b5af89-1b5afaf 473->478 474->473 477->478
                APIs
                • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 01B5AF69
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CreateFile
                • String ID:
                • API String ID: 823142352-0
                • Opcode ID: 1e79f4d94fdc6c365e6eb00f8c2a6341bb2301ae388744881c4cc42f6c672478
                • Instruction ID: 9c4d14df6fcd1a9e81dbd365612eb8046da41e430f1f649ffa770c36735e8096
                • Opcode Fuzzy Hash: 1e79f4d94fdc6c365e6eb00f8c2a6341bb2301ae388744881c4cc42f6c672478
                • Instruction Fuzzy Hash: BD319EB1504344AFE721CF25DD84F56FBF8EF05210F0888AAE9859B692D375E908CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 493 5e62786-5e627de 496 5e627e3-5e627ef 493->496 497 5e627e0 493->497 498 5e627f4-5e627fd 496->498 499 5e627f1 496->499 497->496 500 5e62802-5e62819 498->500 501 5e627ff 498->501 499->498 503 5e6285b-5e62860 500->503 504 5e6281b-5e6282e RegCreateKeyExW 500->504 501->500 503->504 505 5e62862-5e62867 504->505 506 5e62830-5e62858 504->506 505->506
                APIs
                • RegCreateKeyExW.KERNELBASE(?,00000E24), ref: 05E62821
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: Create
                • String ID:
                • API String ID: 2289755597-0
                • Opcode ID: d30c5f2ca0a42f87c9497545c711c8b77354a993ab113c552d81a4505e50bf7c
                • Instruction ID: 21306db0c0f7683d58cab7f58495618a2cfa6b5406d04876ea1fab784f1167ba
                • Opcode Fuzzy Hash: d30c5f2ca0a42f87c9497545c711c8b77354a993ab113c552d81a4505e50bf7c
                • Instruction Fuzzy Hash: DD219E76500204AFEB31DE55CD84FA7BBECEF08354F04886AEA85D7651D734E5088A71
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5A40C
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: 3ece93f763d9f5a1f4a7d8eb2281c58e313e1a52477d60a5401cdaf8325aaad8
                • Instruction ID: 7b2e1778ca7154dff9f757ca04811296ad6129f8027609856d2a452bd01862ee
                • Opcode Fuzzy Hash: 3ece93f763d9f5a1f4a7d8eb2281c58e313e1a52477d60a5401cdaf8325aaad8
                • Instruction Fuzzy Hash: A031AE75104384AFE722CF25CC84F92BFF8EF06210F08859AE9859B292D364E908CB71
                APIs
                • GetProcessTimes.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E61599
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ProcessTimes
                • String ID:
                • API String ID: 1995159646-0
                • Opcode ID: 883093c4538c710f793c47beec00e0f1c3a7151e72df07edacf29e26f3e0335a
                • Instruction ID: ac66daf5a50a4328369a1efcbd1488ae2253452a0545084cc7bf0d83aaffebb0
                • Opcode Fuzzy Hash: 883093c4538c710f793c47beec00e0f1c3a7151e72df07edacf29e26f3e0335a
                • Instruction Fuzzy Hash: E52137725043406FE722CF55DC45FA7FBB8EF06320F0488AAE9858B152D334A908CB75
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: select
                • String ID:
                • API String ID: 1274211008-0
                • Opcode ID: 5c115a2919007be84b4b2b797284d720a5651728e2a323429d0b7870afdbb8c0
                • Instruction ID: d673fbf4b2dacf90307b46591c2fa048d776e1f0fbdaf20360ad730eedba8179
                • Opcode Fuzzy Hash: 5c115a2919007be84b4b2b797284d720a5651728e2a323429d0b7870afdbb8c0
                • Instruction Fuzzy Hash: A2215E795093849FEB22CF25DC44B62BFF8EF06254F0984DAE984CB163D275E909CB61
                APIs
                • GetFileType.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5B055
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: FileType
                • String ID:
                • API String ID: 3081899298-0
                • Opcode ID: 5e8c44492a789b75112b4d67b243334dbaa4af217714f50d289230c909a280c4
                • Instruction ID: 5187f5096c0316290de5e0e8b5eb1a68ce6e209f565257076fd445c573d4f4a6
                • Opcode Fuzzy Hash: 5e8c44492a789b75112b4d67b243334dbaa4af217714f50d289230c909a280c4
                • Instruction Fuzzy Hash: 1C21F8B54053846FE7128B15DD41BA2BFBCEF06324F0985D6ED808B2A3D264AA09C775
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5A4F8
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: 9e5a91ade88ac583922b42ed43486049fdf6a6e2849ef56187bd562e86195827
                • Instruction ID: c6c252c6791590c3b56273574cefb49fbd339eb96e312e699d87bb9ef9d7c0ce
                • Opcode Fuzzy Hash: 9e5a91ade88ac583922b42ed43486049fdf6a6e2849ef56187bd562e86195827
                • Instruction Fuzzy Hash: 0921B0761043846FE7228F65DD44FA7BFBCEF06220F08859AE985DB652C364E908C771
                APIs
                • WSASocketW.WS2_32(?,?,?,?,?), ref: 05E60B56
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: Socket
                • String ID:
                • API String ID: 38366605-0
                • Opcode ID: 79e000778ca59dbcec09cf2cba5c4de542ab942e8652df2e2e56c72af50decdd
                • Instruction ID: a0f0bdc5aa2e6f454fede9223732b71f2902d290012622145cd34acbdc655e7b
                • Opcode Fuzzy Hash: 79e000778ca59dbcec09cf2cba5c4de542ab942e8652df2e2e56c72af50decdd
                • Instruction Fuzzy Hash: 6321BD71404380AFE721CF55DD45FA6FFB8EF05224F08889EE9858B652C275A508CB62
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: FileView
                • String ID:
                • API String ID: 3314676101-0
                • Opcode ID: f32591976fdcc01481a95ac70a54734a40b99723e11af2e1895a1db8cd32a974
                • Instruction ID: 47da3d4b61be57f85d565cd0fdfeb42bd03f060db61c7543eee7aa00a89570d1
                • Opcode Fuzzy Hash: f32591976fdcc01481a95ac70a54734a40b99723e11af2e1895a1db8cd32a974
                • Instruction Fuzzy Hash: 3521AD71404384AFE722CB55DD45FA6FFF8EF09224F04889EE9848B652D375B908CB62
                APIs
                • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 01B5AF69
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CreateFile
                • String ID:
                • API String ID: 823142352-0
                • Opcode ID: ece3fbb98d1e5d46e5f080764ff2c77a506fdb883a74c8aa8128182c68a1fce7
                • Instruction ID: 45c377bc2f6ebb089fc653268633054953315497c62c4a40dc69d5f575b18185
                • Opcode Fuzzy Hash: ece3fbb98d1e5d46e5f080764ff2c77a506fdb883a74c8aa8128182c68a1fce7
                • Instruction Fuzzy Hash: 4B219FB1500304AFE721DF29DD85B66FBE8EF08220F0489A9EE45DB691D375E408CA71
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E60E9C
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: fb94a0380c34238b76c5ec9fd8e611c95d26f27c4f7cd461e88b9c6a39060fb5
                • Instruction ID: cf63430d92dd48e4279bac7ce6da444e28b1b5bbc750850f5ede16c00687db5e
                • Opcode Fuzzy Hash: fb94a0380c34238b76c5ec9fd8e611c95d26f27c4f7cd461e88b9c6a39060fb5
                • Instruction Fuzzy Hash: 4621AE76509384AFE722CB15CD44F67BFF8EF45310F08889AE9859B692D364E908CB71
                APIs
                • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000E24), ref: 05E60F87
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: DescriptorSecurity$ConvertString
                • String ID:
                • API String ID: 3907675253-0
                • Opcode ID: 156f97600f000e6c09ed5f70ddece20bae36358ee92037e805599dfa18977fb6
                • Instruction ID: 3c8ad0ce46d62a1313d483f573872a793cf642c5d5847c6bc75464711f574143
                • Opcode Fuzzy Hash: 156f97600f000e6c09ed5f70ddece20bae36358ee92037e805599dfa18977fb6
                • Instruction Fuzzy Hash: A121C272500215AFE720DF69DD49FAABBECEF44224F04886AF944DB641D774E5088AB2
                APIs
                • RegOpenKeyExW.KERNELBASE(?,00000E24), ref: 01B5A945
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: Open
                • String ID:
                • API String ID: 71445658-0
                • Opcode ID: 77b2732af753c37511d4b198116e1fddf50a01e2d8d4420fc4a854435e30e52a
                • Instruction ID: 8931fe4d89e9bee910ac3e56cc5b786a165c69f4f6240d7d68df366b702b5de1
                • Opcode Fuzzy Hash: 77b2732af753c37511d4b198116e1fddf50a01e2d8d4420fc4a854435e30e52a
                • Instruction Fuzzy Hash: 8721F276400204AFE7319F29CD44FAAFBECEF04220F04855AEE449B651D734E4088A71
                APIs
                • GetProcessWorkingSetSize.KERNEL32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E62E0F
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ProcessSizeWorking
                • String ID:
                • API String ID: 3584180929-0
                • Opcode ID: 1ae30760aaff97f1e182431d17c21f67ee571bc07bc1833e8c3aefc19f3ddc1a
                • Instruction ID: dcd7bc2be06540e3e0379ec925ed6c7a3445e40540bdba5a96547266ad3d39de
                • Opcode Fuzzy Hash: 1ae30760aaff97f1e182431d17c21f67ee571bc07bc1833e8c3aefc19f3ddc1a
                • Instruction Fuzzy Hash: 6C21D4755043846FE722CF25DC44FAABFB8EF45224F08C4ABE985DB152D274A908CB71
                APIs
                • SetProcessWorkingSetSize.KERNEL32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E62EF3
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ProcessSizeWorking
                • String ID:
                • API String ID: 3584180929-0
                • Opcode ID: 1ae30760aaff97f1e182431d17c21f67ee571bc07bc1833e8c3aefc19f3ddc1a
                • Instruction ID: 9a004570521cd945b91216584740d47a5618e19e4dc0ecbd51aa2459227739ce
                • Opcode Fuzzy Hash: 1ae30760aaff97f1e182431d17c21f67ee571bc07bc1833e8c3aefc19f3ddc1a
                • Instruction Fuzzy Hash: 7121D4755053846FE722CF15DC44FAABFB8EF45224F08C4AAF984DB192D274A908CBB5
                APIs
                • LookupPrivilegeValueW.ADVAPI32(?,?,?), ref: 01B5B6A2
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: LookupPrivilegeValue
                • String ID:
                • API String ID: 3899507212-0
                • Opcode ID: f3d0c3557411962dfdb77f149ee11ca4c6f6cfb6263657a151303efcec7c5c48
                • Instruction ID: 312c0300d56bf850a967d625438ae4514f77983a0826c1b0d4f41a4142209ebd
                • Opcode Fuzzy Hash: f3d0c3557411962dfdb77f149ee11ca4c6f6cfb6263657a151303efcec7c5c48
                • Instruction Fuzzy Hash: C72160B25053805FE752CB25DD45B52BFE8EF06214F0984DAE984CB163D274D908CB61
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 01B5A6B9
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: 3c40c41faf67d79a466e33fc21c0c38aad7dca311c215f5388bc2e10a6193028
                • Instruction ID: d28adf76df9557b77b86d20b64cd501b6461f1dc16adcd57d54a8ef6f486e776
                • Opcode Fuzzy Hash: 3c40c41faf67d79a466e33fc21c0c38aad7dca311c215f5388bc2e10a6193028
                • Instruction Fuzzy Hash: 7C21D0756002049FF720CF29DD85BA6FBE8EF04220F0488A9ED459B741D774E808CA71
                APIs
                • shutdown.WS2_32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E613C0
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: shutdown
                • String ID:
                • API String ID: 2510479042-0
                • Opcode ID: 22c6ff1914c3f29c024afbc692409378a33ee1cd3ff2dfe07d9101fd72271922
                • Instruction ID: 7c5affb7bb96cfde81d0dab705d0f6bcaf2983b0acc275012ebc45e84f5f0cbd
                • Opcode Fuzzy Hash: 22c6ff1914c3f29c024afbc692409378a33ee1cd3ff2dfe07d9101fd72271922
                • Instruction Fuzzy Hash: 5E2195714093846FE722CB55DC44B56BFB8EF46224F0884DAE9849B152C378A948C771
                APIs
                • ReadFile.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E608E1
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: FileRead
                • String ID:
                • API String ID: 2738559852-0
                • Opcode ID: aa1f17b0cac272a21e796cb64ed9f1c12459cd7bba0eb0d805456366bd3ab35d
                • Instruction ID: bf3bb5b7e70b6f3102895c95a8f63719320fe164166b3690cbd8318a8f43265b
                • Opcode Fuzzy Hash: aa1f17b0cac272a21e796cb64ed9f1c12459cd7bba0eb0d805456366bd3ab35d
                • Instruction Fuzzy Hash: 4221A471505384AFE722CF55DD44FA7BFF8EF45314F08889AE9849B552C274A508CB71
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5A40C
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: 0df229a2f4113953450bc2dca15e1f50a409d141320d317603980e17d930e15a
                • Instruction ID: 2b4a7953d8d5ddeb404da650f0a4acbfff4e9c22b5dbbf63706a785b5591337b
                • Opcode Fuzzy Hash: 0df229a2f4113953450bc2dca15e1f50a409d141320d317603980e17d930e15a
                • Instruction Fuzzy Hash: E621AE752002049FE721CF69CD88FA6BBECEF04624F04C5AAED459B652D774E908CA71
                APIs
                • ioctlsocket.WS2_32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E629AF
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ioctlsocket
                • String ID:
                • API String ID: 3577187118-0
                • Opcode ID: 36ff55f8dd8896286441784a2b2c71f931b920b40f1b315da9eb3b38c483938e
                • Instruction ID: 48a3d843a26526621a94b4ddf8623ecce0c6e004b31f9db07370150d875aeb54
                • Opcode Fuzzy Hash: 36ff55f8dd8896286441784a2b2c71f931b920b40f1b315da9eb3b38c483938e
                • Instruction Fuzzy Hash: C021F3714093846FE722CF15CC44FA6BFB8EF45314F08C8AAE9849B152C274A908C771
                APIs
                • WSAConnect.WS2_32(?,?,?,?,?,?,?), ref: 05E61756
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: Connect
                • String ID:
                • API String ID: 3144859779-0
                • Opcode ID: d1e98c63a71c36af4263d220f86614eb5dac20ac5a7f67877260f48027e78899
                • Instruction ID: 405ab938a957f4030b1f5664538d9ec639b93ff032ca85d022fa3b41472e9241
                • Opcode Fuzzy Hash: d1e98c63a71c36af4263d220f86614eb5dac20ac5a7f67877260f48027e78899
                • Instruction Fuzzy Hash: 0F21C5750093809FDB22CF60DC44A62BFF4FF06320F0984DAE9858F162D375A909DB61
                APIs
                • WSASocketW.WS2_32(?,?,?,?,?), ref: 05E60B56
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: Socket
                • String ID:
                • API String ID: 38366605-0
                • Opcode ID: 3f96686d7b8b4b2bfdf6ae0bcb79eedcfd5fa21dc0db13564dea22a69ba6d6d7
                • Instruction ID: 63960130e9e8ff384c695dc20fcb324b84bc8df762e3b8a33956e3e03188eb8a
                • Opcode Fuzzy Hash: 3f96686d7b8b4b2bfdf6ae0bcb79eedcfd5fa21dc0db13564dea22a69ba6d6d7
                • Instruction Fuzzy Hash: 6D219F71500204AFEB21DF55DD49FA6FBE9EF08328F04C86EE9858B651D375A508CB72
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: FileView
                • String ID:
                • API String ID: 3314676101-0
                • Opcode ID: aade2faccd79704318cf6cf1624f7ca5876db698f86eb7ede5de081db07108d4
                • Instruction ID: 414540edbfb1ff3a15966f27deace975768e6fe32b47fd08360f4eb1ec800ff3
                • Opcode Fuzzy Hash: aade2faccd79704318cf6cf1624f7ca5876db698f86eb7ede5de081db07108d4
                • Instruction Fuzzy Hash: 7321A171500344AFEB22CF55DD45FAAFBE9EF08224F048459E9858B751D375F508CBA2
                APIs
                • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 01B5BDEE
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: DuplicateHandle
                • String ID:
                • API String ID: 3793708945-0
                • Opcode ID: 4eb97b740ea06f1534f77f8d645322aee4ea6bcae214659faf5cbc18f8940169
                • Instruction ID: 8b12b746933136969deabaccf2d94c1385964f3b5af9b43942ed28a3cb021dd6
                • Opcode Fuzzy Hash: 4eb97b740ea06f1534f77f8d645322aee4ea6bcae214659faf5cbc18f8940169
                • Instruction Fuzzy Hash: 3D21A471409380AFDB228F54DD44B62FFF4EF4A310F0988DAED858B163C275A918DB61
                APIs
                • SendMessageTimeoutA.USER32(?,00000E24), ref: 01B5AA49
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: MessageSendTimeout
                • String ID:
                • API String ID: 1599653421-0
                • Opcode ID: 874a6b3b6a79106827924ac862096d34597bf6634bfc5da6b8ad9bde1bcbe7c9
                • Instruction ID: f8a31a68b30e777e811ce6bb49ce424ef54b9bafe9536ad4a8892e4756f461bc
                • Opcode Fuzzy Hash: 874a6b3b6a79106827924ac862096d34597bf6634bfc5da6b8ad9bde1bcbe7c9
                • Instruction Fuzzy Hash: 13210231100200AFEB319F24CE44FA6FBA8EF04320F04899AFE459B651C375B508CBB1
                APIs
                • LoadLibraryA.KERNELBASE(?,00000E24), ref: 05E61AFB
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: LibraryLoad
                • String ID:
                • API String ID: 1029625771-0
                • Opcode ID: 1ca4cf2a0fbcbf978d652c79651a097f29063babd4676b062f3536845851b3db
                • Instruction ID: c6200395007f42d3bf05a43dc6b431ffb39d150d048658199777bce957f6c18b
                • Opcode Fuzzy Hash: 1ca4cf2a0fbcbf978d652c79651a097f29063babd4676b062f3536845851b3db
                • Instruction Fuzzy Hash: 15110671004344AFE721CB15DD85FA6FFB8DF45320F04849AF9449B292D274B948CB72
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5A4F8
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: caf51cc37495950d8453048e86eeee3a39dab720b2a3c6eb6e919f891f4c6109
                • Instruction ID: 6e9885c761e35c84a53d5cf5133c9c9f61206a77e854892b174542a64e600066
                • Opcode Fuzzy Hash: caf51cc37495950d8453048e86eeee3a39dab720b2a3c6eb6e919f891f4c6109
                • Instruction Fuzzy Hash: D911E176100304AFE7218F25DD44FA6BBECEF04224F04859AED459B741D374E808CAB1
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E60E9C
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: 97f2cf0077c49a0c78fb7e136b71a0110e5bbdd16805ea994b67c104097444d6
                • Instruction ID: 8c941b145661826b8f8434efb9f44f89cdb5dba263baef415c62eb1ad1139ad8
                • Opcode Fuzzy Hash: 97f2cf0077c49a0c78fb7e136b71a0110e5bbdd16805ea994b67c104097444d6
                • Instruction Fuzzy Hash: 8311AF76500214AFEB31CF15DD48FA6BBE8EF04664F04C45AE9858B651D774E908CAB1
                APIs
                • CopyFileW.KERNELBASE(?,?,?), ref: 01B5AE6A
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CopyFile
                • String ID:
                • API String ID: 1304948518-0
                • Opcode ID: 9e95065aa649e2d19d43be39558e797b5d0fd3ea5c0301ee8d0cb6cb0aa14996
                • Instruction ID: 45dfb622124701b61d4fac803e4376b14d32aa5ca0dbe7e528e1d1bb5c679d28
                • Opcode Fuzzy Hash: 9e95065aa649e2d19d43be39558e797b5d0fd3ea5c0301ee8d0cb6cb0aa14996
                • Instruction Fuzzy Hash: FB117F716053809FE761CF29DC85B96BFE8EF45220F0884AAED85DB652D274E908CB61
                APIs
                • GetProcessTimes.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E61599
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ProcessTimes
                • String ID:
                • API String ID: 1995159646-0
                • Opcode ID: e03b52e50ac5126f081d2ab8d927af576a1647aa031f39bdc859ac400fff1242
                • Instruction ID: 54ff6a2b3110f817bf390615d2e5365fa532ec7bab36e4229db2bf19269f0084
                • Opcode Fuzzy Hash: e03b52e50ac5126f081d2ab8d927af576a1647aa031f39bdc859ac400fff1242
                • Instruction Fuzzy Hash: CC119076500204AFEB21CF55DD45FAAFBE8EF44324F04C86AE9868B651D774E908CBB1
                APIs
                • GetProcessWorkingSetSize.KERNEL32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E62E0F
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ProcessSizeWorking
                • String ID:
                • API String ID: 3584180929-0
                • Opcode ID: 6ff26eb218f94b36524f220871938d9c7a70700645bf0dcbf25f0565e9498ca9
                • Instruction ID: 751a97681e120b162192e90d0e0b2684ed03d2d245a3f6f75b4d46bacac2a846
                • Opcode Fuzzy Hash: 6ff26eb218f94b36524f220871938d9c7a70700645bf0dcbf25f0565e9498ca9
                • Instruction Fuzzy Hash: 2B1104755002049FEB21CF15DD44BAAB7E8EF44724F08C46AEE45CB641D774E908CAB1
                APIs
                • SetProcessWorkingSetSize.KERNEL32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E62EF3
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ProcessSizeWorking
                • String ID:
                • API String ID: 3584180929-0
                • Opcode ID: 6ff26eb218f94b36524f220871938d9c7a70700645bf0dcbf25f0565e9498ca9
                • Instruction ID: c02752a71bd15dfea3884350cde77d6700d8ded10cc6aaf33c5a741c66bb2281
                • Opcode Fuzzy Hash: 6ff26eb218f94b36524f220871938d9c7a70700645bf0dcbf25f0565e9498ca9
                • Instruction Fuzzy Hash: 2411EF76500204AFEB21CF15DD44BAAB7A8EF44324F04C86AEE44DB641D774A9088AB5
                APIs
                • GetExitCodeProcess.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5BB40
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CodeExitProcess
                • String ID:
                • API String ID: 3861947596-0
                • Opcode ID: d6dd69a42b3a1d0599e73dc688595414b72a0cc4d9b867fc9cd4bb597cb4944c
                • Instruction ID: 488f3fc7afe30a21303e4a9e2bb9b183cc3aecd8658187be6eeb71449e06b4d4
                • Opcode Fuzzy Hash: d6dd69a42b3a1d0599e73dc688595414b72a0cc4d9b867fc9cd4bb597cb4944c
                • Instruction Fuzzy Hash: D611E372500204AFEB61CF19DE45BAAB7DCEF44224F14C4AAFD44CB645D7B8A9088AB1
                APIs
                • ReadFile.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E608E1
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: FileRead
                • String ID:
                • API String ID: 2738559852-0
                • Opcode ID: f140a0f9751c8f11405e8ab4efd016937a386d97eee09c0f2827d0f4cf47089c
                • Instruction ID: 5726a4ead07cbbd4677c7847e955d42b4f0ddee70712a32cfa1bd730cb2baf44
                • Opcode Fuzzy Hash: f140a0f9751c8f11405e8ab4efd016937a386d97eee09c0f2827d0f4cf47089c
                • Instruction Fuzzy Hash: 8711C472500304AFEB21CF55DD48FAAFBE9EF44324F04C8AAE9859B651D374A508CBB1
                APIs
                • ioctlsocket.WS2_32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E629AF
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ioctlsocket
                • String ID:
                • API String ID: 3577187118-0
                • Opcode ID: 0ae1e447a18f1e23c15059e17048e5e38ba88cbbcf3bb345b9510b6b71c682af
                • Instruction ID: ec026a47fa4bb2ea85bf677041027108d4e9c6ef848116bc40b1c28f4e6ade66
                • Opcode Fuzzy Hash: 0ae1e447a18f1e23c15059e17048e5e38ba88cbbcf3bb345b9510b6b71c682af
                • Instruction Fuzzy Hash: 6611C176500304AFE721CF55DD44BAAB7A8EF44324F14C86AEA848B641D674A508CBB5
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: Initialize
                • String ID:
                • API String ID: 2538663250-0
                • Opcode ID: 5619f206d3e4440258a107c9dcd6032822e3aec1cd22a4bfe6ef5c2723cc443b
                • Instruction ID: 0ce39c3ef965d6978b0624b2dfb8bf6e7fa535288d403f79cbd5101559555ce5
                • Opcode Fuzzy Hash: 5619f206d3e4440258a107c9dcd6032822e3aec1cd22a4bfe6ef5c2723cc443b
                • Instruction Fuzzy Hash: E41160715093C06FDB128B25DC44B92BFB4DF46220F0884DAED848F193C275A508CB62
                APIs
                • shutdown.WS2_32(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 05E613C0
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: shutdown
                • String ID:
                • API String ID: 2510479042-0
                • Opcode ID: 708a39a3fbe44cb9e1fbea6e3f93dff028a149fee6c7f96399ca41a3f1c83a02
                • Instruction ID: 0e99fe0747b14e3857e62c092337c2c6c76e92711f85dcea78dabe77c29dee86
                • Opcode Fuzzy Hash: 708a39a3fbe44cb9e1fbea6e3f93dff028a149fee6c7f96399ca41a3f1c83a02
                • Instruction Fuzzy Hash: D9112575940204AFEB21CF15DD84FAAF7ECEF44324F04C4AAED458B641D378A908CAB1
                APIs
                • SetErrorMode.KERNELBASE(?), ref: 01B5A330
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: ErrorMode
                • String ID:
                • API String ID: 2340568224-0
                • Opcode ID: 3724ca01a715a140756f9e51829a5f94a447ea84b5fdc5ec2fc6a2ed939680d2
                • Instruction ID: 87220ae5a06ded9ad2581a43e8d7720365f8e096a0c09fede2eb0e0155e147d3
                • Opcode Fuzzy Hash: 3724ca01a715a140756f9e51829a5f94a447ea84b5fdc5ec2fc6a2ed939680d2
                • Instruction Fuzzy Hash: 70118F714093C06FDB238B25DC54B62BFB8DF47224F0980CBED848B263C265A908D772
                APIs
                • CoGetObjectContext.COMBASE(?,?), ref: 05E61A2F
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ContextObject
                • String ID:
                • API String ID: 3343934925-0
                • Opcode ID: 1be0fbaa842267230de96d777d4a120c343f201ed7f61abb63fb2081d8b907fa
                • Instruction ID: f6de21bcfc01a52a3b818bb8d8c5eaaa388ecede2d6d37efe437628193383771
                • Opcode Fuzzy Hash: 1be0fbaa842267230de96d777d4a120c343f201ed7f61abb63fb2081d8b907fa
                • Instruction Fuzzy Hash: 8D1193754083809FD7128F25DD85B61BFF4EF06320F0984DAD9854F2A3D278A909DB62
                APIs
                • LoadLibraryA.KERNELBASE(?,00000E24), ref: 05E61AFB
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: LibraryLoad
                • String ID:
                • API String ID: 1029625771-0
                • Opcode ID: b84d311aadb96892568bd759aa8cebaa01c96fb3581f4ffa003bbdbf492b7889
                • Instruction ID: cfb58016f8daba220513e64ea8e53e67deb41426139230cdde9664e69a8fc469
                • Opcode Fuzzy Hash: b84d311aadb96892568bd759aa8cebaa01c96fb3581f4ffa003bbdbf492b7889
                • Instruction Fuzzy Hash: B7110231500204AEF721DB15DD85FB6F7A9EF44724F14C49AEE444B681D2B4B908CAA2
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: select
                • String ID:
                • API String ID: 1274211008-0
                • Opcode ID: e6987588472f46e01643d0171387cf1258398fb09c0e3d3af0976dcc098054c4
                • Instruction ID: b8f753569d262b0849a8086d8a920adb8fc95c0495b24c06fd08297fdc385e33
                • Opcode Fuzzy Hash: e6987588472f46e01643d0171387cf1258398fb09c0e3d3af0976dcc098054c4
                • Instruction Fuzzy Hash: D11163796002009FE720CF55D984B66F7E8EF04254F08C49ADD89CB651D775E508CB61
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: send
                • String ID:
                • API String ID: 2809346765-0
                • Opcode ID: cb1323b840ca53179bbf37116358097b7333b9ec4800c00658be46fb9533c844
                • Instruction ID: f8387a1c7e7c4e1dcfdaa738140591d5003847afea0f0757fc3f24d15edbbe3d
                • Opcode Fuzzy Hash: cb1323b840ca53179bbf37116358097b7333b9ec4800c00658be46fb9533c844
                • Instruction Fuzzy Hash: 9A119175509380AFDB22CF15DD44B52FFB4EF46224F0884DAED849B553C275A918CB62
                APIs
                • CopyFileW.KERNELBASE(?,?,?), ref: 01B5AE6A
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CopyFile
                • String ID:
                • API String ID: 1304948518-0
                • Opcode ID: afa67fbcce30254fc52f7666c304eca63d4cb4338e7b7c88fb7350be96e42de0
                • Instruction ID: 37f3ceb8973c61ca06f658dd7cc026baace158dffc964da85cdaf269e26f90cb
                • Opcode Fuzzy Hash: afa67fbcce30254fc52f7666c304eca63d4cb4338e7b7c88fb7350be96e42de0
                • Instruction Fuzzy Hash: B7118E72A002008FEB64DF29D988B56FBE8EF44620F18C5AAED49DB742D774E404DA61
                APIs
                • LookupPrivilegeValueW.ADVAPI32(?,?,?), ref: 01B5B6A2
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: LookupPrivilegeValue
                • String ID:
                • API String ID: 3899507212-0
                • Opcode ID: afa67fbcce30254fc52f7666c304eca63d4cb4338e7b7c88fb7350be96e42de0
                • Instruction ID: 2d7304008d4f44a12fa1a748b9e7f7cab9252c12b026c91dc03d69d72007da4a
                • Opcode Fuzzy Hash: afa67fbcce30254fc52f7666c304eca63d4cb4338e7b7c88fb7350be96e42de0
                • Instruction Fuzzy Hash: A61165766002409FEB54DF29DA85756FBE8EF44220F08C4AAED45CB742D774E404CB72
                APIs
                • GetFileType.KERNELBASE(?,00000E24,C0B363B3,00000000,00000000,00000000,00000000), ref: 01B5B055
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: FileType
                • String ID:
                • API String ID: 3081899298-0
                • Opcode ID: 11d9707e0ef83e09787f5163958fc0a8340148243302605dfd5526f91cfef33d
                • Instruction ID: cc07aec71cf4a80279b59ef25947480f6fa513eacf211b2123503eff4f73b3f4
                • Opcode Fuzzy Hash: 11d9707e0ef83e09787f5163958fc0a8340148243302605dfd5526f91cfef33d
                • Instruction Fuzzy Hash: 63010475500304AEE760CF05DE45BAAB798DF44224F08C096ED048B741C378A9088AA1
                APIs
                • WSAConnect.WS2_32(?,?,?,?,?,?,?), ref: 05E61756
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: Connect
                • String ID:
                • API String ID: 3144859779-0
                • Opcode ID: 69c231597a7e7d66c9f6cc7041cc10faf624d2d0fb3f03cc483f22ef3059e55a
                • Instruction ID: ad5fd85931c32624c92c5a7738b761c3890f44b60d7008540d3f5a663d7041c1
                • Opcode Fuzzy Hash: 69c231597a7e7d66c9f6cc7041cc10faf624d2d0fb3f03cc483f22ef3059e55a
                • Instruction Fuzzy Hash: DA117C365002009FEB21CF55D944B62FBE9FF09364F08C8AAED858B622D375F418DB62
                APIs
                • GetVolumeInformationA.KERNELBASE(?,00000E24,?,?), ref: 05E61856
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: InformationVolume
                • String ID:
                • API String ID: 2039140958-0
                • Opcode ID: 80f3313ab538008473abcc5864d4e4d4d9d5b64d1af263c1b4ff50c3e8a088b5
                • Instruction ID: 96ccf6e79781743b5a26badf968c8f4386db14754f7db32bd8d3952606b93b9e
                • Opcode Fuzzy Hash: 80f3313ab538008473abcc5864d4e4d4d9d5b64d1af263c1b4ff50c3e8a088b5
                • Instruction Fuzzy Hash: 5101B171600200ABD310DF1ACD85B66FBE8EB88B20F14C52AEC089BB41D731F915CBE5
                APIs
                • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 01B5BDEE
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: DuplicateHandle
                • String ID:
                • API String ID: 3793708945-0
                • Opcode ID: 867485b8582e2ae50d2bf8e5d3bea6b65f9882389ff98856969c924692e355ac
                • Instruction ID: 5a2bb4e8c5e1901b64b6ce5a029349b1dd1321ca99f2d9be30e66a2e1bfcc19f
                • Opcode Fuzzy Hash: 867485b8582e2ae50d2bf8e5d3bea6b65f9882389ff98856969c924692e355ac
                • Instruction Fuzzy Hash: 900184325007049FDB61CF55DA44B62FBE5EF48320F08C99AEE454B652C375E414DF62
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,?,?), ref: 05E60A9E
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: 8eafd31a7a45261b7e8ac9c1e5239db05e3e72db7767481276c7640b80ab6945
                • Instruction ID: 14c91d85df25b675f5669124cdeff714faa8cfc600759bb5bc17b080175e59ba
                • Opcode Fuzzy Hash: 8eafd31a7a45261b7e8ac9c1e5239db05e3e72db7767481276c7640b80ab6945
                • Instruction Fuzzy Hash: 8F018F71500205ABD310DF1ACD86B66FBE8EB88A20F14C11AEC089BB41D771F955CAE6
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: send
                • String ID:
                • API String ID: 2809346765-0
                • Opcode ID: fe30970645f917be6f6c2f5c6c446fc90d9a73df914fa2b9d80e984283cc1e19
                • Instruction ID: d9cdcfef84179c0441312d3201dbb5cfae309cb0bb2a5f5baeb31a3bf46ff0de
                • Opcode Fuzzy Hash: fe30970645f917be6f6c2f5c6c446fc90d9a73df914fa2b9d80e984283cc1e19
                • Instruction Fuzzy Hash: F0019E355002409FEB61CF55D948B61FBE4FF48320F08C59AED499B652D375E408CBA2
                APIs
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: Initialize
                • String ID:
                • API String ID: 2538663250-0
                • Opcode ID: 5d7cbd1dff7a5e21a9c244c821eede342441f8812e9de73bf71e90fdff799809
                • Instruction ID: 22ba986074f58b931aed92ce8151487f10c5e85e4194c111ded911bee64af13d
                • Opcode Fuzzy Hash: 5d7cbd1dff7a5e21a9c244c821eede342441f8812e9de73bf71e90fdff799809
                • Instruction Fuzzy Hash: 3601FD719002448FEB10DF29D988761FBE4EF44220F08C5EADD489F342D378A408CAA2
                APIs
                • CoGetObjectContext.COMBASE(?,?), ref: 05E61A2F
                Memory Dump Source
                • Source File: 00000001.00000002.4231148596.0000000005E60000.00000040.00000800.00020000.00000000.sdmp, Offset: 05E60000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_5e60000_lsass.jbxd
                Similarity
                • API ID: ContextObject
                • String ID:
                • API String ID: 3343934925-0
                • Opcode ID: 4431a68a201d6c41b158e3e23ed2cd077bbd6bb2db1cac7d0283a74118fb1857
                • Instruction ID: 9c0b31a83645f461f127305218b3f5c2821265f1e2707bfaecbee814487fda7a
                • Opcode Fuzzy Hash: 4431a68a201d6c41b158e3e23ed2cd077bbd6bb2db1cac7d0283a74118fb1857
                • Instruction Fuzzy Hash: BCF08179904340DFEB11CF05DA88B61FBE5FF44764F08C09ADD894B752D279E408CAA2
                APIs
                • SetErrorMode.KERNELBASE(?), ref: 01B5A330
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: ErrorMode
                • String ID:
                • API String ID: 2340568224-0
                • Opcode ID: f8777e8bb0703a438c234ef2ed1ee0c92c36677f27a159c2d5c5f8969c63bd55
                • Instruction ID: 282a8cc4a60837253cd65546ad22720a6f7b7572c9d2beec5a963341918ebb30
                • Opcode Fuzzy Hash: f8777e8bb0703a438c234ef2ed1ee0c92c36677f27a159c2d5c5f8969c63bd55
                • Instruction Fuzzy Hash: 3CF08C359042408FEB508F19E988761FBE4EF44324F08C1DADD495B752D3B9A408CAA2
                APIs
                • CloseHandle.KERNELBASE(?), ref: 01B5B978
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 8f3297a963fcbbc5d6ef0f0e452d2b8ed939a9f36b1aae0b300dc8950e5c3b79
                • Instruction ID: d276a19b1da887b8ca278b1b924785a8a4c62fa29661673d5c81d844724a820b
                • Opcode Fuzzy Hash: 8f3297a963fcbbc5d6ef0f0e452d2b8ed939a9f36b1aae0b300dc8950e5c3b79
                • Instruction Fuzzy Hash: 6D21AE7250D3C05FEB128B25DD54792BFB4AF07324F0984DAED858F663D264A908CB62
                APIs
                • CloseHandle.KERNELBASE(?), ref: 01B5A780
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 14eaa2c3c058bf43da2125349ff20c78c7d2467c101d8515a08f6e6d75de41ea
                • Instruction ID: da6ba54354973531e3c53dea8479292c1647b9dc8c9e91bbc30dcd8fd68d2989
                • Opcode Fuzzy Hash: 14eaa2c3c058bf43da2125349ff20c78c7d2467c101d8515a08f6e6d75de41ea
                • Instruction Fuzzy Hash: 4811D3B55043809FD711CF69DD85B62BFB8EF02320F0984ABED859B293D335A909CB61
                APIs
                • CloseHandle.KERNELBASE(?), ref: 01B5B978
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: be5ea204054c87338468c3acef40a8421a0bdea561f4c2a58651b77e562d3c13
                • Instruction ID: 00d9c180eafa1348b6367bb27aee3cfcdb208d1abbadc34ccaabdc3b182df10c
                • Opcode Fuzzy Hash: be5ea204054c87338468c3acef40a8421a0bdea561f4c2a58651b77e562d3c13
                • Instruction Fuzzy Hash: AF01D4755042008FDB50CF19DA88756FBE4EF44220F08C0EADD498B742C774E408CFA2
                APIs
                • CloseHandle.KERNELBASE(?), ref: 01B5A780
                Memory Dump Source
                • Source File: 00000001.00000002.4228879768.0000000001B5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B5A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b5a000_lsass.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 7b0d79ea25d02d3a5fe485b0f163f91c9d035a1f2efbf022df39d2a15658e56e
                • Instruction ID: 7fe69777e0b3ec2400c9f2a3c89e5384281b4dd606de2a6555d30cfe00ae533b
                • Opcode Fuzzy Hash: 7b0d79ea25d02d3a5fe485b0f163f91c9d035a1f2efbf022df39d2a15658e56e
                • Instruction Fuzzy Hash: 1701D4755002008FEB50CF29E988765FBE4EF44220F08C5EBDD469B742D778E404CEA1
                Memory Dump Source
                • Source File: 00000001.00000002.4229464077.0000000003601000.00000040.00000020.00020000.00000000.sdmp, Offset: 03601000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_3601000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 2ee5ef7ef50e452063688d39d38411db745a6dd47f157d1563ed8e42a757c8fa
                • Instruction ID: d185d227d891c43125d3d8f2c432c77f9f5c17bb73e1f21ddbd675134a436c51
                • Opcode Fuzzy Hash: 2ee5ef7ef50e452063688d39d38411db745a6dd47f157d1563ed8e42a757c8fa
                • Instruction Fuzzy Hash: C431293514E3C58FC70B8B70C961652BFB1AF47314F1D85DBD4848B6A3D66A9C06CB62
                Memory Dump Source
                • Source File: 00000001.00000002.4229464077.0000000003601000.00000040.00000020.00020000.00000000.sdmp, Offset: 03601000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_3601000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 6133b7fa7dece0919e2db23bc1450ab2e8e44c77cf0257e68acc61302c79bbf5
                • Instruction ID: 1a9465ba5d15a224abc848e8cf70a114971f688e0a5c5bc0f90a92eb67ff3bad
                • Opcode Fuzzy Hash: 6133b7fa7dece0919e2db23bc1450ab2e8e44c77cf0257e68acc61302c79bbf5
                • Instruction Fuzzy Hash: 90110638244280DFC319CB20D645B27F7D5EB8A708F28C59CE5494BB92C77BD803CA51
                Memory Dump Source
                • Source File: 00000001.00000002.4231434915.00000000063E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 063E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_63e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 3735f607f6f9365cb73a3e1bb4139739b9f4ac14fcc1200da139d4f909a3857b
                • Instruction ID: 5d043a16790889c009e52c2b9e8735070de3bee461b62e3722315a483340fa63
                • Opcode Fuzzy Hash: 3735f607f6f9365cb73a3e1bb4139739b9f4ac14fcc1200da139d4f909a3857b
                • Instruction Fuzzy Hash: 6411DAB5908301AFD340CF19D981A5BFBE4FB88664F04895EF998D7311D335EA048FA2
                Memory Dump Source
                • Source File: 00000001.00000002.4231434915.00000000063E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 063E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_63e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 55e6079ece3da7ec71a0c10b3974f44e232737709f2268a2085a6790eb05c89e
                • Instruction ID: 34945ffe8f27e0d2d12076ecb62256f2794e66cfe86831a8626db5d59858bdcd
                • Opcode Fuzzy Hash: 55e6079ece3da7ec71a0c10b3974f44e232737709f2268a2085a6790eb05c89e
                • Instruction Fuzzy Hash: 1011FAB5908301AFD350CF09DD85E5BFBE8EB88660F04C81EF99897311D271E9088FA2
                Memory Dump Source
                • Source File: 00000001.00000002.4228986510.0000000001B6A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B6A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b6a000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 76224ca29b45930fa1a907f9bd67dbd6ddc7a9f6085c8006ea92624d48186462
                • Instruction ID: 3c444f373c7c804278253e8af84542d9bed7570db6ede7cbec66db81a923f098
                • Opcode Fuzzy Hash: 76224ca29b45930fa1a907f9bd67dbd6ddc7a9f6085c8006ea92624d48186462
                • Instruction Fuzzy Hash: 3D11FAB5A08301AFD350CF09DD45E5BFBE8EB88660F04C91EF99897311D271E9088FA2
                Memory Dump Source
                • Source File: 00000001.00000002.4229464077.0000000003601000.00000040.00000020.00020000.00000000.sdmp, Offset: 03601000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_3601000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d7170b843ac5e1aa7230222bc63d3e973c515276e3a2cbc03d93d67df0817b4c
                • Instruction ID: bb4c02a9a9a6e54eab69d839923ddd45bfda9f092fe27ca9e11ede1dc3591183
                • Opcode Fuzzy Hash: d7170b843ac5e1aa7230222bc63d3e973c515276e3a2cbc03d93d67df0817b4c
                • Instruction Fuzzy Hash: 5901F9B64493805FC7128F15EC40893BFF8EF4623070984ABEC88CB612D129B909CB72
                Memory Dump Source
                • Source File: 00000001.00000002.4229464077.0000000003601000.00000040.00000020.00020000.00000000.sdmp, Offset: 03601000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_3601000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e86483557dd7da402352a38d8c23262ea7f2be1902b6c4ab915b814faf957ce1
                • Instruction ID: f9bf10e58a5693ea50948240ea74cc12c8f10e0273163e399dfa3e9cb5f6bb88
                • Opcode Fuzzy Hash: e86483557dd7da402352a38d8c23262ea7f2be1902b6c4ab915b814faf957ce1
                • Instruction Fuzzy Hash: 6EF01D39144644DFC306CB50D541B16FBA6EB89718F24CAADE94907B62C737D813DA81
                Memory Dump Source
                • Source File: 00000001.00000002.4229464077.0000000003601000.00000040.00000020.00020000.00000000.sdmp, Offset: 03601000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_3601000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1ba88b7740394a2ecd167ae2ece73ce1e09f5abf8f4f0954ab3f49f14260f997
                • Instruction ID: 63f5c4419d43743f059666e4089b8c3f5af44fa5b7fb480b2cd30db2054ba70f
                • Opcode Fuzzy Hash: 1ba88b7740394a2ecd167ae2ece73ce1e09f5abf8f4f0954ab3f49f14260f997
                • Instruction Fuzzy Hash: 4BE092B66006044B9750CF0AFD45452F7D8EB88630B18C07FDC0D8B701D679B508CAA6
                Memory Dump Source
                • Source File: 00000001.00000002.4231434915.00000000063E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 063E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_63e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d39759c2e9773c684bd194029f047a6cc188a8b359fd0c6e1b12a082da4e2836
                • Instruction ID: e3c0f66f5e46287654314947c84a854935149a3ed7dc63d5e55be38db9568307
                • Opcode Fuzzy Hash: d39759c2e9773c684bd194029f047a6cc188a8b359fd0c6e1b12a082da4e2836
                • Instruction Fuzzy Hash: 71E0D8B250020067D210DE06AD4AF53FBDCDB40A30F04C45BED085B701D176B614C9E5
                Memory Dump Source
                • Source File: 00000001.00000002.4231434915.00000000063E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 063E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_63e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 871d4cdb7abf3c1eecf56c585c51debc54e90fdce3d2907d4f7adfa57abeed37
                • Instruction ID: 6ad8ec05cc1a8ed1a1aea8614a7bd87835b80f29c1e306b6ad90055437d25836
                • Opcode Fuzzy Hash: 871d4cdb7abf3c1eecf56c585c51debc54e90fdce3d2907d4f7adfa57abeed37
                • Instruction Fuzzy Hash: C5E0D8B250020467D2509E06AD46F53FBDCDB40A30F04C457ED085B702E176B60489F5
                Memory Dump Source
                • Source File: 00000001.00000002.4231434915.00000000063E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 063E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_63e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: c2e132df72c28311e6a8771a26584502446761ace72c7cb7fe46e82a6f04a7c5
                • Instruction ID: 4911a81eb6cdf3b53f7147181b62fa6b5c6f505b919773aec5363bbb849d7c84
                • Opcode Fuzzy Hash: c2e132df72c28311e6a8771a26584502446761ace72c7cb7fe46e82a6f04a7c5
                • Instruction Fuzzy Hash: C1E0D8B254020067D3108E06AD46F52FBDCDB44A30F04C467ED085B741D175B61489E5
                Memory Dump Source
                • Source File: 00000001.00000002.4228986510.0000000001B6A000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B6A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b6a000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b59c8268ccadaf11dc8be3513826c5857479739a8c3c163962c8ac7f103e05f6
                • Instruction ID: 8fe3cf553ca0d7deccc791c770010edfa95d385baf630c0c0a1c7b7f59313605
                • Opcode Fuzzy Hash: b59c8268ccadaf11dc8be3513826c5857479739a8c3c163962c8ac7f103e05f6
                • Instruction Fuzzy Hash: 08E0D8B254020467D3108E06AD46F52F7DCDB40A30F04C557ED085B741D175B50489F5
                Memory Dump Source
                • Source File: 00000001.00000002.4228851299.0000000001B52000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B52000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b52000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 339c714e02b0505b7186b4affa4576919295271a47d13226df0bd621ffbb9ba2
                • Instruction ID: b1b0141915c7e93efd54de802e19b4076caa18271684219c4459baf4741fed82
                • Opcode Fuzzy Hash: 339c714e02b0505b7186b4affa4576919295271a47d13226df0bd621ffbb9ba2
                • Instruction Fuzzy Hash: 19D05E792067D18FE32A9F1CC6A5B953FE4BB51714F4A44F9AD00CB763C768D581D600
                Memory Dump Source
                • Source File: 00000001.00000002.4228851299.0000000001B52000.00000040.00000800.00020000.00000000.sdmp, Offset: 01B52000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_1_2_1b52000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 3130fbb4dff0e364d9d7834003b9ec76ce994c908fa8aaad9821c723422b6793
                • Instruction ID: 0b9484d489387e2d710599d6c32f06f0265c29cbffcb93fbe03e45be1834dd85
                • Opcode Fuzzy Hash: 3130fbb4dff0e364d9d7834003b9ec76ce994c908fa8aaad9821c723422b6793
                • Instruction Fuzzy Hash: 4FD05E343412818FE729DF0CC6D4F593BD4AF44B15F0644F8AC108B762C7A8D9C0DA00

                Execution Graph

                Execution Coverage:8.1%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:12
                Total number of Limit Nodes:0
                execution_graph 890 13ea646 891 13ea67e CreateMutexW 890->891 893 13ea6c1 891->893 898 13ea612 900 13ea646 CreateMutexW 898->900 901 13ea6c1 900->901 902 13ea462 904 13ea486 RegSetValueExW 902->904 905 13ea507 904->905 906 13ea361 907 13ea392 RegQueryValueExW 906->907 909 13ea41b 907->909

                Callgraph

                • Executed
                • Not Executed
                • Opacity -> Relevance
                • Disassembly available
                callgraph 0 Function_013E213C 1 Function_013E23BC 2 Function_013EA23C 3 Function_02E011E3 4 Function_02E010E7 5 Function_056803E1 6 Function_013E2834 7 Function_013E2430 8 Function_02E0106E 9 Function_013EA02E 10 Function_013E2AAB 11 Function_02E01176 12 Function_013E2729 13 Function_013E2624 14 Function_013E27A5 15 Function_013EA120 16 Function_013E201C 17 Function_0568024B 18 Function_013EA09A 19 Function_013E2098 20 Function_02E01048 21 Function_013E2194 22 Function_013E2895 23 Function_013EA215 24 Function_013EA392 25 Function_013EA612 26 Function_013EA710 27 Function_013E2511 28 Function_05680258 29 Function_02E010D2 30 Function_013EA486 31 Function_013E2704 32 Function_013E2805 33 Function_013EA005 34 Function_013E2681 35 Function_013EA2FE 36 Function_013E257F 37 Function_02E01221 38 Function_013EA078 39 Function_013E2979 40 Function_02E011A8 41 Function_02E01028 42 Function_013E23F4 43 Function_013EA1F4 44 Function_013EA172 45 Function_056802A5 46 Function_013E21F0 47 Function_02E010AE 47->29 48 Function_013EA56E 49 Function_0568043D 50 Function_056805BE 51 Function_056806B0 52 Function_02E01038 53 Function_013E2264 54 Function_013E2364 55 Function_013EA462 56 Function_013EA361 57 Function_013EA25E 58 Function_02E01001 59 Function_013EA45C 60 Function_013E2458 61 Function_05680080 62 Function_013EA2D2 63 Function_013E20D0 64 Function_05680006 65 Function_013E28D1 66 Function_013EA74E 67 Function_05680498 68 Function_013E284C 69 Function_013EA14D 70 Function_0568001D 71 Function_013EA646 72 Function_013E28C5 73 Function_013EA540 74 Function_02E0119F

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 5680258-5680279 2 568027b-56802a3 0->2 3 56802c0-56802e7 0->3 8 56802b6 2->8 9 56802f2-56802f8 3->9 8->3 10 56802fa 9->10 11 56802ff-568030c 9->11 10->11 13 568030e-5680338 11->13 14 5680343-5680407 11->14 13->14 33 5680409-568043b 14->33 34 568044e-568045f 14->34 33->34 37 568046a-5680475 34->37 38 5680461-5680467 34->38 42 568047b-5680481 37->42 43 56806b4-56806ca 37->43 38->37 44 56804a9-56804ad 42->44 45 5680483-5680496 42->45 43->34 46 56804e9-56804f0 44->46 47 56804af-56804ca 44->47 45->44 46->34 50 56804f6-5680562 46->50 47->46 59 56804cc-56804e1 47->59 66 56805cf-568063b 50->66 67 5680564-56805bc 50->67 59->46 66->34 79 5680641-5680699 66->79 67->66 79->34
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2085487994.0000000005680000.00000040.00000800.00020000.00000000.sdmp, Offset: 05680000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_5680000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: -\=k^$2k$2k$=\=k^$M\=k^
                • API String ID: 0-390800236
                • Opcode ID: e2cd2b8b9b35d9faf5defb2df1440c3e926955e21c4ac06c9f0fde5ea4ffedfb
                • Instruction ID: 54c394feb9e0d58c27d5cac717dda5563c834a7b092d08ce51cbe8bd3f5bba29
                • Opcode Fuzzy Hash: e2cd2b8b9b35d9faf5defb2df1440c3e926955e21c4ac06c9f0fde5ea4ffedfb
                • Instruction Fuzzy Hash: 8BB1AF34700204CFEB19EB35D459A6D77A3FB8A318B10446EDA069B390DF79AC4BCB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 85 568024b-5680279 87 568027b-56802a3 85->87 88 56802c0-56802e7 85->88 93 56802b6 87->93 94 56802f2-56802f8 88->94 93->88 95 56802fa 94->95 96 56802ff-568030c 94->96 95->96 98 568030e-5680338 96->98 99 5680343-5680407 96->99 98->99 118 5680409-568043b 99->118 119 568044e-568045f 99->119 118->119 122 568046a-5680475 119->122 123 5680461-5680467 119->123 127 568047b-5680481 122->127 128 56806b4-56806ca 122->128 123->122 129 56804a9-56804ad 127->129 130 5680483-5680496 127->130 128->119 131 56804e9-56804f0 129->131 132 56804af-56804ca 129->132 130->129 131->119 135 56804f6-5680562 131->135 132->131 144 56804cc-56804e1 132->144 151 56805cf-568063b 135->151 152 5680564-56805bc 135->152 144->131 151->119 164 5680641-5680699 151->164 152->151 164->119
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2085487994.0000000005680000.00000040.00000800.00020000.00000000.sdmp, Offset: 05680000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_5680000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: -\=k^$2k$2k$=\=k^$M\=k^
                • API String ID: 0-390800236
                • Opcode ID: b86a587b65c02e203015f3dcee1c4f46e512e05ac4b967c7326d5ac9a91b082f
                • Instruction ID: f85e009f9394492158abe6fda365c040d3ed13e93eb4a145d5fd5423d0424f10
                • Opcode Fuzzy Hash: b86a587b65c02e203015f3dcee1c4f46e512e05ac4b967c7326d5ac9a91b082f
                • Instruction Fuzzy Hash: 40B19D34B00205CFE719EB35D459A6D77A3FB8A318B10446EDA069B390DF79AC4ACB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 170 56802a5-56802f8 178 56802fa 170->178 179 56802ff-568030c 170->179 178->179 181 568030e-5680338 179->181 182 5680343-5680407 179->182 181->182 201 5680409-568043b 182->201 202 568044e-568045f 182->202 201->202 205 568046a-5680475 202->205 206 5680461-5680467 202->206 210 568047b-5680481 205->210 211 56806b4-56806ca 205->211 206->205 212 56804a9-56804ad 210->212 213 5680483-5680496 210->213 211->202 214 56804e9-56804f0 212->214 215 56804af-56804ca 212->215 213->212 214->202 218 56804f6-5680562 214->218 215->214 227 56804cc-56804e1 215->227 234 56805cf-568063b 218->234 235 5680564-56805bc 218->235 227->214 234->202 247 5680641-5680699 234->247 235->234 247->202
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2085487994.0000000005680000.00000040.00000800.00020000.00000000.sdmp, Offset: 05680000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_5680000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: -\=k^$2k$2k$=\=k^$M\=k^
                • API String ID: 0-390800236
                • Opcode ID: 1923ad79d3f3012590ce897c9a96a2eab54264e60de5a4a81b3e164d55f16a95
                • Instruction ID: ecc84cd97bb4130bb98f905052695b664ecdd9508b135814740b636f7a989f26
                • Opcode Fuzzy Hash: 1923ad79d3f3012590ce897c9a96a2eab54264e60de5a4a81b3e164d55f16a95
                • Instruction Fuzzy Hash: 40A1AE34B00200CFEB19EB34D459A6D77A3EB8A318B10446EDA069B391DF799C4BCB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 253 13ea612-13ea695 257 13ea69a-13ea6a3 253->257 258 13ea697 253->258 259 13ea6a8-13ea6b1 257->259 260 13ea6a5 257->260 258->257 261 13ea702-13ea707 259->261 262 13ea6b3-13ea6d7 CreateMutexW 259->262 260->259 261->262 265 13ea709-13ea70e 262->265 266 13ea6d9-13ea6ff 262->266 265->266
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 013EA6B9
                Memory Dump Source
                • Source File: 00000007.00000002.2082253221.00000000013EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 013EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13ea000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: ad754b52907c419fa4484cbcdfafe2bee447784d58c95d442f6bb497171cf810
                • Instruction ID: 68255c7169ec090fdf700f827410f504be85e3a5d8101024a759e9694ccc24dc
                • Opcode Fuzzy Hash: ad754b52907c419fa4484cbcdfafe2bee447784d58c95d442f6bb497171cf810
                • Instruction Fuzzy Hash: 3D31B3755093805FE712CB25DC85B96BFF8EF06214F08849AE984CB293D374E909CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 269 13ea361-13ea3cf 272 13ea3d4-13ea3dd 269->272 273 13ea3d1 269->273 274 13ea3df 272->274 275 13ea3e2-13ea3e8 272->275 273->272 274->275 276 13ea3ed-13ea404 275->276 277 13ea3ea 275->277 279 13ea43b-13ea440 276->279 280 13ea406-13ea419 RegQueryValueExW 276->280 277->276 279->280 281 13ea41b-13ea438 280->281 282 13ea442-13ea447 280->282 282->281
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,AD2E5C02,00000000,00000000,00000000,00000000), ref: 013EA40C
                Memory Dump Source
                • Source File: 00000007.00000002.2082253221.00000000013EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 013EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13ea000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: bb1dbddddecf7216eccc487798b326591415bee1db3d2de1d73bb10034a28193
                • Instruction ID: 8e6e5a3d35680a5bb5bd2494f72d29ac9ce65f694c2384ad9a9f1e67e1768a5b
                • Opcode Fuzzy Hash: bb1dbddddecf7216eccc487798b326591415bee1db3d2de1d73bb10034a28193
                • Instruction Fuzzy Hash: C4319175504784AFE722CF15CC88FA6BFF8EF06214F08849AE945CB292D364E909CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 286 13ea462-13ea4c3 289 13ea4c8-13ea4d4 286->289 290 13ea4c5 286->290 291 13ea4d9-13ea4f0 289->291 292 13ea4d6 289->292 290->289 294 13ea527-13ea52c 291->294 295 13ea4f2-13ea505 RegSetValueExW 291->295 292->291 294->295 296 13ea52e-13ea533 295->296 297 13ea507-13ea524 295->297 296->297
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,AD2E5C02,00000000,00000000,00000000,00000000), ref: 013EA4F8
                Memory Dump Source
                • Source File: 00000007.00000002.2082253221.00000000013EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 013EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13ea000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: b6bd4fc46b69baacda17c52de5890fd540f0eb3533fc18da667552cc0e0913cb
                • Instruction ID: 3c3e09a9d42708784bcdd7ac732b206fe9634900d4893be644afe79ab4f20f7d
                • Opcode Fuzzy Hash: b6bd4fc46b69baacda17c52de5890fd540f0eb3533fc18da667552cc0e0913cb
                • Instruction Fuzzy Hash: 2721B076104384AFE7228F15CC44FA7BFF8EF46214F08849AE985DB692C364E908CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 301 13ea646-13ea695 304 13ea69a-13ea6a3 301->304 305 13ea697 301->305 306 13ea6a8-13ea6b1 304->306 307 13ea6a5 304->307 305->304 308 13ea702-13ea707 306->308 309 13ea6b3-13ea6bb CreateMutexW 306->309 307->306 308->309 311 13ea6c1-13ea6d7 309->311 312 13ea709-13ea70e 311->312 313 13ea6d9-13ea6ff 311->313 312->313
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 013EA6B9
                Memory Dump Source
                • Source File: 00000007.00000002.2082253221.00000000013EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 013EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13ea000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: 04be155f8596c258666f8525497ef4c1ffba469280eb5d65696f2fcc2c8ffdd5
                • Instruction ID: 138d3681ae5e267c4caf3345caa4ce658023dcf83c88229076a59b6e029e8682
                • Opcode Fuzzy Hash: 04be155f8596c258666f8525497ef4c1ffba469280eb5d65696f2fcc2c8ffdd5
                • Instruction Fuzzy Hash: DD21D4756003049FF720DF29DD89BA6FBE8EF44224F048869E945CB782D374E909CA71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 316 13ea392-13ea3cf 318 13ea3d4-13ea3dd 316->318 319 13ea3d1 316->319 320 13ea3df 318->320 321 13ea3e2-13ea3e8 318->321 319->318 320->321 322 13ea3ed-13ea404 321->322 323 13ea3ea 321->323 325 13ea43b-13ea440 322->325 326 13ea406-13ea419 RegQueryValueExW 322->326 323->322 325->326 327 13ea41b-13ea438 326->327 328 13ea442-13ea447 326->328 328->327
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,AD2E5C02,00000000,00000000,00000000,00000000), ref: 013EA40C
                Memory Dump Source
                • Source File: 00000007.00000002.2082253221.00000000013EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 013EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13ea000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: b6af9da2a171c238f334b2b79726dc6fd5582121d4a75c2632efb95dddc6dd69
                • Instruction ID: 23f8cde1b9b87dcb7942c84ea5bb6175f20bea4a61e0457ad2842c67d14cd051
                • Opcode Fuzzy Hash: b6af9da2a171c238f334b2b79726dc6fd5582121d4a75c2632efb95dddc6dd69
                • Instruction Fuzzy Hash: 09218E756003049FE721CF19CD88FA6BBECEF04624F04C46AE9459B791D774E909CA71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 332 13ea486-13ea4c3 334 13ea4c8-13ea4d4 332->334 335 13ea4c5 332->335 336 13ea4d9-13ea4f0 334->336 337 13ea4d6 334->337 335->334 339 13ea527-13ea52c 336->339 340 13ea4f2-13ea505 RegSetValueExW 336->340 337->336 339->340 341 13ea52e-13ea533 340->341 342 13ea507-13ea524 340->342 341->342
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,AD2E5C02,00000000,00000000,00000000,00000000), ref: 013EA4F8
                Memory Dump Source
                • Source File: 00000007.00000002.2082253221.00000000013EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 013EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13ea000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: 77534da5a4cfa8f9162d729171493f91e4b311813ca6ea29d9ed20ada0711c19
                • Instruction ID: fab689603d38554a2392586220035a0a5484dfa894b5783fa5ea7ba5eb4b185f
                • Opcode Fuzzy Hash: 77534da5a4cfa8f9162d729171493f91e4b311813ca6ea29d9ed20ada0711c19
                • Instruction Fuzzy Hash: E811BE76500304AFEB218F15DD49FA6BBECEF04624F04845AED459BB82D774E808CAB1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 346 5680080-5680123 355 568012e-5680240 346->355
                Memory Dump Source
                • Source File: 00000007.00000002.2085487994.0000000005680000.00000040.00000800.00020000.00000000.sdmp, Offset: 05680000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_5680000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7eb2bc779659f294571194eba3627cf38dbfba2858e69bc35853b56b6b5b2ef2
                • Instruction ID: ba9ed57728cb1816942dd4fee92f1e636d36cc1194bee4c69085e143027202bc
                • Opcode Fuzzy Hash: 7eb2bc779659f294571194eba3627cf38dbfba2858e69bc35853b56b6b5b2ef2
                • Instruction Fuzzy Hash: 8A414470605242CFD704EB38E55988EB7E2FF8520CB50886ED2454B669DF7C6D4BCB92

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 374 2e01048-2e0106b 375 2e0106e-2e01088 374->375 376 2e0108e-2e010ab 375->376
                Memory Dump Source
                • Source File: 00000007.00000002.2082617033.0000000002E01000.00000040.00000020.00020000.00000000.sdmp, Offset: 02E01000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_2e01000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9092571c124685529ba112f01fe09da0c512ba0f8ab8ac3d5b095beca568493a
                • Instruction ID: 1d7bfb07eef47700e1031679ebd4dd8c7c14964cb5721c81e21a20934dcd45e1
                • Opcode Fuzzy Hash: 9092571c124685529ba112f01fe09da0c512ba0f8ab8ac3d5b095beca568493a
                • Instruction Fuzzy Hash: 2701D6B65093846FD7018B15AC54862FFB8DF86620708C49FE849CB652D125A808C772

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 377 568001d-5680076
                Memory Dump Source
                • Source File: 00000007.00000002.2085487994.0000000005680000.00000040.00000800.00020000.00000000.sdmp, Offset: 05680000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_5680000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: cc693a9497a8abff08b9c04b868bc0b6c100472996fafe40093aafccceb5041a
                • Instruction ID: cbe2824faa5272fec3147080d4712507fdc57ff80a07eb90b04b5bc824263f03
                • Opcode Fuzzy Hash: cc693a9497a8abff08b9c04b868bc0b6c100472996fafe40093aafccceb5041a
                • Instruction Fuzzy Hash: 28F0DFA684F3C24FD34347B04C65A813FB4AE23211B0F85DBC480CB1A3E24849098723

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 378 2e0106e-2e01088 379 2e0108e-2e010ab 378->379
                Memory Dump Source
                • Source File: 00000007.00000002.2082617033.0000000002E01000.00000040.00000020.00020000.00000000.sdmp, Offset: 02E01000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_2e01000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 4a58308a73070dbd45726c317c3fb348be0850cdb6104e9d72874950a7ae023c
                • Instruction ID: 8d1ebc6df430c62cab1bb385a3759ca82106aa31bae4633e58d2cbe53d333ec9
                • Opcode Fuzzy Hash: 4a58308a73070dbd45726c317c3fb348be0850cdb6104e9d72874950a7ae023c
                • Instruction Fuzzy Hash: E3E092B66006044B9650CF0AED45462F7D8EB88630748C07FDC0D8B701D635B908CAA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 380 13e23f4-13e23ff 381 13e2412-13e2417 380->381 382 13e2401-13e240e 380->382 383 13e241a 381->383 384 13e2419 381->384 382->381 385 13e2420-13e2421 383->385
                Memory Dump Source
                • Source File: 00000007.00000002.2082237962.00000000013E2000.00000040.00000800.00020000.00000000.sdmp, Offset: 013E2000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13e2000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 99c0a203f29441ebb4a52a26aaec38f255aab03440bf253678539bd322866e13
                • Instruction ID: 0fbda62c6b9021773c27cdd084946c19b173c3d53067d9feb28b0b7959238e94
                • Opcode Fuzzy Hash: 99c0a203f29441ebb4a52a26aaec38f255aab03440bf253678539bd322866e13
                • Instruction Fuzzy Hash: B9D05E792057E14FE3269F1CC6A8B963BE8BB51718F4A44F9A800CB7A3C768D581DA00

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 386 13e23bc-13e23c3 387 13e23d6-13e23db 386->387 388 13e23c5-13e23d2 386->388 389 13e23dd-13e23e0 387->389 390 13e23e1 387->390 388->387 391 13e23e7-13e23e8 390->391
                Memory Dump Source
                • Source File: 00000007.00000002.2082237962.00000000013E2000.00000040.00000800.00020000.00000000.sdmp, Offset: 013E2000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_13e2000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 84b4b1cdb0ebfbf319871893c6210049eef8fd294a5bb37d3a8d9545a761f7ce
                • Instruction ID: 794a7f2ac5e63c1f2552ff76848688db7eca2f39483cfc93e16c80f1ebe0549f
                • Opcode Fuzzy Hash: 84b4b1cdb0ebfbf319871893c6210049eef8fd294a5bb37d3a8d9545a761f7ce
                • Instruction Fuzzy Hash: 57D05E343403818BD725DE0CC6D8F5A3BD8AF40B19F1A44E8AC108B7A2C7A8D9C0DE00

                Execution Graph

                Execution Coverage:8%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:12
                Total number of Limit Nodes:0
                execution_graph 917 2eba462 919 2eba486 RegSetValueExW 917->919 920 2eba507 919->920 925 2eba612 928 2eba646 CreateMutexW 925->928 927 2eba6c1 928->927 921 2eba361 922 2eba392 RegQueryValueExW 921->922 924 2eba41b 922->924 909 2eba646 910 2eba67e CreateMutexW 909->910 912 2eba6c1 910->912

                Callgraph

                • Executed
                • Not Executed
                • Opacity -> Relevance
                • Disassembly available
                callgraph 0 Function_02EBA56E 1 Function_02EBA462 2 Function_02EBA361 3 Function_02EB2264 4 Function_02EB2364 5 Function_02EB2979 6 Function_02EBA078 7 Function_02EB257F 8 Function_02EBA2FE 9 Function_02EBA172 10 Function_057B03E1 11 Function_0300101B 12 Function_02EB21F0 13 Function_0300119C 14 Function_02EB23F4 15 Function_02EBA1F4 16 Function_057B0258 17 Function_02EBA74E 18 Function_02EBA14D 19 Function_02EB284C 20 Function_0300102B 21 Function_02EBA540 22 Function_02EBA646 23 Function_030010AE 43 Function_030010D2 23->43 24 Function_02EB28C5 25 Function_02EB2044 26 Function_057B024B 27 Function_02EB2458 28 Function_02EBA25E 29 Function_02EBA45C 30 Function_02EBA2D2 31 Function_02EB28D1 32 Function_0300103B 33 Function_02EB20D0 34 Function_02EB2AAB 35 Function_02EB2729 36 Function_057B05BE 37 Function_02EBA02E 38 Function_057B043D 39 Function_03001048 40 Function_02EBA120 41 Function_02EB27A5 42 Function_02EB2624 44 Function_057B06AD 45 Function_02EB23BC 46 Function_02EB213C 47 Function_02EBA23C 48 Function_02EB2430 49 Function_057B02A5 50 Function_02EB22B4 51 Function_02EB2834 52 Function_057B0498 53 Function_057B001D 54 Function_030010E7 55 Function_02EB2681 56 Function_02EBA486 57 Function_0300106E 58 Function_02EB2005 59 Function_02EB2805 60 Function_02EBA005 61 Function_02EB2704 62 Function_02EBA09A 63 Function_02EB2098 64 Function_03001176 65 Function_02EBA392 66 Function_02EBA612 67 Function_02EB2511 68 Function_02EB2310 69 Function_057B0080 70 Function_02EBA710 71 Function_057B0007 72 Function_02EB2895 73 Function_02EBA215 74 Function_02EB2194

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 57b0258-57b0279 2 57b027b-57b02a3 0->2 3 57b02c0-57b02e7 0->3 8 57b02b6 2->8 9 57b02f2-57b02f8 3->9 8->3 10 57b02fa 9->10 11 57b02ff-57b030c 9->11 10->11 13 57b030e-57b0338 11->13 14 57b0343-57b0407 11->14 13->14 33 57b0409-57b043b 14->33 34 57b044e-57b045f 14->34 33->34 37 57b046a-57b0475 34->37 38 57b0461-57b0467 34->38 42 57b047b-57b0481 37->42 43 57b06b4-57b06ca 37->43 38->37 44 57b04a9-57b04ad 42->44 45 57b0483-57b0496 42->45 43->34 46 57b04e9-57b04f0 44->46 47 57b04af-57b04ca 44->47 45->44 46->34 50 57b04f6-57b0562 46->50 47->46 59 57b04cc-57b04e1 47->59 66 57b05cf-57b063b 50->66 67 57b0564-57b05bc 50->67 59->46 66->34 79 57b0641-57b0699 66->79 67->66 79->34
                Strings
                Memory Dump Source
                • Source File: 00000008.00000002.2164231800.00000000057B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 057B0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_57b0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: 2k$2k
                • API String ID: 0-107389494
                • Opcode ID: 2aae860126bc566ade81b4e92fc300941daa29c1e3858976ba9538b2fc1fb528
                • Instruction ID: db41e15d0ec14a60d660c026495cf739b47a3bc66400618f6f822d189f6cb2b9
                • Opcode Fuzzy Hash: 2aae860126bc566ade81b4e92fc300941daa29c1e3858976ba9538b2fc1fb528
                • Instruction Fuzzy Hash: 83B19138B002008FDB55DB75D4596ED77E3EFCA318B209469D8069B390EF7A9C86CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 85 57b024b-57b0279 87 57b027b-57b02a3 85->87 88 57b02c0-57b02e7 85->88 93 57b02b6 87->93 94 57b02f2-57b02f8 88->94 93->88 95 57b02fa 94->95 96 57b02ff-57b030c 94->96 95->96 98 57b030e-57b0338 96->98 99 57b0343-57b0407 96->99 98->99 118 57b0409-57b043b 99->118 119 57b044e-57b045f 99->119 118->119 122 57b046a-57b0475 119->122 123 57b0461-57b0467 119->123 127 57b047b-57b0481 122->127 128 57b06b4-57b06ca 122->128 123->122 129 57b04a9-57b04ad 127->129 130 57b0483-57b0496 127->130 128->119 131 57b04e9-57b04f0 129->131 132 57b04af-57b04ca 129->132 130->129 131->119 135 57b04f6-57b0562 131->135 132->131 144 57b04cc-57b04e1 132->144 151 57b05cf-57b063b 135->151 152 57b0564-57b05bc 135->152 144->131 151->119 164 57b0641-57b0699 151->164 152->151 164->119
                Strings
                Memory Dump Source
                • Source File: 00000008.00000002.2164231800.00000000057B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 057B0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_57b0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: 2k$2k
                • API String ID: 0-107389494
                • Opcode ID: 1be94e2d50f683811f1b40c86028de87b8a5e71a4b7d5bd382e5b869dcbd4433
                • Instruction ID: b4c85a2d567f56d60421c1ae51a608480ea83055b7cf471576f20d3f8c959104
                • Opcode Fuzzy Hash: 1be94e2d50f683811f1b40c86028de87b8a5e71a4b7d5bd382e5b869dcbd4433
                • Instruction Fuzzy Hash: D6B1A238B002008FDB55DB75D4596EE77E3EBCA314B209469D8069B390EF7A9C87CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 170 57b02a5-57b02f8 178 57b02fa 170->178 179 57b02ff-57b030c 170->179 178->179 181 57b030e-57b0338 179->181 182 57b0343-57b0407 179->182 181->182 201 57b0409-57b043b 182->201 202 57b044e-57b045f 182->202 201->202 205 57b046a-57b0475 202->205 206 57b0461-57b0467 202->206 210 57b047b-57b0481 205->210 211 57b06b4-57b06ca 205->211 206->205 212 57b04a9-57b04ad 210->212 213 57b0483-57b0496 210->213 211->202 214 57b04e9-57b04f0 212->214 215 57b04af-57b04ca 212->215 213->212 214->202 218 57b04f6-57b0562 214->218 215->214 227 57b04cc-57b04e1 215->227 234 57b05cf-57b063b 218->234 235 57b0564-57b05bc 218->235 227->214 234->202 247 57b0641-57b0699 234->247 235->234 247->202
                Strings
                Memory Dump Source
                • Source File: 00000008.00000002.2164231800.00000000057B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 057B0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_57b0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: 2k$2k
                • API String ID: 0-107389494
                • Opcode ID: bace3ea13c2636feeca37f3e814825ba22c8d8d56636afa1cbf0a29230514394
                • Instruction ID: c1af034beae09733c1c4a55f5a986b9fa9d04ab08a0338aef8a96e4dda734235
                • Opcode Fuzzy Hash: bace3ea13c2636feeca37f3e814825ba22c8d8d56636afa1cbf0a29230514394
                • Instruction Fuzzy Hash: 50A17F38B402008FDB59DB75D0596ED77E3EBCA318B209469D8069B390EF799C87CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 253 2eba612-2eba695 257 2eba69a-2eba6a3 253->257 258 2eba697 253->258 259 2eba6a8-2eba6b1 257->259 260 2eba6a5 257->260 258->257 261 2eba6b3-2eba6d7 CreateMutexW 259->261 262 2eba702-2eba707 259->262 260->259 265 2eba709-2eba70e 261->265 266 2eba6d9-2eba6ff 261->266 262->261 265->266
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 02EBA6B9
                Memory Dump Source
                • Source File: 00000008.00000002.2163513163.0000000002EBA000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EBA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eba000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: 3182d2701846122d12900821ee1b3f1f0a360afc1b0eabeb9cb5e34fa08589c4
                • Instruction ID: c7c9937310a8c989cb358f56e2fcadb3f2eba7db31d6a4969a9aa18280adcb0d
                • Opcode Fuzzy Hash: 3182d2701846122d12900821ee1b3f1f0a360afc1b0eabeb9cb5e34fa08589c4
                • Instruction Fuzzy Hash: A531C7B55093805FE722CB25DC45B96BFF8EF06214F0884AAE944CF292D374E909C771

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 269 2eba361-2eba3cf 272 2eba3d1 269->272 273 2eba3d4-2eba3dd 269->273 272->273 274 2eba3df 273->274 275 2eba3e2-2eba3e8 273->275 274->275 276 2eba3ea 275->276 277 2eba3ed-2eba404 275->277 276->277 279 2eba43b-2eba440 277->279 280 2eba406-2eba419 RegQueryValueExW 277->280 279->280 281 2eba41b-2eba438 280->281 282 2eba442-2eba447 280->282 282->281
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,A4E595BD,00000000,00000000,00000000,00000000), ref: 02EBA40C
                Memory Dump Source
                • Source File: 00000008.00000002.2163513163.0000000002EBA000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EBA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eba000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: e1b7e7e9a493f81448bd17cb42ce8be2a7c2d38c4c0cadcd12f04b42cecb159f
                • Instruction ID: 79ef479b71674a4b29a038313f0ef36dcf1086744fe794f95615a60f42329a73
                • Opcode Fuzzy Hash: e1b7e7e9a493f81448bd17cb42ce8be2a7c2d38c4c0cadcd12f04b42cecb159f
                • Instruction Fuzzy Hash: B9319175505784AFE722CF15CC84F97BBF8EF06214F0884AAE985CB292D324E949CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 286 2eba462-2eba4c3 289 2eba4c8-2eba4d4 286->289 290 2eba4c5 286->290 291 2eba4d9-2eba4f0 289->291 292 2eba4d6 289->292 290->289 294 2eba4f2-2eba505 RegSetValueExW 291->294 295 2eba527-2eba52c 291->295 292->291 296 2eba52e-2eba533 294->296 297 2eba507-2eba524 294->297 295->294 296->297
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,A4E595BD,00000000,00000000,00000000,00000000), ref: 02EBA4F8
                Memory Dump Source
                • Source File: 00000008.00000002.2163513163.0000000002EBA000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EBA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eba000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: ebb7741aceb4d1cd79b4d803f573edc66f6465869b7ddb1c52ce46381de5b250
                • Instruction ID: 37f0c16465a960b5006423796bfea2218fbc80e834d57255bd578cc87095b6f0
                • Opcode Fuzzy Hash: ebb7741aceb4d1cd79b4d803f573edc66f6465869b7ddb1c52ce46381de5b250
                • Instruction Fuzzy Hash: 4B21C1B65053846FDB228F51CC44FA7BFBCEF46214F08849AE985CB652D364E948CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 301 2eba646-2eba695 304 2eba69a-2eba6a3 301->304 305 2eba697 301->305 306 2eba6a8-2eba6b1 304->306 307 2eba6a5 304->307 305->304 308 2eba6b3-2eba6bb CreateMutexW 306->308 309 2eba702-2eba707 306->309 307->306 310 2eba6c1-2eba6d7 308->310 309->308 312 2eba709-2eba70e 310->312 313 2eba6d9-2eba6ff 310->313 312->313
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 02EBA6B9
                Memory Dump Source
                • Source File: 00000008.00000002.2163513163.0000000002EBA000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EBA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eba000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: b7c1685a0a4a14fdb5b8a29497554a34d8048c3bc3d8de05b9ef2accefc63418
                • Instruction ID: 1238af11abef33edf7b5275e7d6ee2adb2b254c07b2e4f5dbc68f36fcad881aa
                • Opcode Fuzzy Hash: b7c1685a0a4a14fdb5b8a29497554a34d8048c3bc3d8de05b9ef2accefc63418
                • Instruction Fuzzy Hash: 4921C2B56002049FEB21CF25DD85BAAFBE8EF04224F04C869E944CB741D374E909CA71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 316 2eba392-2eba3cf 318 2eba3d1 316->318 319 2eba3d4-2eba3dd 316->319 318->319 320 2eba3df 319->320 321 2eba3e2-2eba3e8 319->321 320->321 322 2eba3ea 321->322 323 2eba3ed-2eba404 321->323 322->323 325 2eba43b-2eba440 323->325 326 2eba406-2eba419 RegQueryValueExW 323->326 325->326 327 2eba41b-2eba438 326->327 328 2eba442-2eba447 326->328 328->327
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,A4E595BD,00000000,00000000,00000000,00000000), ref: 02EBA40C
                Memory Dump Source
                • Source File: 00000008.00000002.2163513163.0000000002EBA000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EBA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eba000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: 32d0554bbd1675fc2e80e201b700d880c31342938227132fdd92d1fb495476fc
                • Instruction ID: 0e2a9122237f21e44769b789a5dcbae5bcb9dc4f24c8297499b5dca0fb6443b4
                • Opcode Fuzzy Hash: 32d0554bbd1675fc2e80e201b700d880c31342938227132fdd92d1fb495476fc
                • Instruction Fuzzy Hash: 52215B756002049FEB21CF15DD88FA7B7E8EF04624F04C46AE9458B751D774E909CA71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 332 2eba486-2eba4c3 334 2eba4c8-2eba4d4 332->334 335 2eba4c5 332->335 336 2eba4d9-2eba4f0 334->336 337 2eba4d6 334->337 335->334 339 2eba4f2-2eba505 RegSetValueExW 336->339 340 2eba527-2eba52c 336->340 337->336 341 2eba52e-2eba533 339->341 342 2eba507-2eba524 339->342 340->339 341->342
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,A4E595BD,00000000,00000000,00000000,00000000), ref: 02EBA4F8
                Memory Dump Source
                • Source File: 00000008.00000002.2163513163.0000000002EBA000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EBA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eba000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: ce6bc73ea2eab525883f2ab356fc01cabd6b08135b8c3220297fcb6c4b26e3cc
                • Instruction ID: f6c52dea30ca22b0c2fa9dcbe4eb6d3c63f086390475f489e2f5ca18d30a64b1
                • Opcode Fuzzy Hash: ce6bc73ea2eab525883f2ab356fc01cabd6b08135b8c3220297fcb6c4b26e3cc
                • Instruction Fuzzy Hash: 5911ACB6500304AFEB228F15DD45FABBBECEF04624F04C46AED458A751D374E948CAB2

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 346 57b0080-57b0123 355 57b012e-57b0240 346->355
                Memory Dump Source
                • Source File: 00000008.00000002.2164231800.00000000057B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 057B0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_57b0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7d2a615a25234c4a309042968e6cde6a223eeb9e49f60e981df52ddb04e5d5e2
                • Instruction ID: 2df125d79c4450b4d645f61f8459cf7d27efafc97d407cd00ee1db5e19b9a3a2
                • Opcode Fuzzy Hash: 7d2a615a25234c4a309042968e6cde6a223eeb9e49f60e981df52ddb04e5d5e2
                • Instruction Fuzzy Hash: C341B6786051418FCB40DB74E5AD8C9B7E2EFC5248B50D968E0444B624FF3C6D8BCBA2

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 374 57b001d-57b001e 375 57b0020-57b0024 374->375 376 57b0025-57b002a 374->376 375->376 377 57b002c-57b002f 376->377 378 57b0031-57b003e 376->378 377->378 379 57b0040-57b0044 378->379 380 57b0045-57b0076 378->380 379->380
                Memory Dump Source
                • Source File: 00000008.00000002.2164231800.00000000057B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 057B0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_57b0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1a8debcf5b16bab7843ea8d3c731396331d1cc442b78fcabf309f1605c8f7f16
                • Instruction ID: 9e5bfe0dd080df9d702a7bd1316d9621f5b949fa9ac1a1b8706455f44da30c2b
                • Opcode Fuzzy Hash: 1a8debcf5b16bab7843ea8d3c731396331d1cc442b78fcabf309f1605c8f7f16
                • Instruction Fuzzy Hash: DB019D5244E3C04FDB435BB84CB9AE23FB5AD5721074E45C7C884CF5A7E148981AE322

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 383 3001048-300106b 384 300106e-3001088 383->384 385 300108e-30010ab 384->385
                Memory Dump Source
                • Source File: 00000008.00000002.2163828017.0000000003001000.00000040.00000020.00020000.00000000.sdmp, Offset: 03001000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_3001000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e6f5df888455aed79a10d943789cd0d764442cc8774d372d1ffb91a2fc29062a
                • Instruction ID: f8ee23e0842f42c77f3598b919d5e664da626a3b9261a466c56e36d101d04e50
                • Opcode Fuzzy Hash: e6f5df888455aed79a10d943789cd0d764442cc8774d372d1ffb91a2fc29062a
                • Instruction Fuzzy Hash: 270186B65093806FD7128F15AC44862FFF8EF8663070984DFEC49CB652D229A908CB72

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 386 300106e-3001088 387 300108e-30010ab 386->387
                Memory Dump Source
                • Source File: 00000008.00000002.2163828017.0000000003001000.00000040.00000020.00020000.00000000.sdmp, Offset: 03001000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_3001000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 2f32d5fb65f82d91fa86aa3e91864edcba1cfe2a17babf78826dfde4c80f168e
                • Instruction ID: 6e97aaabd713403c1e24553365c1c7d91d0710c06773be2080412add3fa58724
                • Opcode Fuzzy Hash: 2f32d5fb65f82d91fa86aa3e91864edcba1cfe2a17babf78826dfde4c80f168e
                • Instruction Fuzzy Hash: 9AE092B6A006044B9650CF0AEC45452F7D8EB88630708C07FDC0D8B711D639B908CEA6

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 388 2eb23f4-2eb23ff 389 2eb2412-2eb2417 388->389 390 2eb2401-2eb240e 388->390 391 2eb241a 389->391 392 2eb2419 389->392 390->389 393 2eb2420-2eb2421 391->393
                Memory Dump Source
                • Source File: 00000008.00000002.2163485459.0000000002EB2000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EB2000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eb2000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7221b8ce5b957205aee309edd8ffbf8c67e6be4e8b04eccb93cf6297cd8d3e4f
                • Instruction ID: 27e6a263d7fc9e002115086afa83530876fa623cc4570bfe42eed956fb860051
                • Opcode Fuzzy Hash: 7221b8ce5b957205aee309edd8ffbf8c67e6be4e8b04eccb93cf6297cd8d3e4f
                • Instruction Fuzzy Hash: 9FD0C7392406804ED3268A0CC6A4BC63B94AF40708F0A84B9AC008BB62C728D480E200

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 394 2eb23bc-2eb23c3 395 2eb23d6-2eb23db 394->395 396 2eb23c5-2eb23d2 394->396 397 2eb23dd-2eb23e0 395->397 398 2eb23e1 395->398 396->395 399 2eb23e7-2eb23e8 398->399
                Memory Dump Source
                • Source File: 00000008.00000002.2163485459.0000000002EB2000.00000040.00000800.00020000.00000000.sdmp, Offset: 02EB2000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_8_2_2eb2000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 42b704243804d83cb110b84191595ccdc01e3bac4addd4f130d2f48fb07bce88
                • Instruction ID: 204fd64ea76f950c17b2fa9a5e93c802e0aba15c97b0d4dff7bd07b1b8d446ac
                • Opcode Fuzzy Hash: 42b704243804d83cb110b84191595ccdc01e3bac4addd4f130d2f48fb07bce88
                • Instruction Fuzzy Hash: 20D05E343802824BC726DE0CD6D4F9A37D4AF44B19F0684E8AC108B762C7A8D9C0DA00

                Execution Graph

                Execution Coverage:9.3%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:19
                Total number of Limit Nodes:1
                execution_graph 834 30ea74e 835 30ea77a CloseHandle 834->835 836 30ea7b9 834->836 837 30ea788 835->837 836->835 842 30ea646 843 30ea67e CreateMutexW 842->843 845 30ea6c1 843->845 850 30ea612 852 30ea646 CreateMutexW 850->852 853 30ea6c1 852->853 858 30ea462 860 30ea486 RegSetValueExW 858->860 861 30ea507 860->861 854 30ea710 857 30ea720 CloseHandle 854->857 856 30ea788 857->856 862 30ea361 863 30ea392 RegQueryValueExW 862->863 865 30ea41b 863->865

                Callgraph

                • Executed
                • Not Executed
                • Opacity -> Relevance
                • Disassembly available
                callgraph 0 Function_059E0498 1 Function_030E2006 2 Function_030EA486 3 Function_03201029 4 Function_030E2704 5 Function_030E2805 6 Function_030EA005 7 Function_032010AE 63 Function_032010D2 7->63 8 Function_030E2681 9 Function_030EA09A 10 Function_030E2098 11 Function_03201038 12 Function_059E0006 13 Function_030E2194 14 Function_030E2895 15 Function_030EA215 16 Function_030EA612 17 Function_030EA392 18 Function_059E0080 19 Function_030EA710 20 Function_030E2511 21 Function_030EA02E 22 Function_059E05BE 23 Function_03201001 24 Function_059E043D 25 Function_030E2AAB 26 Function_030E2729 27 Function_030E2624 28 Function_030E27A5 29 Function_030EA120 30 Function_030E23BC 31 Function_030E213C 32 Function_030EA23C 33 Function_030E22B4 34 Function_030E2834 35 Function_059E02A5 36 Function_0320119C 37 Function_030E2430 38 Function_030EA74E 39 Function_030E284C 40 Function_030EA14D 41 Function_059E0258 42 Function_032010E7 43 Function_030EA646 44 Function_030E28C5 45 Function_0320106E 46 Function_030EA540 47 Function_030EA25E 48 Function_030EA45C 49 Function_059E024B 50 Function_03201176 51 Function_030E2458 52 Function_030EA2D2 53 Function_030E20D0 54 Function_030E28D1 55 Function_030EA56E 56 Function_03201047 57 Function_030E2364 58 Function_030E2264 59 Function_030EA462 60 Function_030EA361 61 Function_030EA2FE 62 Function_030E257F 64 Function_030EA078 65 Function_030E2979 66 Function_030E23F4 67 Function_030EA1F4 68 Function_030EA172 69 Function_030E21F0 70 Function_059E03E1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 59e0258-59e0279 2 59e027b-59e02a3 0->2 3 59e02c0-59e02e7 0->3 8 59e02b6 2->8 9 59e02f2-59e02f8 3->9 8->3 10 59e02ff-59e030c 9->10 11 59e02fa 9->11 13 59e030e-59e0338 10->13 14 59e0343-59e0407 10->14 11->10 13->14 33 59e044e-59e045f 14->33 34 59e0409-59e043b 14->34 37 59e046a-59e0475 33->37 38 59e0461-59e0467 33->38 34->33 41 59e047b-59e0481 37->41 42 59e06b4-59e06ca 37->42 38->37 44 59e04a9-59e04ad 41->44 45 59e0483-59e0496 41->45 42->33 46 59e04af-59e04ca 44->46 47 59e04e9-59e04f0 44->47 45->44 46->47 59 59e04cc-59e04e1 46->59 47->33 51 59e04f6-59e0562 47->51 66 59e05cf-59e063b 51->66 67 59e0564-59e05bc 51->67 59->47 66->33 79 59e0641-59e0699 66->79 67->66 79->33
                Strings
                Memory Dump Source
                • Source File: 00000009.00000002.2248221047.00000000059E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_59e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: -\mi^$2k$2k$=\mi^$M\mi^
                • API String ID: 0-282747480
                • Opcode ID: 4143b788b0b4314b31680e827aee28a29bd1f225e32ce2dc0bcfe6efedd69100
                • Instruction ID: 97b562f57ed59a46b5fe59deb7d10956a3cd20b042a066ae3286ef26b400a4a8
                • Opcode Fuzzy Hash: 4143b788b0b4314b31680e827aee28a29bd1f225e32ce2dc0bcfe6efedd69100
                • Instruction Fuzzy Hash: B1B1AE387002048FCB19EB35D45DA6D77E7EBC9318B104869D8069B394EF7EAC86CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 85 59e024b-59e0279 87 59e027b-59e02a3 85->87 88 59e02c0-59e02e7 85->88 93 59e02b6 87->93 94 59e02f2-59e02f8 88->94 93->88 95 59e02ff-59e030c 94->95 96 59e02fa 94->96 98 59e030e-59e0338 95->98 99 59e0343-59e0407 95->99 96->95 98->99 118 59e044e-59e045f 99->118 119 59e0409-59e043b 99->119 122 59e046a-59e0475 118->122 123 59e0461-59e0467 118->123 119->118 126 59e047b-59e0481 122->126 127 59e06b4-59e06ca 122->127 123->122 129 59e04a9-59e04ad 126->129 130 59e0483-59e0496 126->130 127->118 131 59e04af-59e04ca 129->131 132 59e04e9-59e04f0 129->132 130->129 131->132 144 59e04cc-59e04e1 131->144 132->118 136 59e04f6-59e0562 132->136 151 59e05cf-59e063b 136->151 152 59e0564-59e05bc 136->152 144->132 151->118 164 59e0641-59e0699 151->164 152->151 164->118
                Strings
                Memory Dump Source
                • Source File: 00000009.00000002.2248221047.00000000059E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_59e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: -\mi^$2k$2k$=\mi^$M\mi^
                • API String ID: 0-282747480
                • Opcode ID: f1eef3f676125398e9a80e71b3ee9acbb1c7ea5285f0746e68d51755d6ce39a3
                • Instruction ID: 6a952d768b4204f6c53d58092aa26ee370e54a1cb1ba3d0795cb83b0604d40dd
                • Opcode Fuzzy Hash: f1eef3f676125398e9a80e71b3ee9acbb1c7ea5285f0746e68d51755d6ce39a3
                • Instruction Fuzzy Hash: 1AB19E387002048FCB19EB35D45DA6D77E3EBC9318B144869D8069B394EF7EAC86CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 170 59e02a5-59e02f8 178 59e02ff-59e030c 170->178 179 59e02fa 170->179 181 59e030e-59e0338 178->181 182 59e0343-59e0407 178->182 179->178 181->182 201 59e044e-59e045f 182->201 202 59e0409-59e043b 182->202 205 59e046a-59e0475 201->205 206 59e0461-59e0467 201->206 202->201 209 59e047b-59e0481 205->209 210 59e06b4-59e06ca 205->210 206->205 212 59e04a9-59e04ad 209->212 213 59e0483-59e0496 209->213 210->201 214 59e04af-59e04ca 212->214 215 59e04e9-59e04f0 212->215 213->212 214->215 227 59e04cc-59e04e1 214->227 215->201 219 59e04f6-59e0562 215->219 234 59e05cf-59e063b 219->234 235 59e0564-59e05bc 219->235 227->215 234->201 247 59e0641-59e0699 234->247 235->234 247->201
                Strings
                Memory Dump Source
                • Source File: 00000009.00000002.2248221047.00000000059E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_59e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID: -\mi^$2k$2k$=\mi^$M\mi^
                • API String ID: 0-282747480
                • Opcode ID: a7e65f57a58b6a020b55980e234f0c874c60bc20a13e81cb8ad90e2054cbe6c5
                • Instruction ID: 8714f38263aecd6e5d10add396c7fd1fa76c2e49559bf64985322665635860c0
                • Opcode Fuzzy Hash: a7e65f57a58b6a020b55980e234f0c874c60bc20a13e81cb8ad90e2054cbe6c5
                • Instruction Fuzzy Hash: 2AA1AF38B002048FCB19EB35D05D66D77E3EBC9318B144869D8069B394EF7EAC86CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 253 30ea612-30ea695 257 30ea69a-30ea6a3 253->257 258 30ea697 253->258 259 30ea6a8-30ea6b1 257->259 260 30ea6a5 257->260 258->257 261 30ea702-30ea707 259->261 262 30ea6b3-30ea6d7 CreateMutexW 259->262 260->259 261->262 265 30ea709-30ea70e 262->265 266 30ea6d9-30ea6ff 262->266 265->266
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 030EA6B9
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: 53f37c33ba9ed66e98f96fc83d792efd47f7998b7c53270071183f2772a56a18
                • Instruction ID: 51542ba8493bfc17c5be65913ea797774a992a1e630e65dfa40f972ac4cbcaa0
                • Opcode Fuzzy Hash: 53f37c33ba9ed66e98f96fc83d792efd47f7998b7c53270071183f2772a56a18
                • Instruction Fuzzy Hash: 5F3181B56093845FE711CB25DD85B96FFF8EF06210F08849AE984CB292D375A909C771

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 269 30ea361-30ea3cf 272 30ea3d4-30ea3dd 269->272 273 30ea3d1 269->273 274 30ea3df 272->274 275 30ea3e2-30ea3e8 272->275 273->272 274->275 276 30ea3ed-30ea404 275->276 277 30ea3ea 275->277 279 30ea43b-30ea440 276->279 280 30ea406-30ea419 RegQueryValueExW 276->280 277->276 279->280 281 30ea41b-30ea438 280->281 282 30ea442-30ea447 280->282 282->281
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,75EDE220,00000000,00000000,00000000,00000000), ref: 030EA40C
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: 167ffe7c4521b0a17e57facbdf78ddcaa1cb0ba79e08876c4f13a312b55b00c8
                • Instruction ID: 750486bd6fd322d24ceff571037fa30cf43d5c72afc20df76a7ecd129b3c51c1
                • Opcode Fuzzy Hash: 167ffe7c4521b0a17e57facbdf78ddcaa1cb0ba79e08876c4f13a312b55b00c8
                • Instruction Fuzzy Hash: BF318175605784AFE722CF15CC84F96FBFCEF05210F08849AE9458B692D324E909CB71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 286 30ea462-30ea4c3 289 30ea4c8-30ea4d4 286->289 290 30ea4c5 286->290 291 30ea4d9-30ea4f0 289->291 292 30ea4d6 289->292 290->289 294 30ea527-30ea52c 291->294 295 30ea4f2-30ea505 RegSetValueExW 291->295 292->291 294->295 296 30ea52e-30ea533 295->296 297 30ea507-30ea524 295->297 296->297
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,75EDE220,00000000,00000000,00000000,00000000), ref: 030EA4F8
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: d133a996b426c54054d2eebac7c16e37e065c939f225605dc3ea4df67cb6d659
                • Instruction ID: 983e9c2a27ab4cf2f4dd683eb9739c6fdb6096283418ab37936dd47fc4c2d7bd
                • Opcode Fuzzy Hash: d133a996b426c54054d2eebac7c16e37e065c939f225605dc3ea4df67cb6d659
                • Instruction Fuzzy Hash: D1219FB62053846FD722CB11DC44F66BFB8DF45210F08849AE9858B652C264E908C771

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 301 30ea646-30ea695 304 30ea69a-30ea6a3 301->304 305 30ea697 301->305 306 30ea6a8-30ea6b1 304->306 307 30ea6a5 304->307 305->304 308 30ea702-30ea707 306->308 309 30ea6b3-30ea6bb CreateMutexW 306->309 307->306 308->309 311 30ea6c1-30ea6d7 309->311 312 30ea709-30ea70e 311->312 313 30ea6d9-30ea6ff 311->313 312->313
                APIs
                • CreateMutexW.KERNELBASE(?,?), ref: 030EA6B9
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: CreateMutex
                • String ID:
                • API String ID: 1964310414-0
                • Opcode ID: 272efad128fccd7973558064ea02000116b4e95155bc2d757faae538f2504869
                • Instruction ID: 2d4fd3623134a8c2b819522853c9a3c201a85ec19049f08b08883918e737ade2
                • Opcode Fuzzy Hash: 272efad128fccd7973558064ea02000116b4e95155bc2d757faae538f2504869
                • Instruction Fuzzy Hash: 812192757012449FE720DF25DD85BAAFBE8EF09224F0888A9ED44CB741D375E909CA71

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 316 30ea392-30ea3cf 318 30ea3d4-30ea3dd 316->318 319 30ea3d1 316->319 320 30ea3df 318->320 321 30ea3e2-30ea3e8 318->321 319->318 320->321 322 30ea3ed-30ea404 321->322 323 30ea3ea 321->323 325 30ea43b-30ea440 322->325 326 30ea406-30ea419 RegQueryValueExW 322->326 323->322 325->326 327 30ea41b-30ea438 326->327 328 30ea442-30ea447 326->328 328->327
                APIs
                • RegQueryValueExW.KERNELBASE(?,00000E24,75EDE220,00000000,00000000,00000000,00000000), ref: 030EA40C
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: QueryValue
                • String ID:
                • API String ID: 3660427363-0
                • Opcode ID: a5f9592b26e4bf77a66e58db254c0fc2634a8255fa49574b7b616a0f88d77e81
                • Instruction ID: 4a252a17a73dbf579444fc38c24310f192766bf17c22b46569694a2f698f7456
                • Opcode Fuzzy Hash: a5f9592b26e4bf77a66e58db254c0fc2634a8255fa49574b7b616a0f88d77e81
                • Instruction Fuzzy Hash: C7216DB67013049FE720CE15DD88FA6F7ECEF48620F08C4AAE9458B651D374E909CA75

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 332 30ea486-30ea4c3 334 30ea4c8-30ea4d4 332->334 335 30ea4c5 332->335 336 30ea4d9-30ea4f0 334->336 337 30ea4d6 334->337 335->334 339 30ea527-30ea52c 336->339 340 30ea4f2-30ea505 RegSetValueExW 336->340 337->336 339->340 341 30ea52e-30ea533 340->341 342 30ea507-30ea524 340->342 341->342
                APIs
                • RegSetValueExW.KERNELBASE(?,00000E24,75EDE220,00000000,00000000,00000000,00000000), ref: 030EA4F8
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: Value
                • String ID:
                • API String ID: 3702945584-0
                • Opcode ID: 0b73bbba29b35ae1da3ad0183ba8cbe46ed4a7b67e7e8addd161f1e31d90d69b
                • Instruction ID: 7f7aec98dbc5e443890eccfd3c54110bf8b55f44436629943ad6dd0118dc4ed7
                • Opcode Fuzzy Hash: 0b73bbba29b35ae1da3ad0183ba8cbe46ed4a7b67e7e8addd161f1e31d90d69b
                • Instruction Fuzzy Hash: B611B1B6700304AFE721CE15DD45FAAFBECEF48720F08845AED458AA51D374E808CAB1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 346 30ea710-30ea778 349 30ea77a-30ea79a CloseHandle 346->349 350 30ea7b9-30ea7be 346->350 353 30ea79c-30ea7b8 349->353 354 30ea7c0-30ea7c5 349->354 350->349 354->353
                APIs
                • CloseHandle.KERNELBASE(?), ref: 030EA780
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 9c9a031dcfd2677cad57a2034893e90e666b5f4a215eacb3b415af5668cfc6e0
                • Instruction ID: 1c4b694891a95a93be6a044f034faf7ad166b26607524c9c95b7bdeff07c9be2
                • Opcode Fuzzy Hash: 9c9a031dcfd2677cad57a2034893e90e666b5f4a215eacb3b415af5668cfc6e0
                • Instruction Fuzzy Hash: 1121D2B55093809FD712CB25DC85B52BFB8EF06320F0984DBED858F293D235A909CB61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 356 30ea74e-30ea778 357 30ea77a-30ea782 CloseHandle 356->357 358 30ea7b9-30ea7be 356->358 359 30ea788-30ea79a 357->359 358->357 361 30ea79c-30ea7b8 359->361 362 30ea7c0-30ea7c5 359->362 362->361
                APIs
                • CloseHandle.KERNELBASE(?), ref: 030EA780
                Memory Dump Source
                • Source File: 00000009.00000002.2247460632.00000000030EA000.00000040.00000800.00020000.00000000.sdmp, Offset: 030EA000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30ea000_lsass.jbxd
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 9bd9dd4a13e8903b1848e9fbca5097589ae386dc4462b2bfa2e05fda606e40f1
                • Instruction ID: 7ed082bfa2d41b575ba01a6556528af7cc30e5b4b8e8d73c13e79dbef825a09f
                • Opcode Fuzzy Hash: 9bd9dd4a13e8903b1848e9fbca5097589ae386dc4462b2bfa2e05fda606e40f1
                • Instruction Fuzzy Hash: 5C0171757012408FEB10CF15E989766FBE4EF48220F08C4ABED858B756D275E804DAA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 364 59e0080-59e0123 372 59e012e-59e0240 364->372
                Memory Dump Source
                • Source File: 00000009.00000002.2248221047.00000000059E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_59e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 90324815a9cfbb8d1cb10e7781791ad7ca76019ba72d8d592c97ca57f4611d98
                • Instruction ID: 9c8be3a0e894f358259643425f114415e6f06cb722dec346df7a11b2498161d7
                • Opcode Fuzzy Hash: 90324815a9cfbb8d1cb10e7781791ad7ca76019ba72d8d592c97ca57f4611d98
                • Instruction Fuzzy Hash: F3412278605242CFC304EF35E59D889B7E2EFC4348B508D69D4444B769EB3C6D8ACBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 391 59e0006-59e0076
                Memory Dump Source
                • Source File: 00000009.00000002.2248221047.00000000059E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 059E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_59e0000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 924348a70d6c2a02a96e495731e4393c3e04be6f09434c084e8a4c6741c40516
                • Instruction ID: e30fab0958b932f99390639270d4fc03190d63bdfdaf64576934b910b8bc3bbf
                • Opcode Fuzzy Hash: 924348a70d6c2a02a96e495731e4393c3e04be6f09434c084e8a4c6741c40516
                • Instruction Fuzzy Hash: 7F0168A644E3C54FD38387708C626513FB0EF13A05B4F85E7C081CB6A7E658990AD726

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 392 3201047-320106b 393 320106e-3201088 392->393 394 320108e-32010ab 393->394
                Memory Dump Source
                • Source File: 00000009.00000002.2247946276.0000000003201000.00000040.00000020.00020000.00000000.sdmp, Offset: 03201000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_3201000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1e9563cb28332c1616c4a5f01ea377656a07db5b6a79ede4598890d20d5685bb
                • Instruction ID: 15be1777cbb3e292ba1e49a48cedebdcd7f0e21451778ab80f79e18e737ac5e6
                • Opcode Fuzzy Hash: 1e9563cb28332c1616c4a5f01ea377656a07db5b6a79ede4598890d20d5685bb
                • Instruction Fuzzy Hash: 5401D6751493806FD3018B06EC40893BFF8EF86330B0984AFE8488B652D229B909CB65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 395 320106e-3201088 396 320108e-32010ab 395->396
                Memory Dump Source
                • Source File: 00000009.00000002.2247946276.0000000003201000.00000040.00000020.00020000.00000000.sdmp, Offset: 03201000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_3201000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e46a699eb2468eb9d799d9c9236ffdc762841099a4e520701fd450e2b5b1c3d5
                • Instruction ID: 633298116a085d30ad97fab9c60240b6bf0aa247c3562e7e266c70ad2c62b54f
                • Opcode Fuzzy Hash: e46a699eb2468eb9d799d9c9236ffdc762841099a4e520701fd450e2b5b1c3d5
                • Instruction Fuzzy Hash: 48E092B66006044BD650CF0AFD45452F7D8EB88630708C57FDC0D8B701D635B909CAA5
                Memory Dump Source
                • Source File: 00000009.00000002.2247422628.00000000030E2000.00000040.00000800.00020000.00000000.sdmp, Offset: 030E2000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30e2000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 5029b0dc27ec38982d3abc40c4451ff662d5cdfe8660d2fbd824e0c8ab432e4a
                • Instruction ID: 02e30b974e4f366c36dcd86d6dc66f5ed7d65c55ed2354ce3732eeaed79f197f
                • Opcode Fuzzy Hash: 5029b0dc27ec38982d3abc40c4451ff662d5cdfe8660d2fbd824e0c8ab432e4a
                • Instruction Fuzzy Hash: 04D017BA3066914ED326EA1CC6A4B9577D8AB51714F4A48B9A8008BB62C768D5D1D600
                Memory Dump Source
                • Source File: 00000009.00000002.2247422628.00000000030E2000.00000040.00000800.00020000.00000000.sdmp, Offset: 030E2000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_9_2_30e2000_lsass.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b37b6e1bbcbcf83424d6a478e4624c1f2c9bd9e1f9bdac7c4358620a46bd3a6a
                • Instruction ID: 36a475126b966c5d82bfca1b0fe169ae1c00683b6e53dc6b4963f644107260a2
                • Opcode Fuzzy Hash: b37b6e1bbcbcf83424d6a478e4624c1f2c9bd9e1f9bdac7c4358620a46bd3a6a
                • Instruction Fuzzy Hash: F0D05E343412814FC725EE1CC6D4F5977DCAF40B15F1A48E8AC108B762C7A8D9C0DE00