Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
174 Power Global_Enrollment_.docx.doc

Overview

General Information

Sample name:174 Power Global_Enrollment_.docx.doc
Analysis ID:1576717
MD5:6c8a333d687e2fa1f33743f871bb91da
SHA1:707b8e6335ae0bab3c1655fa6171cd9c40a5b9ed
SHA256:8793e8d51991da9adf6b67071cc9086dd80bd246fc06fb7edd15770eb05f4d2a
Tags:docuser-smica83
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected landing page (webpage, office document or email)
AI detected suspicious URL
Creates files inside the system directory
Deletes files inside the Windows folder
Document misses a certain OLE stream usually present in this Microsoft Office document type
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware

Classification

  • System is w11x64_office
  • WINWORD.EXE (PID: 2448 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /Automation -Embedding MD5: A9F0EC89897AC6C878D217DFB64CA752)
  • chrome.exe (PID: 8708 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 290DF23002E9B52249B5549F0C668A86)
    • chrome.exe (PID: 8932 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=1728,i,5776590258799465979,17540366911350167540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2148 /prefetch:11 MD5: 290DF23002E9B52249B5549F0C668A86)
  • chrome.exe (PID: 468 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ==" MD5: 290DF23002E9B52249B5549F0C668A86)
  • cleanup
No configs have been found
No yara matches
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE, ProcessId: 2448, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: Office documentJoe Sandbox AI: Office document contains prominent button: 'clicking here'
Source: EmailJoe Sandbox AI: AI detected Brand spoofing attempt in URL: https://nhlnkc.com
Source: EmailJoe Sandbox AI: AI detected Typosquatting in URL: https://nhlnkc.com
Source: https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ==HTTP Parser: No favicon
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49866 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49868 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49869 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49871 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49872 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49874 version: TLS 1.2
Source: winword.exeMemory has grown: Private usage: 4MB later: 95MB
Source: Joe Sandbox ViewASN Name: GOOGLE-AS-APGoogleAsiaPacificPteLtdSG GOOGLE-AS-APGoogleAsiaPacificPteLtdSG
Source: Joe Sandbox ViewJA3 fingerprint: 6a5d235ee78c6aede6a61448b4e9ff1e
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 172.64.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 20.223.36.55
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 172.64.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.64.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.64.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.64.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 172.64.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.200
Source: global trafficHTTP traffic detected: GET /th?id=OADD2.10239402414229_1P4RDVHBQE93FAZFW&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: tse1.mm.bing.netConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /th?id=OADD2.10239402415504_17DDWI2WCHUD2N4TB&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: tse1.mm.bing.netConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /th?id=OADD2.10239402415503_1IET5OVL073FDA0RX&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: tse1.mm.bing.netConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /th?id=OADD2.10239402414228_1EUMX2S6TUEXTBXLL&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: tse1.mm.bing.netConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /th?id=OADD2.10239359955652_1UH15L5Z2LXM3P8PA&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: tse1.mm.bing.netConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /th?id=OADD2.10239359955653_16Q8BS61PKT108CUW&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: tse1.mm.bing.netConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /creativeservice/2d863f0f-0fd5-72db-6971-f905df03ef53_3255140379518978990_128000000004796009_assets__image_1709055739600.jpg HTTP/1.1Accept: */*Accept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631Host: res.public.onecdn.static.microsoftConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ== HTTP/1.1Host: nhlnkc.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: nhlnkc.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36sec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ==Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /weathermapdata/1/static/weather/Icons/MSIAWwA=/Teaser/cold.png HTTP/1.1Accept: */*Accept-Language: en-CH,en-US;q=0.7,en;q=0.3UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: assets.msn.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /r/r1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Cache-Control: max-age = 3600Connection: Keep-AliveAccept: */*If-Modified-Since: Mon, 12 Feb 2024 22:07:27 GMTIf-None-Match: "65ca969f-2cd"User-Agent: Microsoft-CryptoAPI/10.0Host: x1.c.lencr.org
Source: global trafficDNS traffic detected: DNS query: cxcs.microsoft.net
Source: global trafficDNS traffic detected: DNS query: tse1.mm.bing.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: nhlnkc.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 17 Dec 2024 12:15:02 GMTContent-Type: text/plainContent-Length: 9Via: 1.1 googleAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Connection: close
Source: Primary1734437654651587900_797670CB-5BB2-4DEC-8A79-ECBD87D87A93.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40/flatfontassets.pkg
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49866 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49868 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49869 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49871 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49872 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.198.119.84:443 -> 192.168.2.24:49874 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir8708_713934461Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir8708_713934461Jump to behavior
Source: ~WRF{A2FD5B01-B097-4CF1-A2EB-A3A6EC38E851}.tmp.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: classification engineClassification label: mal48.winDOC@19/232@6/3
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Roaming\Microsoft\OfficeJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\{797670CB-5BB2-4DEC-8A79-ECBD87D87A93} - OProcSessId.datJump to behavior
Source: Element design set.dotx.0.drOLE indicator, Word Document stream: true
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drOLE indicator, Word Document stream: true
Source: Insight design set.dotx.0.drOLE indicator, Word Document stream: true
Source: Equations.dotx.0.drOLE indicator, Word Document stream: true
Source: ~WRD0000.tmp.0.drOLE indicator, Word Document stream: true
Source: ~WRF{A2FD5B01-B097-4CF1-A2EB-A3A6EC38E851}.tmp.0.drOLE document summary: title field not present or empty
Source: ~WRF{A2FD5B01-B097-4CF1-A2EB-A3A6EC38E851}.tmp.0.drOLE document summary: author field not present or empty
Source: ~WRF{A2FD5B01-B097-4CF1-A2EB-A3A6EC38E851}.tmp.0.drOLE document summary: edited time not present or 0
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /Automation -Embedding
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=1728,i,5776590258799465979,17540366911350167540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2148 /prefetch:11
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ=="
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=1728,i,5776590258799465979,17540366911350167540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2148 /prefetch:11Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: 174 Power Global_Enrollment_.docx.LNK.0.drLNK file: ..\..\..\..\..\Desktop\174 Power Global_Enrollment_.docx.doc
Source: Templates.LNK.0.drLNK file: ..\..\Templates
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = customXml/item2.xml
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
Source: Element design set.dotx.0.drInitial sample: OLE zip file path = docProps/custom.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/theme/_rels/theme1.xml.rels
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/_rels/settings.xml.rels
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = word/glossary/stylesWithEffects.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/item2.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/itemProps3.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/item3.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = customXml/_rels/item3.xml.rels
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
Source: Text Sidebar (Annual Report Red and Black design).docx.0.drInitial sample: OLE zip file path = docProps/custom.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/media/image2.jpg
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = word/media/image10.jpeg
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = customXml/item2.xml
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
Source: Insight design set.dotx.0.drInitial sample: OLE zip file path = docProps/custom.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/document.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
Source: Equations.dotx.0.drInitial sample: OLE zip file path = customXml/itemProps2.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = docProps/custom.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: Equations.dotx.0.drInitial sample: OLE zip file path = customXml/item2.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = [trash]/0000.dat
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/stylesWithEffects.xml
Source: Equations.dotx.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
Source: ~WRD0000.tmp.0.drInitial sample: OLE zip file path = word/glossary/document.xml
Source: ~WRD0000.tmp.0.drInitial sample: OLE zip file path = word/glossary/settings.xml
Source: ~WRD0000.tmp.0.drInitial sample: OLE zip file path = word/glossary/_rels/document.xml.rels
Source: ~WRD0000.tmp.0.drInitial sample: OLE zip file path = word/glossary/styles.xml
Source: ~WRD0000.tmp.0.drInitial sample: OLE zip file path = word/glossary/webSettings.xml
Source: ~WRD0000.tmp.0.drInitial sample: OLE zip file path = word/glossary/fontTable.xml
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: Element design set.dotx.0.drInitial sample: OLE indicators vbamacros = False
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
13
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
174 Power Global_Enrollment_.docx.doc0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://nhlnkc.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.181.100
truefalse
    high
    ax-0001.ax-msedge.net
    150.171.27.10
    truefalse
      high
      sni1gl.wpc.sigmacdn.net
      152.199.21.175
      truefalse
        high
        nhlnkc.com
        34.117.42.160
        truetrue
          unknown
          tse1.mm.bing.net
          unknown
          unknownfalse
            high
            cxcs.microsoft.net
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://tse1.mm.bing.net/th?id=OADD2.10239402415503_1IET5OVL073FDA0RX&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90false
                high
                https://res.public.onecdn.static.microsoft/creativeservice/2d863f0f-0fd5-72db-6971-f905df03ef53_3255140379518978990_128000000004796009_assets__image_1709055739600.jpgfalse
                  high
                  https://nhlnkc.com/favicon.icofalse
                  • Avira URL Cloud: safe
                  unknown
                  https://tse1.mm.bing.net/th?id=OADD2.10239359955653_16Q8BS61PKT108CUW&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90false
                    high
                    https://tse1.mm.bing.net/th?id=OADD2.10239402414229_1P4RDVHBQE93FAZFW&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90false
                      high
                      https://assets.msn.com/weathermapdata/1/static/weather/Icons/MSIAWwA=/Teaser/cold.pngfalse
                        high
                        https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ==false
                          unknown
                          https://tse1.mm.bing.net/th?id=OADD2.10239402415504_17DDWI2WCHUD2N4TB&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90false
                            high
                            https://tse1.mm.bing.net/th?id=OADD2.10239359955652_1UH15L5Z2LXM3P8PA&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90false
                              high
                              https://tse1.mm.bing.net/th?id=OADD2.10239402414228_1EUMX2S6TUEXTBXLL&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90false
                                high
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                142.250.181.100
                                www.google.comUnited States
                                15169GOOGLEUSfalse
                                34.117.42.160
                                nhlnkc.comUnited States
                                139070GOOGLE-AS-APGoogleAsiaPacificPteLtdSGtrue
                                IP
                                192.168.2.24
                                Joe Sandbox version:41.0.0 Charoite
                                Analysis ID:1576717
                                Start date and time:2024-12-17 13:13:10 +01:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:0h 6m 37s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:defaultwindowsofficecookbook.jbs
                                Analysis system description:Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09
                                Run name:Potential for more IOCs and behavior
                                Number of analysed new started processes analysed:36
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Sample name:174 Power Global_Enrollment_.docx.doc
                                Detection:MAL
                                Classification:mal48.winDOC@19/232@6/3
                                EGA Information:Failed
                                HCA Information:
                                • Successful, ratio: 100%
                                • Number of executed functions: 0
                                • Number of non-executed functions: 0
                                Cookbook Comments:
                                • Found application associated with file extension: .doc
                                • Found Word or Excel or PowerPoint or XPS Viewer
                                • Attach to Office via COM
                                • Browse link: https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ==
                                • Scroll down
                                • Close Viewer
                                • Exclude process from analysis (whitelisted): dllhost.exe, sppsvc.exe, BackgroundTransferHost.exe, SIHClient.exe, backgroundTaskHost.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
                                • Excluded IPs from analysis (whitelisted): 23.38.56.142, 52.109.28.46, 52.109.68.130, 52.113.194.132, 52.109.32.7, 13.89.179.10, 52.111.252.15, 52.111.252.16, 52.111.252.17, 52.111.252.18, 92.123.103.64, 92.123.103.82, 199.232.210.172, 2.19.198.19, 23.32.239.26, 23.32.239.73, 172.217.21.35, 64.233.164.84, 172.217.17.78, 142.250.181.142, 172.217.17.46, 172.217.17.42, 172.217.19.202, 172.217.19.10, 142.250.181.74, 142.250.181.138, 172.217.19.234, 142.250.181.42, 142.250.181.106, 216.58.208.234, 172.217.17.74, 172.217.21.42, 142.250.181.10, 172.217.17.35, 23.57.90.150, 23.57.90.161, 20.190.177.82, 152.199.21.175, 20.109.210.53, 20.223.35.26
                                • Excluded domains from analysis (whitelisted): odc.officeapps.live.com, slscr.update.microsoft.com, clientservices.googleapis.com, cxcs.microsoft.net.edgekey.net, mobile.events.data.microsoft.com, a1847.dscg2.akamai.net, clients2.google.com, login.live.com, update.googleapis.com, officeclient.microsoft.com, e3230.b.akamaiedge.net, www.bing.com, ecs.office.com, prod-inc-resolver.naturallanguageeditorservice.osi.office.net.akadns.net, frc-azsc-000.odc.officeapps.live.com, prod.roaming1.live.com.akadns.net, www.googleapis.com, s-0005-office.config.skype.com, cdn-office.ec.azureedge.net, x1.c.lencr.org, nleditor.osi.office.net, edgedl.me.gvt1.com, res-prod.trafficmanager.net, mm-mm.bing.net.trafficmanager.net, s-0005.s-msedge.net, osiprod-frc-bronze-azsc-000.francecentral.cloudapp.azure.com, metadata.templates.cdn.office.net, ecs.office.trafficmanager.net, clients.l.google.com, europe.configsvc1.live.com.akadns.net, mobile.events.data.trafficmanager.net, binaries.templates.cdn.office.net.edgesuite.net, res-2.cdn.o
                                • Not all processes where analyzed, report is missing behavior information
                                • Report size getting too big, too many NtCreateFile calls found.
                                • Report size getting too big, too many NtOpenFile calls found.
                                • Report size getting too big, too many NtQueryAttributesFile calls found.
                                • Report size getting too big, too many NtQueryValueKey calls found.
                                • Report size getting too big, too many NtReadVirtualMemory calls found.
                                • Report size getting too big, too many NtSetInformationFile calls found.
                                • Report size getting too big, too many NtSetValueKey calls found.
                                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                • VT rate limit hit for: 174 Power Global_Enrollment_.docx.doc
                                No simulations
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                34.117.42.160phish_alert_sp2_2.0.0.0 (36).emlGet hashmaliciousHTMLPhisherBrowse
                                  https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=http://930634sxy2v0.fastfiles.co/ad/Z2lsbGVzLmdhcmNpYUBiY3AtYmFuay5jb20=Get hashmaliciousHTMLPhisherBrowse
                                    https://nethunt.co/api/v1/track/link/click/6128be9d9a7b02bc0f63224d/emails.615aa7fa44d278ae1a885422?link=https://Aafintl.martinez-ruiz.com/%23amhlY2tAYWFmaW50bC5jb20=&c=E,1,Cji-4Tbk_oFxMwR-xSPvJMfrjo3tP5zDP94POJOJ8cm4E7I_MzPNIXEtRsMi14Z4ETjvNo5v_BFBrK2axGp1odhzsYob9-IZS5l0u5wn&typo=1Get hashmaliciousHTMLPhisherBrowse
                                      https://exclusifmoveis.com.br/new/auth/ZZMHI/c2NvdHQuZGFobmtlQGxjYXR0ZXJ0b24uY29tGet hashmaliciousUnknownBrowse
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        sni1gl.wpc.sigmacdn.nethttps://mailustabucaedu-my.sharepoint.com/:u:/g/personal/stella_pabon_ustabuca_edu_co/EWCk8BqICKBBrExz32n-PvYBCVoLK4PToNCGKPT0vElGYg?e=w0tQWEGet hashmaliciousUnknownBrowse
                                        • 152.199.21.175
                                        wayneenterprisesbatcave-6.0.1901-windows-installer.msiGet hashmaliciousScreenConnect ToolBrowse
                                        • 152.199.21.175
                                        QyzM5yhuwd.exeGet hashmaliciousMedusaLockerBrowse
                                        • 152.199.21.175
                                        Document.xlaGet hashmaliciousUnknownBrowse
                                        • 152.199.21.175
                                        letter_sjoslin_odeonuk.com.pdfGet hashmaliciousUnknownBrowse
                                        • 152.195.19.97
                                        sjoslin@odeonuk.com_print.svgGet hashmaliciousUnknownBrowse
                                        • 152.195.19.97
                                        sjoslin@odeonuk.com_print.svgGet hashmaliciousUnknownBrowse
                                        • 152.199.21.175
                                        https://docs.google.com/presentation/d/e/2PACX-1vQdSuwONgWFnuoaK9jWkn4a4T1fFD4ixA3V2X7f5aWnD4sHxk2b10z2j2TMxkq3G15FQX3bbwReJ2PF/pub?start=false&loop=false&delayms=3000Get hashmaliciousUnknownBrowse
                                        • 152.199.21.175
                                        letter_olivia.law_mercerhole.co.uk.pdfGet hashmaliciousHTMLPhisherBrowse
                                        • 152.199.21.175
                                        IMG_1205 #U2014 ThingLink.htmlGet hashmaliciousUnknownBrowse
                                        • 152.199.21.175
                                        ax-0001.ax-msedge.netnSs9QIsTua.jsGet hashmaliciousUnknownBrowse
                                        • 150.171.27.10
                                        http://uhsee.comGet hashmaliciousUnknownBrowse
                                        • 150.171.27.10
                                        veOECiSunn.exeGet hashmaliciousUnknownBrowse
                                        • 150.171.27.10
                                        V65xPrgEHH.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                        • 150.171.28.10
                                        OrderList.xlsx.lnkGet hashmaliciousUnknownBrowse
                                        • 150.171.28.10
                                        #U041e#U043f#U043b#U0430#U0442#U0430.xlsGet hashmaliciousUnknownBrowse
                                        • 150.171.28.10
                                        https://tinyurl.com/5faazntxGet hashmaliciousUnknownBrowse
                                        • 150.171.28.10
                                        wayneenterprisesbatcave-6.0.1901-windows-installer.msiGet hashmaliciousScreenConnect ToolBrowse
                                        • 150.171.27.10
                                        https://afg.acemlnb.com/lt.php?x=3TZy~GE3UnGZEpJA-w9HgOSc2K2ji_L0wu1gjqXGIXSh587-zEy.zuJr1Y2iitE~judAXHPHJeTMHaWtOdxFVOFx23MoiNDGet hashmaliciousUnknownBrowse
                                        • 150.171.28.10
                                        Tbconsulting Company Guidelines Employee Handbook.docxGet hashmaliciousUnknownBrowse
                                        • 150.171.28.10
                                        nhlnkc.comhttps://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=http://930634sxy2v0.fastfiles.co/ad/Z2lsbGVzLmdhcmNpYUBiY3AtYmFuay5jb20=Get hashmaliciousHTMLPhisherBrowse
                                        • 34.117.42.160
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        GOOGLE-AS-APGoogleAsiaPacificPteLtdSGhttps://alluc.co/watch-movies/passengers.htmlGet hashmaliciousUnknownBrowse
                                        • 34.117.77.79
                                        kjDPynh9vQ.exeGet hashmaliciousCredential FlusherBrowse
                                        • 34.117.188.166
                                        kjDPynh9vQ.exeGet hashmaliciousCredential FlusherBrowse
                                        • 34.117.188.166
                                        http://inspirafinancial.comGet hashmaliciousUnknownBrowse
                                        • 34.117.77.79
                                        Tbconsulting Company Guidelines Employee Handbook.docxGet hashmaliciousUnknownBrowse
                                        • 34.117.77.79
                                        file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                        • 34.117.188.166
                                        fNlxQP0jBz.exeGet hashmaliciousCredential FlusherBrowse
                                        • 34.117.188.166
                                        LbgqLv7gT7.exeGet hashmaliciousCredential FlusherBrowse
                                        • 34.117.188.166
                                        fNlxQP0jBz.exeGet hashmaliciousCredential FlusherBrowse
                                        • 34.117.188.166
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        6a5d235ee78c6aede6a61448b4e9ff1eCodale Electric Supply Health Insurance Benefits Open Enrollment Plan.html.shtmlGet hashmaliciousUnknownBrowse
                                        • 20.198.119.84
                                        No context
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):118
                                        Entropy (8bit):3.5700810731231707
                                        Encrypted:false
                                        SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                                        MD5:573220372DA4ED487441611079B623CD
                                        SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                                        SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                                        SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                                        Malicious:false
                                        Reputation:high, very likely benign file
                                        Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:JSON data
                                        Category:dropped
                                        Size (bytes):521377
                                        Entropy (8bit):4.9084889265453135
                                        Encrypted:false
                                        SSDEEP:3072:gdTb5Sb3F2FqSrfZm+CnQsbzxZO7aYb6f5780K2:wb5q3umBnzT
                                        MD5:C37972CBD8748E2CA6DA205839B16444
                                        SHA1:9834B46ACF560146DD7EE9086DB6019FBAC13B4E
                                        SHA-256:D4CFBB0E8B9D3E36ECE921B9B51BD37EF1D3195A9CFA1C4586AEA200EB3434A7
                                        SHA-512:02B4D134F84122B6EE9A304D79745A003E71803C354FB01BAF986BD15E3BA57BA5EF167CC444ED67B9BA5964FF5922C50E2E92A8A09862059852ECD9CEF1A900
                                        Malicious:false
                                        Reputation:high, very likely benign file
                                        Preview:{"MajorVersion":4,"MinorVersion":40,"Expiration":14,"Fonts":[{"a":[4294966911],"f":"Abadi","fam":[],"sf":[{"c":[1,0],"dn":"Abadi","fs":32696,"ful":[{"lcp":983041,"lsc":"Latn","ltx":"Abadi"}],"gn":"Abadi","id":"23643452060","p":[2,11,6,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":26215680},{"c":[1,0],"dn":"Abadi Extra Light","fs":22180,"ful":[{"lcp":983042,"lsc":"Latn","ltx":"Abadi Extra Light"}],"gn":"Abadi Extra Light","id":"17656736728","p":[2,11,2,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":13108480}]},{"a":[4294966911],"f":"ADLaM Display","fam":[],"sf":[{"c":[536870913,0],"dn":"ADLaM Display Regular","fs":140072,"ful":[{"lcp":983040,"lsc":"Latn","ltx":"ADLaM Display"}],"gn":"ADLaM Display","id":"31965479471","p":[2,1,0,0,0,0,0,0,0,0],"sub":[],"t":"ttf","u":[2147491951,1107296330,0,0],"v":131072,"w":26215680}]},{"a":[4294966911],"f":"Agency FB","fam":[],"sf":[{"c":[536870913,0],"dn":"Agency FB Bold","fs":54372,"ful":[{"lcp":9830
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409, \251 2018 Microsoft Corporation. All Rights Reserved.msofp_4_40RegularVersion 4.40;O365
                                        Category:dropped
                                        Size (bytes):773040
                                        Entropy (8bit):6.55939673749297
                                        Encrypted:false
                                        SSDEEP:12288:Zn84XULLDs51UJQSOf9VvLXHyheIQ47gEFGHtAgk3+/cLQ/zhm1kjFKy6Nyjbqq+:N8XPDs5+ivOXgo1kYvyz2
                                        MD5:4296A064B917926682E7EED650D4A745
                                        SHA1:3953A6AA9100F652A6CA533C2E05895E52343718
                                        SHA-256:E04E41C74D6C78213BA1588BACEE64B42C0EDECE85224C474A714F39960D8083
                                        SHA-512:A25388DDCE58D9F06716C0F0BDF2AEFA7F68EBCA7171077533AF4A9BE99A08E3DCD8DFE1A278B7AA5DE65DA9F32501B4B0B0ECAB51F9AF0F12A3A8A75363FF2C
                                        Malicious:false
                                        Reputation:high, very likely benign file
                                        Preview:........... OS/29....(...`cmap.s.,.......pglyf..&....|....head2..........6hheaE.@v.......$hmtx...........@loca.U.....8...Dmaxp........... name.P+........post...<...... .........b~1_.<...........<......r......Aa...................Q....Aa....Aa.........................~...................................................3..............................MS .@.......(...Q................. ...........d...........0...J.......8.......>..........+a..#...,................................................/...K.......z...............N......*...!...-...+........z.......h..%^..3...&j..+...+%..'R..+..."....................k......$A...,.......g...&...=.......X..&........*......&....B..(B...............#.......j...............+...P...5...@...)..........#...)Q...............*...{.. ....?..'...#....N...7......<...;>.............. ]...........5......#....s.......$.......$.......^..................+...>....H.......%...7.......6.......O...V...........K......"........c...N......!...............$...&...*p..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1822
                                        Entropy (8bit):2.6969522021127315
                                        Encrypted:false
                                        SSDEEP:48:m8/WKGjo/+vxsidpep4TB4M5EtK0Ial1Mepp5kyTzX:b3idraOqJm23
                                        MD5:0FF289DA942DD1F020B3C7A3BCFEBFBB
                                        SHA1:E4D55FBA37B1745A10B86FD6212F3C76A4142D54
                                        SHA-256:EB8224033B322E539D336D1B261495C0F83930DDEE9CCD79684903B6C4D1C50A
                                        SHA-512:FAEA2C260C4D0C3EE03580D79056F266018D204A05937D351C6111ED51CA05D4FCDE60F8A00EB751A3F31FC5563B48063B897A5068610BCD92C3D7EF99BE6DD1
                                        Malicious:false
                                        Preview:1.0.7.,.3.7.4.6.3.7.6.,.1.2.3.,.7.7.8.7.0.2.2.2.4.,.6.3.6.4.3.3.4.,.1.4.6.1.9.5.4.,.2.6.0.1.,.1.1.9.,.3.7.4.6.3.7.2.,.1.5.6.1.9.5.8.,.3.7.4.6.2.5.9.,.1.1.9.6.3.7.8.,.3.7.4.6.3.6.8.,.4.2.1.4.2.1.7.,.3.7.4.6.3.6.9.,.6.3.6.4.3.3.1.,.1.2.5.,.7.0.0.9.9.8.4.,.1.9.8.4.4.3.5.,.1.5.6.1.9.5.5.,.7.7.8.7.0.2.2.2.5.,.4.8.0.9.1.5.7.6.3.,.3.7.4.6.3.7.3.,.4.8.0.9.1.5.7.6.5.,.7.7.8.7.0.2.2.3.4.,.1.2.2.3.4.3.4.,.5.2.1.6.4.2.,.1.2.2.0.7.7.9.,.4.8.0.9.1.5.7.6.4.,.7.2.9.1.8.1.0.4.3.,.6.3.6.4.3.3.2.,.1.4.6.1.9.5.5.,.1.2.8.,.1.0.0.,.1.0.1.,.1.0.3.,.1.0.4.,.1.0.5.,.1.0.6.,.1.0.8.,.1.0.9.,.1.1.2.,.1.1.4.,.1.1.8.,.1.2.0.,.1.2.1.,.1.2.2.,.5.4.5.6.5.4.3.,.1.2.4.,.6.5.4.2.1.8.5.1.,.1.2.6.,.;.1.0.3.4.5.0.2.0.,.3.,.1.0.6.9.5.5.3.,.2.6.9.5.0.9.3.5.1.,.3.2.9.4.5.8.7.9.9.,.6.5.4.0.2.1.5.,.1.2.7.,.1.6.5.7.4.5.2.,.7.4.5.3.4.5.9.,.2.3.7.1.6.5.1.,.1.6.5.7.4.5.3.,.3.0.1.2.3.4.6.6.,.3.1.4.1.5.9.1.5.,.3.0.1.5.3.7.2.1.,.2.7.1.5.3.4.9.7.,.3.7.4.6.3.7.9.,.6.3.7.1.6.9.4.,.1.0.3.4.5.0.2.1.,.1.0.6.9.5.3.3.,.3.4.4.1.3.9.5.3.,.6.3.6.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 527x227, components 3
                                        Category:dropped
                                        Size (bytes):19546
                                        Entropy (8bit):7.961538731010203
                                        Encrypted:false
                                        SSDEEP:384:QU7NGTzwt8QV0ajHQTuJHM2O9L0wxXmaC5dcUH6gwMyp0m8ZSS9:D7NGvv4j46QmESr1A0L
                                        MD5:7D5AE40DE2739D3E4145CA4E6729EDA5
                                        SHA1:0720A23CB2633DB1190ADCA71A90A2C56C099EB0
                                        SHA-256:EA7EE7CA44825CC55032952011E489BED47C8EA83F972186D8367E75B03BC5D6
                                        SHA-512:F75A8F51EC39EC5582551FCB71003D0009E9490FEA5F09D42C6F3FB7CC8609842FEED7E506FD13A4C9D08F74430D8DD1F49DC540081D9C2556A765CE6B4B9B01
                                        Malicious:false
                                        Preview:......JFIF..............Compressed by jpeg-recompress......................................................"..."*%%*424DD\.................................................."..."*%%*424DD\...........".....................................................................&:l.@......8...z.....Y.J.......5}k......U....g.k......w......4-:L.........m...lVG.(~.N.8.m....-...~V*w*.[c.0.....l...?<..Z..6.R....,k.WOo._...l3.2z.!;...QU.....%.....&.~..._...U..N}.....|....ow`.....1S.TH..O...K.....=....=.=...Q.F..GO..h..V.x.....];7.7ObK;`....^...u..e]......h.O.?P.......}..U(.#.....hGw.>q..........=....*..z......=Z..?.F....O..N.*t...e.i.....r..K..Wa.Kb....L..nN...Ki.x..}...4.9b..*..o....v.W...J>>v..1j.`.....NX.......l..>..N.G#.r*.|./.4.=..._...B..}.....s.[.K..`.r._.?v....K....}^$o@.........m,.....Z.....G...4l^ri6j.Nk.rd..r....z.............<...q..^a.yy..Y.v.;.@......._.=... .............1..;...;C....E9).|c.d........a.s.W........ ...o.8.......T..e...U..#.....w.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Composite Document File V2 Document, Cannot read section info
                                        Category:dropped
                                        Size (bytes):2560
                                        Entropy (8bit):1.4158520490581685
                                        Encrypted:false
                                        SSDEEP:6:rl912N0xVN+CFQXFlXw9X//tlA9X//tlA9XCw9X0qlA9X0qlA9XCw9XCw9XCB9XP:rl3lTpFQfXI//o//oCI0l0lCICICb77
                                        MD5:721A0B8B60845ED63C4A0EC0C09296AD
                                        SHA1:CC8CA85208A548868A79C062BC6701A90E532438
                                        SHA-256:5CEA2D03D57495A34CBC04A722459C84163D4AD29FA73D93BA2328EBBAE2DC54
                                        SHA-512:038298B1A27AB9AF8A775C487FB76FE850B34D0E9BF97C345D4A3CEF48FC6A8315EB64090774FB65A4AC740089941B7591580B3A202A138064204145C1E9A66D
                                        Malicious:false
                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3296
                                        Entropy (8bit):2.4199534876865494
                                        Encrypted:false
                                        SSDEEP:24:6YpG3fAlMzHMPMC7DzTSlcjuilSUHLdcawKJKWcBQcmT3XU8DN84MHdn0:6Yo3fABEWDzelcjuilfLDwH6/N8xH10
                                        MD5:D3B862F3B3425E8DD6606A34B6835B6C
                                        SHA1:4057EF34E5986146CC6B69DC107DD5C6E9BB828D
                                        SHA-256:F86254703D7B1512122F8F00792969AE32FD98C6E6AF8C537E3C9287D60397F8
                                        SHA-512:D874E7AB82B17093DE10D250B98071750932D22F4680E7FBEC854BBED60A6E04A9EA624F88487F258217CEE9C15C9F39AADEAB4013978299B2CB6B070CB74E99
                                        Malicious:false
                                        Preview:........................................P.A.G.E...../.........................1.7.4.P.o.w.e.r.g.l.o.b.a.l. .e.m.p.l.o.y.e.e.s.,. .I.t.'.s. .t.h.a.t. .t.i.m.e. .o.f. .y.e.a.r. .a.g.a.i.n.,. .H.e.a.l.t.h. .B.e.n.e.f.i.t.s. .O.p.e.n. .E.n.r.o.l.l.m.e.n.t..................................................................................................................................................................................................................................................................................................................... ..."...$...4...:...>...B...F...J...N...........................x.......................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1822
                                        Entropy (8bit):2.6969522021127315
                                        Encrypted:false
                                        SSDEEP:48:m8/WKGjo/+vxsidpep4TB4M5EtK0Ial1Mepp5kyTzX:b3idraOqJm23
                                        MD5:0FF289DA942DD1F020B3C7A3BCFEBFBB
                                        SHA1:E4D55FBA37B1745A10B86FD6212F3C76A4142D54
                                        SHA-256:EB8224033B322E539D336D1B261495C0F83930DDEE9CCD79684903B6C4D1C50A
                                        SHA-512:FAEA2C260C4D0C3EE03580D79056F266018D204A05937D351C6111ED51CA05D4FCDE60F8A00EB751A3F31FC5563B48063B897A5068610BCD92C3D7EF99BE6DD1
                                        Malicious:false
                                        Preview:1.0.7.,.3.7.4.6.3.7.6.,.1.2.3.,.7.7.8.7.0.2.2.2.4.,.6.3.6.4.3.3.4.,.1.4.6.1.9.5.4.,.2.6.0.1.,.1.1.9.,.3.7.4.6.3.7.2.,.1.5.6.1.9.5.8.,.3.7.4.6.2.5.9.,.1.1.9.6.3.7.8.,.3.7.4.6.3.6.8.,.4.2.1.4.2.1.7.,.3.7.4.6.3.6.9.,.6.3.6.4.3.3.1.,.1.2.5.,.7.0.0.9.9.8.4.,.1.9.8.4.4.3.5.,.1.5.6.1.9.5.5.,.7.7.8.7.0.2.2.2.5.,.4.8.0.9.1.5.7.6.3.,.3.7.4.6.3.7.3.,.4.8.0.9.1.5.7.6.5.,.7.7.8.7.0.2.2.3.4.,.1.2.2.3.4.3.4.,.5.2.1.6.4.2.,.1.2.2.0.7.7.9.,.4.8.0.9.1.5.7.6.4.,.7.2.9.1.8.1.0.4.3.,.6.3.6.4.3.3.2.,.1.4.6.1.9.5.5.,.1.2.8.,.1.0.0.,.1.0.1.,.1.0.3.,.1.0.4.,.1.0.5.,.1.0.6.,.1.0.8.,.1.0.9.,.1.1.2.,.1.1.4.,.1.1.8.,.1.2.0.,.1.2.1.,.1.2.2.,.5.4.5.6.5.4.3.,.1.2.4.,.6.5.4.2.1.8.5.1.,.1.2.6.,.;.1.0.3.4.5.0.2.0.,.3.,.1.0.6.9.5.5.3.,.2.6.9.5.0.9.3.5.1.,.3.2.9.4.5.8.7.9.9.,.6.5.4.0.2.1.5.,.1.2.7.,.1.6.5.7.4.5.2.,.7.4.5.3.4.5.9.,.2.3.7.1.6.5.1.,.1.6.5.7.4.5.3.,.3.0.1.2.3.4.6.6.,.3.1.4.1.5.9.1.5.,.3.0.1.5.3.7.2.1.,.2.7.1.5.3.4.9.7.,.3.7.4.6.3.7.9.,.6.3.7.1.6.9.4.,.1.0.3.4.5.0.2.1.,.1.0.6.9.5.3.3.,.3.4.4.1.3.9.5.3.,.6.3.6.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:ASCII text, with very long lines (6906), with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):33006
                                        Entropy (8bit):5.497084774036574
                                        Encrypted:false
                                        SSDEEP:768:zwTUTGTjbNxvhGuoKGghB4NRxR4EF1V92vjVOBsp6e4HGzkNVEeU2HLiDd3wAbaJ:zwTUTGTjbnZHGghBaRYK1V92vjVOBspC
                                        MD5:CEEACC50A0E8B093890C6794FBBDE5C6
                                        SHA1:511438D1336FD12F85C5B631261BE10A568F9B1C
                                        SHA-256:A9B9326A29F498C1F5506598898DD0970A64E49E6D73BCA49090337A1FF669F5
                                        SHA-512:D66328A1E97D3DBE25F881B4262FDE1CF1AA9B3710DB94315D52613B741DCBA15BA1FFEE916CE5C5F39E263D67B035F1DCA47E75C831879C1C47D66A3F732CF1
                                        Malicious:false
                                        Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..12/17/2024 12:14:14.742.WINWORD (0x990).0xDD8.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":25,"Time":"2024-12-17T12:14:14.742Z","Contract":"Office.System.Activity","Activity.CV":"y3B2ebJb7E2Keey9h9h6kw.1.9","Activity.Duration":15,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...12/17/2024 12:14:14.742.WINWORD (0x990).0xDD8.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":26,"Time":"2024-12-17T12:14:14.742Z","Contract":"Office.System.Activity","Activity.CV":"y3B2ebJb7E2Keey9h9h6kw.1.10","Activity.Duration":13,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.Cl
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):254
                                        Entropy (8bit):3.4845992218379616
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXQFoElh/lE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny8lLGHmD0+dAH/luWvv
                                        MD5:E8B30D1070779CC14FBE93C8F5CF65BE
                                        SHA1:9C87F7BC66CF55634AB3F070064AAF8CC977CD05
                                        SHA-256:2E90434BE1F6DCEA9257D42C331CD9A8D06B848859FD4742A15612B2CA6EFACB
                                        SHA-512:C0D5363B43D45751192EF06C4EC3C896A161BB11DBFF1FC2E598D28C644824413C78AE3A68027F7E622AF0D709BE0FA893A3A3B4909084DF1ED9A8C1B8267FCA
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .H.e.x.a.g.o.n.R.a.d.i.a.l...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):6024
                                        Entropy (8bit):7.886254023824049
                                        Encrypted:false
                                        SSDEEP:96:bGa2onnLYHTSSxpHVTSH1bywZKmpRqiUtFvS9xrPooBpni6eDa16MUELHsrKjRBA:SJonLYzSSr1TuZNwtFZKpiiyrKXuCUd
                                        MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
                                        SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
                                        SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
                                        SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):4026
                                        Entropy (8bit):7.809492693601857
                                        Encrypted:false
                                        SSDEEP:96:VpDCBFLhxaUGm5EWA07yNdKH1FQpy8tnX8Iz3b7TrT502+fPD:VpDYFFRMNU+RtXzLf35t+3D
                                        MD5:5D9BAD7ADB88CEE98C5203883261ACA1
                                        SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
                                        SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
                                        SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
                                        Malicious:false
                                        Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):250
                                        Entropy (8bit):3.4916022431157345
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXsAl8xoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny8A8xoGHmD0+dAH/luWvv
                                        MD5:1A314B08BB9194A41E3794EF54017811
                                        SHA1:D1E70DB69CA737101524C75E634BB72F969464FF
                                        SHA-256:9025DD691FCAD181D5FD5952C7AA3728CD8A2CAF20DEA14930876419BED9B379
                                        SHA-512:AB29C8674A85711EABAE5F9559E9048FE91A2F51EB12D5A46152A310DE59F759DF8C617DA248798A7C20F60E26FBB1B0FC8DB47C46B098BCD26CF8CE78989ACA
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.r.a.c.k.e.t.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):238
                                        Entropy (8bit):3.472155835869843
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXGE2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny4GHmD0+dAH/luWvv
                                        MD5:2240CF2315F2EB448CEA6E9CE21B5AC5
                                        SHA1:46332668E2169E86760CBD975FF6FA9DB5274F43
                                        SHA-256:0F7D0BD5A8CED523CFF4F99D7854C0EE007F5793FA9E1BA1CD933B0894BFBD0D
                                        SHA-512:10BA73FF861112590BF135F4B337346F9D4ACEB10798E15DC5976671E345BC29AC8527C6052FEC86AA7058E06D1E49052E49D7BCF24A01DB259B5902DB091182
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .r.i.n.g.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):5151
                                        Entropy (8bit):7.859615916913808
                                        Encrypted:false
                                        SSDEEP:96:WkV3UHhcZDEteEJqeSGzpG43GUR8m8b6dDLiCTfjKPnD6H5RhfuDKNtxx3+7tDLp:Wq3UBc9EJqIpGgD5dDL1DjKvDKhfnNti
                                        MD5:6C24ED9C7C868DB0D55492BB126EAFF8
                                        SHA1:C6D96D4D298573B70CF5C714151CF87532535888
                                        SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
                                        SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
                                        Malicious:false
                                        Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):246
                                        Entropy (8bit):3.5039994158393686
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX4f+E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyvGHmD0+dAH/luWvv
                                        MD5:16711B951E1130126E240A6E4CC2E382
                                        SHA1:8095AA79AEE029FD06428244CA2A6F28408448DB
                                        SHA-256:855342FE16234F72DA0C2765455B69CF412948CFBE70DE5F6D75A20ACDE29AE9
                                        SHA-512:454EAA0FD669489583C317699BE1CE5D706C31058B08CF2731A7621FDEFB6609C2F648E02A7A4B2B3A3DFA8406A696D1A6FA5063DDA684BDA4450A2E9FEFB0EF
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.b.e.d.A.r.c...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):3683
                                        Entropy (8bit):7.772039166640107
                                        Encrypted:false
                                        SSDEEP:96:GyfQZd6ZHNCWl9aXFkZwIq/QDsRYPf8P9QtDIs5r:G6wYtNZS1k99AmPfSOtD5r
                                        MD5:E8308DA3D46D0BC30857243E1B7D330D
                                        SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
                                        SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
                                        SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
                                        Malicious:false
                                        Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):254
                                        Entropy (8bit):3.4721586910685547
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX9+RclTloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyteUTloGHmD0+dAH/luWvv
                                        MD5:4DD225E2A305B50AF39084CE568B8110
                                        SHA1:C85173D49FC1522121AA2B0B2E98ADF4BB95B897
                                        SHA-256:6F00DD73F169C73D425CB9895DAC12387E21C6E4C9C7DDCFB03AC32552E577F4
                                        SHA-512:0493AB431004191381FF84AD7CC46BD09A1E0FEEC16B3183089AA8C20CC7E491FAE86FE0668A9AC677F435A203E494F5E6E9E4A0571962F6021D6156B288B28A
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.e.v.r.o.n.a.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):4243
                                        Entropy (8bit):7.824383764848892
                                        Encrypted:false
                                        SSDEEP:96:22MQe4zHye8/djzF+JjvtmMkkBpF7e0LTkaf:22De4zHHCvF+nRBDXoaf
                                        MD5:7BC0A35807CD69C37A949BBD51880FF5
                                        SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
                                        SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
                                        SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
                                        Malicious:false
                                        Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):260
                                        Entropy (8bit):3.494357416502254
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX0XPE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXPGHmD0+dAH/luWvv
                                        MD5:6F8FE7B05855C203F6DEC5C31885DD08
                                        SHA1:9CC27D17B654C6205284DECA3278DA0DD0153AFF
                                        SHA-256:B7F58DF058C938CCF39054B31472DC76E18A3764B78B414088A261E440870175
                                        SHA-512:C518A243E51CB4A1E3C227F6A8A8D9532EE111D5A1C86EBBB23BD4328D92CD6A0587DF65B3B40A0BE2576D8755686D2A3A55E10444D5BB09FC4E0194DB70AFE6
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.G.r.i.d...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):6193
                                        Entropy (8bit):7.855499268199703
                                        Encrypted:false
                                        SSDEEP:192:WavHMKgnU2HUGFhUnkbOKoztj1QfcnLYut3d8:YKeUlGXUnC+HQSMp
                                        MD5:031C246FFE0E2B623BBBD231E414E0D2
                                        SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
                                        SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
                                        SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
                                        Malicious:false
                                        Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):332
                                        Entropy (8bit):3.547857457374301
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXSpGLMeKlPaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyipTIw9eNGHmD0wbnKYZAH/lMZqiv
                                        MD5:4EC6724CBBA516CF202A6BD17226D02C
                                        SHA1:E412C574D567F0BA68B4A31EDB46A6AB3546EA95
                                        SHA-256:18E408155A2C2A24D91CD45E065927FFDA726356AAB115D290A3C1D0B7100402
                                        SHA-512:DE45011A084AB94BF5B27F2EC274D310CF68DF9FB082E11726E08EB89D5D691EA086C9E0298E16AE7AE4B23753E5916F69F78AAD82F4627FC6F80A6A43D163DB
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .h.a.r.v.a.r.d.a.n.g.l.i.a.2.0.0.8.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):284415
                                        Entropy (8bit):5.00549404077789
                                        Encrypted:false
                                        SSDEEP:6144:N9G5o7Fv0ZcxrStAtXWty8zRLYBQd8itHiYYPVJHMSo27hlwNR57johqBXlwNR2b:y
                                        MD5:33A829B4893044E1851725F4DAF20271
                                        SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
                                        SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
                                        SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):286
                                        Entropy (8bit):3.538396048757031
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXcel8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyMelNGHmD0wbnKYZAH/lMZqiv
                                        MD5:149948E41627BE5DC454558E12AF2DA4
                                        SHA1:DB72388C037F0B638FCD007FAB46C916249720A8
                                        SHA-256:1B981DC422A042CDDEBE2543C57ED3D468288C20D280FF9A9E2BB4CC8F4776ED
                                        SHA-512:070B55B305DB48F7A8CD549A5AECF37DE9D6DCD780A5EC546B4BB2165AF4600FA2AF350DDDB48BECCAA3ED954AEE90F5C06C3183310B081F555389060FF4CB01
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .s.i.s.t.0.2...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):250983
                                        Entropy (8bit):5.057714239438731
                                        Encrypted:false
                                        SSDEEP:6144:JwprA6OS95vtfb8p4bgWPzkhUh9I5/oBRSifJeg/yQzvapSiQhHZeruvoXMUw3im:uP
                                        MD5:F883B260A8D67082EA895C14BF56DD56
                                        SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
                                        SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
                                        SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):278
                                        Entropy (8bit):3.5280239200222887
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXQAl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyllNGHmD0wbnKYZAH/lMZqiv
                                        MD5:877A8A960B2140E3A0A2752550959DB9
                                        SHA1:FBEC17B332CBC42F2F16A1A08767623C7955DF48
                                        SHA-256:FE07084A41CF7DB58B06D2C0D11BCACB603D6574261D1E7EBADCFF85F39AFB47
                                        SHA-512:B8B660374EC6504B3B5FCC7DAC63AF30A0C9D24306C36B33B33B23186EC96AEFE958A3851FF3BC57FBA72A1334F633A19C0B8D253BB79AA5E5AFE4A247105889
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.b...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):268317
                                        Entropy (8bit):5.05419861997223
                                        Encrypted:false
                                        SSDEEP:6144:JwprAJLR95vtfb8p4bgWPzDCvCmvQursq7vImej/yQzSS1apSiQhHDOruvoVeMUh:N9
                                        MD5:51D32EE5BC7AB811041F799652D26E04
                                        SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
                                        SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
                                        SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):242
                                        Entropy (8bit):3.4938093034530917
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX44lWWoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyvToGHmD0+dAH/luWvv
                                        MD5:A6B2731ECC78E7CED9ED5408AB4F2931
                                        SHA1:BA15D036D522978409846EA682A1D7778381266F
                                        SHA-256:6A2F9E46087B1F0ED0E847AF05C4D4CC9F246989794993E8F3E15B633EFDD744
                                        SHA-512:666926612E83A7B4F6259C3FFEC3185ED3F07BDC88D43796A24C3C9F980516EB231BDEA4DC4CC05C6D7714BA12AE2DCC764CD07605118698809DEF12A71F1FDD
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):4888
                                        Entropy (8bit):7.8636569313247335
                                        Encrypted:false
                                        SSDEEP:96:StrFZ23/juILHPzms5UTuK9CuZGEoEuZ28H1HiGa2RnnLY+tUb:SPZQ7uCHPzms5UTlqauZVHdJRnLY+tUb
                                        MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
                                        SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
                                        SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
                                        SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
                                        Malicious:false
                                        Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):252
                                        Entropy (8bit):3.4680595384446202
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXivlE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyydGHmD0+dAH/luWvv
                                        MD5:D79B5DE6D93AC06005761D88783B3EE6
                                        SHA1:E05BDCE2673B6AA8CBB17A138751EDFA2264DB91
                                        SHA-256:96125D6804544B8D4E6AE8638EFD4BD1F96A1BFB9EEF57337FFF40BA9FF4CDD1
                                        SHA-512:34057F7B2AB273964CB086D8A7DF09A4E05D244A1A27E7589BDC7E5679AB5F587FAB52A2261DB22070DA11EF016F7386635A2B8E54D83730E77A7B142C2E3929
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .a.r.c.h.i.t.e.c.t.u.r.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):5783
                                        Entropy (8bit):7.88616857639663
                                        Encrypted:false
                                        SSDEEP:96:CDG4D+8VsXzXc2zLXTJ2XFY47pk2G7HVlwFzTXNbMfmn2ivLZcreFWw5fc9ADdZm:CDG4DRGY23l2Xu47GL7YtT9V29yWvWdk
                                        MD5:8109B3C170E6C2C114164B8947F88AA1
                                        SHA1:FC63956575842219443F4B4C07A8127FBD804C84
                                        SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
                                        SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
                                        Malicious:false
                                        Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):286
                                        Entropy (8bit):3.4670546921349774
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX0XPYDxUloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXPYDCloGHmD0+dAH/luWvv
                                        MD5:3D52060B74D7D448DC733FFE5B92CB52
                                        SHA1:3FBA3FFC315DB5B70BF6F05C4FF84B52A50FCCBC
                                        SHA-256:BB980559C6FC38B703D1E9C41720D5CE8D00D2FF86D4F25136DB02B1E54B1518
                                        SHA-512:952EF139A72562A528C1052F1942DAE1C0509D67654BF5E7C0602C87F90147E8EE9E251D2632BCB5B511AB2FF8A3734293D0A4E3DBD3D187F5E3C042685F9A0C
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.l.t.e.r.n.a.t.i.n.g.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):5630
                                        Entropy (8bit):7.87271654296772
                                        Encrypted:false
                                        SSDEEP:96:n5ni6jKZWsD+QJaUQ7R6qYFF5QS+BEgeJam6S7ZCHuKViGa2CnnLYLt/ht:nccqxIBdQ1QS+uDJanS7ZCHHVdJCnLY5
                                        MD5:2F8998AA9CF348F1D6DE16EAB2D92070
                                        SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
                                        SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
                                        SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
                                        Malicious:false
                                        Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):274
                                        Entropy (8bit):3.438490642908344
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXZlaWimoa2nRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxnyplagN2RGHmD0wbnKYZAH+Vwv
                                        MD5:0F98498818DC28E82597356E2650773C
                                        SHA1:1995660972A978D17BC483FCB5EE6D15E7058046
                                        SHA-256:4587CA0B2A60728FF0A5B8E87D35BF6C6FDF396747E13436EC856612AC1C6288
                                        SHA-512:768562F20CFE15001902CCE23D712C7439721ECA6E48DDDCF8BFF4E7F12A3BC60B99C274CBADD0128EEA1231DB19808BAA878E825497F3860C381914C21B46FF
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.l.e.m.e.n.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):34415
                                        Entropy (8bit):7.352974342178997
                                        Encrypted:false
                                        SSDEEP:768:ev13NPo9o5NGEVIi3kvH+3SMdk7zp3tE2:ev13xoOE+R3BkR7
                                        MD5:7CDFFC23FB85AD5737452762FA36AAA0
                                        SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
                                        SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
                                        SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
                                        Malicious:false
                                        Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):374
                                        Entropy (8bit):3.5414485333689694
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX8FaE3f8AWqlQqr++lcWimqnKOE3QepmlJ0+3FbnKfZObdADryMluxHZypo:fxnyj9AWI+acgq9GHmD0wbnKYZAH/lMf
                                        MD5:2F7A8FE4E5046175500AFFA228F99576
                                        SHA1:8A3DE74981D7917E6CE1198A3C8E35C7E2100F43
                                        SHA-256:1495B4EC56B371148EA195D790562E5621FDBF163CDD8A5F3C119F8CA3BD2363
                                        SHA-512:4B8FBB692D91D88B584E46C2F01BDE0C05DCD5D2FF073D83331586FB3D201EACD777D48DB3751E534E22115AA1C3C30392D0D642B3122F21EF10E3EE6EA3BE82
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.e.x.t. .S.i.d.e.b.a.r. .(.A.n.n.u.a.l. .R.e.p.o.r.t. .R.e.d. .a.n.d. .B.l.a.c.k. .d.e.s.i.g.n.)...d.o.c.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):47296
                                        Entropy (8bit):6.42327948041841
                                        Encrypted:false
                                        SSDEEP:768:ftjI1BT8N37szq00s7dB2wMVJGHR97/RDU5naXUsT:fJIPTfq0ndB2w1bpsE
                                        MD5:5A53F55DD7DA8F10A8C0E711F548B335
                                        SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
                                        SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
                                        SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
                                        Malicious:false
                                        Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):280
                                        Entropy (8bit):3.484503080761839
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXGdQ1MecJZMlWlk2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxny2dQ98MlWlzGHmD0+dAH/luWvv
                                        MD5:1309D172F10DD53911779C89A06BBF65
                                        SHA1:274351A1059868E9DEB53ADF01209E6BFBDFADFB
                                        SHA-256:C190F9E7D00E053596C3477455D1639C337C0BE01012C0D4F12DFCB432F5EC56
                                        SHA-512:31B38AD2D1FFF93E03BF707811F3A18AD08192F906E36178457306DDAB0C3D8D044C69DE575ECE6A4EE584800F827FB3C769F98EA650F1C208FEE84177070339
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.t.e.r.c.o.n.n.e.c.t.e.d.B.l.o.c.k.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):9191
                                        Entropy (8bit):7.93263830735235
                                        Encrypted:false
                                        SSDEEP:192:oeAMExvPJMg+yE+AfJLi3+Xoj7F3sPgMG61J88eDhFWT7hFNsdJtnLYJ7tSh:v2d+hnfJLi3+4ja4WqhFWT7FsdHMA
                                        MD5:08D3A25DD65E5E0D36ADC602AE68C77D
                                        SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
                                        SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
                                        SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
                                        Malicious:false
                                        Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):262
                                        Entropy (8bit):3.4901887319218092
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXqhBMl0OoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyiMl0OoGHmD0+dAH/luWvv
                                        MD5:52BD0762F3DC77334807DDFC60D5F304
                                        SHA1:5962DA7C58F742046A116DDDA5DC8EA889C4CB0E
                                        SHA-256:30C20CC835E912A6DD89FD1BF5F7D92B233B2EC24594F1C1FE0CADB03A8C3FAB
                                        SHA-512:FB68B1CF9677A00D5651C51EC604B61DAC2D250D44A71D43CD69F41F16E4F0A7BAA7AD4A6F7BB870429297465A893013BBD7CC77A8F709AD6DB97F5A0927B1DD
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .R.a.d.i.a.l.P.i.c.t.u.r.e.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):5596
                                        Entropy (8bit):7.875182123405584
                                        Encrypted:false
                                        SSDEEP:96:dGa2unnLYEB2EUAPOak380NQjqbHaPKJebgrEVws8Vw+BMa0EbdLVQaZJgDZh0pJ:UJunLYEB2EUAxk3pIYaScgYwsV4bdS0X
                                        MD5:CDC1493350011DB9892100E94D5592FE
                                        SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
                                        SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
                                        SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):290
                                        Entropy (8bit):3.5161159456784024
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX+l8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyulNGHmD0wbnKYZAH/lMZqiv
                                        MD5:C15EB3F4306EBF75D1E7C3C9382DEECC
                                        SHA1:A3F9684794FFD59151A80F97770D4A79F1D030A6
                                        SHA-256:23C262DF3AEACB125E88C8FFB7DBF56FD23F66E0D476AFD842A68DDE69658C7F
                                        SHA-512:ACDF7D69A815C42223FD6300179A991A379F7166EFAABEE41A3995FB2030CD41D8BCD46B566B56D1DFBAE8557AFA1D9FD55143900A506FA733DE9DA5D73389D6
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .t.u.r.a.b.i.a.n...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):344303
                                        Entropy (8bit):5.023195898304535
                                        Encrypted:false
                                        SSDEEP:6144:UwprANnsqvtfL/vF/bkWPRMMv7EOMBPitjASjTQQr7IwR0TnyDk1b78plJwf33iD:6
                                        MD5:F079EC5E2CCB9CD4529673BCDFB90486
                                        SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
                                        SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
                                        SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):314
                                        Entropy (8bit):3.5230842510951934
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXJuJaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyZuUw9eNGHmD0wbnKYZAH/lMZqiv
                                        MD5:F25AC64EC63FA98D9E37782E2E49D6E6
                                        SHA1:97DD9CFA4A22F5B87F2B53EFA37332A9EF218204
                                        SHA-256:834046A829D1EA836131B470884905856DBF2C3C136C98ADEEFA0F206F38F8AB
                                        SHA-512:A0387239CDE98BCDE1668B582B046619C3B3505F9440343DAD22B1B7B9E05F3B74F2AE29E591EC37B6570A0C0E5FE571442873594B0684DDCCB4F6A1B5E10B1F
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.e.e.e.2.0.0.6.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):294178
                                        Entropy (8bit):4.977758311135714
                                        Encrypted:false
                                        SSDEEP:6144:ydkJ3yU0orh0SCLVXyMFsoiOjWIm4vW2uo4hfhf7v3uH4NYYP4BpBaZTTSSamEUD:b
                                        MD5:0C9731C90DD24ED5CA6AE283741078D0
                                        SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
                                        SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
                                        SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):290
                                        Entropy (8bit):3.5081874837369886
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXCOzi8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnydONGHmD0wbnKYZAH/lMZqiv
                                        MD5:8D9B02CC69FA40564E6C781A9CC9E626
                                        SHA1:352469A1ABB8DA1DC550D7E27924E552B0D39204
                                        SHA-256:1D4483830710EF4A2CC173C3514A9F4B0ACA6C44DB22729B7BE074D18C625BAE
                                        SHA-512:8B7DB2AB339DD8085104855F847C48970C2DD32ADB0B8EEA134A64C5CC7DE772615F85D057F4357703B65166C8CF0C06F4F6FD3E60FFC80DA3DD34B16D5B1281
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.n.a.m.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):255948
                                        Entropy (8bit):5.103631650117028
                                        Encrypted:false
                                        SSDEEP:6144:gwprAm795vtfb8p4bgWPWEtTmtcRCDPThNPFQwB+26RxlsIBkAgRMBHcTCwsHe5a:kW
                                        MD5:9888A214D362470A6189DEFF775BE139
                                        SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
                                        SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
                                        SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):260
                                        Entropy (8bit):3.4895685222798054
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX4cPBl4xoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyPl4xoGHmD0+dAH/luWvv
                                        MD5:63E8B0621B5DEFE1EF17F02EFBFC2436
                                        SHA1:2D02AD4FD9BF89F453683B7D2B3557BC1EEEE953
                                        SHA-256:9243D99795DCDAD26FA857CB2740E58E3ED581E3FAEF0CB3781CBCD25FB4EE06
                                        SHA-512:A27CDA84DF5AD906C9A60152F166E7BD517266CAA447195E6435997280104CBF83037F7B05AE9D4617323895DCA471117D8C150E32A3855156CB156E15FA5864
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.r.y.i.n.g.W.i.d.t.h.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):3075
                                        Entropy (8bit):7.716021191059687
                                        Encrypted:false
                                        SSDEEP:48:96yn4sOBoygpySCCxwKsZCB2oLEIK+aQpUNLRQWtmMamIZxAwCC2QnyODhVOzP4:l0vCxJsZQ2ofpKvtmMdIZxAwJyODhVOE
                                        MD5:67766FF48AF205B771B53AA2FA82B4F4
                                        SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
                                        SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
                                        SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
                                        Malicious:false
                                        Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):302
                                        Entropy (8bit):3.537169234443227
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXfQIUA/e/Wl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyXZ/eulNGHmD0wbnKYZAH/lMZqiv
                                        MD5:9C00979164E78E3B890E56BE2DF00666
                                        SHA1:1FA3C439D214C34168ADF0FBA5184477084A0E51
                                        SHA-256:21CCB63A82F1E6ACD6BAB6875ABBB37001721675455C746B17529EE793382C7B
                                        SHA-512:54AC8732C2744B60DA744E54D74A2664658E4257A136ABE886FF21585E8322E028D8243579D131EF4E9A0ABDDA70B4540A051C8B8B60D65C3EC0888FD691B9A7
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0.n.m.e.r.i.c.a.l...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):217137
                                        Entropy (8bit):5.068335381017074
                                        Encrypted:false
                                        SSDEEP:6144:AwprA3Z95vtf58pb1WP2DCvCmvQursq7vIme5QyQzSS1apSiQhHDlruvoVeMUwFj:4P
                                        MD5:3BF8591E1D808BCCAD8EE2B822CC156B
                                        SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
                                        SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
                                        SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):256
                                        Entropy (8bit):3.4842773155694724
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXDAlIJAFIloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyMlI7loGHmD0+dAH/luWvv
                                        MD5:923D406B2170497AD4832F0AD3403168
                                        SHA1:A77DA08C9CB909206CDE42FE1543B9FE96DF24FB
                                        SHA-256:EBF9CF474B25DDFE0F6032BA910D5250CBA2F5EDF9CF7E4B3107EDB5C13B50BF
                                        SHA-512:A4CD8C74A3F916CA6B15862FCA83F17F2B1324973CCBCC8B6D9A8AEE63B83A3CD880DC6821EEADFD882D74C7EF58FA586781DED44E00E8B2ABDD367B47CE45B7
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.o.n.v.e.r.g.i.n.g.T.e.x.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):11380
                                        Entropy (8bit):7.891971054886943
                                        Encrypted:false
                                        SSDEEP:192:VJcnLYnAVbOFLaCPLrGGbhaWEu6d3RmryqLkeAShObPb1AYcRMMXjkfa0nYBwggD:VcMC8lLrRbhy1ZqLyShYb1FHQ4C0nYQJ
                                        MD5:C9F9364C659E2F0C626AC0D0BB519062
                                        SHA1:C4036C576074819309D03BB74C188BF902D1AE00
                                        SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
                                        SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):286
                                        Entropy (8bit):3.5502940710609354
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXfQICl8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyXClNGHmD0wbnKYZAH/lMZqiv
                                        MD5:9B8D7EFE8A69E41CDC2439C38FE59FAF
                                        SHA1:034D46BEC5E38E20E56DD905E2CA2F25AF947ED1
                                        SHA-256:70042F1285C3CD91DDE8D4A424A5948AE8F1551495D8AF4612D59709BEF69DF2
                                        SHA-512:E50BB0C68A33D35F04C75F05AD4598834FEC7279140B1BB0847FF39D749591B8F2A0C94DA4897AAF6C33C50C1D583A836B0376015851910A77604F8396C7EF3C
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):270198
                                        Entropy (8bit):5.073814698282113
                                        Encrypted:false
                                        SSDEEP:6144:JwprAiaR95vtfb8pDbgWPzDCvCmvQursq7vImej/yQ4SS1apSiQhHDOruvoVeMUX:We
                                        MD5:FF0E07EFF1333CDF9FC2523D323DD654
                                        SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
                                        SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
                                        SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):332
                                        Entropy (8bit):3.4871192480632223
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXsdDUaw93Ti8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyoRw9eNGHmD0wbnKYZAH/lMZqiv
                                        MD5:333BA58FCE326DEA1E4A9DE67475AA95
                                        SHA1:F51FAD5385DC08F7D3E11E1165A18F2E8A028C14
                                        SHA-256:66142D15C7325B98B199AB6EE6F35B7409DE64EBD5C0AB50412D18CBE6894097
                                        SHA-512:BFEE521A05B72515A8D4F7D13D8810846DC60F1E85C363FFEBD6CACD23AE8D2E664C563FC74700A4ED4E358F378508D25C46CB5BE1CF587E2E278EBC22BB2625
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .m.l.a.s.e.v.e.n.t.h.e.d.i.t.i.o.n.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):254875
                                        Entropy (8bit):5.003842588822783
                                        Encrypted:false
                                        SSDEEP:6144:MwprAnniNgtfbzbOWPuv7kOMBLitjAUjTQLrYHwR0TnyDkHqV3iPr1zHX5T6SSXj:a
                                        MD5:377B3E355414466F3E3861BCE1844976
                                        SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
                                        SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
                                        SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):258
                                        Entropy (8bit):3.4692172273306268
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXcq9DsoE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnysmYoGHmD0+dAH/luWvv
                                        MD5:C1B36A0547FB75445957A619201143AC
                                        SHA1:CDB0A18152F57653F1A707D39F3D7FB504E244A7
                                        SHA-256:4DFF7D1CEF6DD85CC73E1554D705FA6586A1FBD10E4A73EEE44EAABA2D2FFED9
                                        SHA-512:0923FB41A6DB96C85B44186E861D34C26595E37F30A6F8E554BD3053B99F237D9AC893D47E8B1E9CF36556E86EFF5BE33C015CBBDD31269CDAA68D6947C47F3F
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .p.i.c.t.u.r.e.o.r.g.c.h.a.r.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):7370
                                        Entropy (8bit):7.9204386289679745
                                        Encrypted:false
                                        SSDEEP:192:fYa+ngK2xG6HvLvoUnXxO+blKO1lt2Zg0AV:fYVn8Y6Hv3XxO+8uQZCV
                                        MD5:586CEBC1FAC6962F9E36388E5549FFE9
                                        SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
                                        SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
                                        SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
                                        Malicious:false
                                        Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):333258
                                        Entropy (8bit):4.654450340871081
                                        Encrypted:false
                                        SSDEEP:6144:ybW83Zb181+MKHZR5D7H3hgtfL/8mIDbEhPv9FHSVsioWUyGYmwxAw+GIfnUNv5J:i
                                        MD5:5632C4A81D2193986ACD29EADF1A2177
                                        SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
                                        SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
                                        SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):328
                                        Entropy (8bit):3.541819892045459
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXuqRDA5McaQVTi8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxny+AASZQoNGHmD0wbnKYZAH/lMZqiv
                                        MD5:C3216C3FC73A4B3FFFE7ED67153AB7B5
                                        SHA1:F20E4D33BABE978BE6A6925964C57D6E6EF1A92E
                                        SHA-256:7CF1D6A4F0BE5E6184F59BFB1304509F38E480B59A3B091DBDC43B052D2137CB
                                        SHA-512:D3B78BE6E7633FF943F5E34063B5EFA4AF239CD49F437227FC7575F6CC65C497B7D6F6A979EA065065BEAF257CB368560B5462542692286052B5C7E5C01755BC
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .A.P.A.S.i.x.t.h.E.d.i.t.i.o.n.O.f.f.i.c.e.O.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):292
                                        Entropy (8bit):3.5026803317779778
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXC89ADni8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnyf9ADiNGHmD0wbnKYZAH/lMZqiv
                                        MD5:A0D51783BFEE86F3AC46A810404B6796
                                        SHA1:93C5B21938DA69363DBF79CE594C302344AF9D9E
                                        SHA-256:47B43E7DBDF8B25565D874E4E071547666B08D7DF4D736EA8521591D0DED640F
                                        SHA-512:CA3DB5A574745107E1D6CAA60E491F11D8B140637D4ED31577CC0540C12FDF132D8BC5EBABEA3222F4D7BA1CA016FF3D45FE7688D355478C27A4877E6C4D0D75
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.t.i.t.l.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):251032
                                        Entropy (8bit):5.102652100491927
                                        Encrypted:false
                                        SSDEEP:6144:hwprA5R95vtfb8p4bgWPwW6/m26AnV9IBgIkqm6HITUZJcjUZS1XkaNPQTlvB2zr:JA
                                        MD5:F425D8C274A8571B625EE66A8CE60287
                                        SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
                                        SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
                                        SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):16806
                                        Entropy (8bit):7.9519793977093505
                                        Encrypted:false
                                        SSDEEP:384:eSMjhqgJDGwOzHR3iCpK+QdLdfufFJ9aDn9LjDMVAwHknbz7OW:eSkhqglGwERSAHQdLhDn9AKokv7H
                                        MD5:950F3AB11CB67CC651082FEBE523AF63
                                        SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
                                        SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
                                        SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):254
                                        Entropy (8bit):3.4720677950594836
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXOu9+MlWlk2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnycMlWlzGHmD0+dAH/luWvv
                                        MD5:D04EC08EFE18D1611BDB9A5EC0CC00B1
                                        SHA1:668FF6DFE64D5306220341FC2C1353199D122932
                                        SHA-256:FA60500F951AFAF8FFDB6D1828456D60004AE1558E8E1364ADC6ECB59F5450C9
                                        SHA-512:97EBCCAF64FA33238B7CFC0A6D853EFB050D877E21EE87A78E17698F0BB38382FCE7F6C4D97D550276BD6B133D3099ECAB9CFCD739F31BFE545F4930D896EEC3
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.l.e.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):252
                                        Entropy (8bit):3.48087342759872
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXXt1MIae2E3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyfMIaRGHmD0+dAH/luWvv
                                        MD5:69757AF3677EA8D80A2FBE44DEE7B9E4
                                        SHA1:26AF5881B48F0CB81F194D1D96E3658F8763467C
                                        SHA-256:0F14CA656CDD95CAB385F9B722580DDE2F46F8622E17A63F4534072D86DF97C3
                                        SHA-512:BDA862300BAFC407D662872F0BFB5A7F2F72FE1B7341C1439A22A70098FA50C81D450144E757087778396496777410ADCE4B11B655455BEDC3D128B80CFB472A
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.i.c.t.u.r.e.F.r.a.m.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):4326
                                        Entropy (8bit):7.821066198539098
                                        Encrypted:false
                                        SSDEEP:96:+fF+Jrp7Yo5hnJiGa24TxEcpUeONo1w2NFocy2LQi33Z:2+f7YuhJdJ4TxEcmKwGkk3Z
                                        MD5:D32E93F7782B21785424AE2BEA62B387
                                        SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
                                        SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
                                        SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
                                        Malicious:false
                                        Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):256
                                        Entropy (8bit):3.464918006641019
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXR+EqRGRnRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxnyB+5RmRGHmD0wbnKYZAH+Vwv
                                        MD5:93149E194021B37162FD86684ED22401
                                        SHA1:1B31CAEBE1BBFA529092BE834D3B4AD315A6F8F1
                                        SHA-256:50BE99A154A6F632D49B04FCEE6BCA4D6B3B4B7C1377A31CE9FB45C462D697B2
                                        SHA-512:410A7295D470EC85015720B2B4AC592A472ED70A04103D200FA6874BEA6A423AF24766E98E5ACAA3A1DBC32C44E8790E25D4611CD6C0DBFFFE8219D53F33ACA7
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.q.u.a.t.i.o.n.s...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):51826
                                        Entropy (8bit):5.541375256745271
                                        Encrypted:false
                                        SSDEEP:384:erH5dYPCA4t3aEFGiSUDtYfEbi5Ry/AT7/6tHODaFlDSomurYNfT4A0VIwWNS89u:Q6Cbh9tENyWdaFUSYNfZS89/3qtEu
                                        MD5:2AB22AC99ACFA8A82742E774323C0DBD
                                        SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
                                        SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
                                        SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
                                        Malicious:false
                                        Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):288
                                        Entropy (8bit):3.523917709458511
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXC1l8ME3QepmlJ0+3FbnKfZObdADryMluxHZypwwyv:fxnySvNGHmD0wbnKYZAH/lMZqiv
                                        MD5:4A9A2E8DB82C90608C96008A5B6160EF
                                        SHA1:A49110814D9546B142C132EBB5B9D8A1EC23E2E6
                                        SHA-256:4FA948EEB075DFCB8DCA773A3F994560C69D275690953625731C4743CD5729F7
                                        SHA-512:320B9CC860FFBDB0FD2DB7DA7B7B129EEFF3FFB2E4E4820C3FBBFEA64735EB8CFE1F4BB5980302770C0F77FF575825F2D9A8BB59FC80AD4C198789B3D581963B
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.i.c.a.g.o...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):296658
                                        Entropy (8bit):5.000002997029767
                                        Encrypted:false
                                        SSDEEP:6144:RwprAMk0qvtfL/vF/bkWPz9yv7EOMBPitjASjTQQr7IwR0TnyDkJb78plJwf33iV:M
                                        MD5:9AC6DE7B629A4A802A41F93DB2C49747
                                        SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
                                        SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
                                        SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):3.4866056878458096
                                        Encrypted:false
                                        SSDEEP:6:fxnxUX0XrZUloE3QepmlJ0+hdADryMluyS6Bkls0Lwv:fxnyEXWloGHmD0+dAH/luWvv
                                        MD5:6C489D45F3B56845E68BE07EA804C698
                                        SHA1:C4C9012C0159770CB882870D4C92C307126CEC3F
                                        SHA-256:3FE447260CDCDEE287B8D01CF5F9F53738BFD6AAEC9FB9787F2826F8DEF1CA45
                                        SHA-512:D1355C48A09E7317773E4F1613C4613B7EA42D21F5A6692031D288D69D47B19E8F4D5A29AFD8B751B353FC7DE865EAE7CFE3F0BEC05F33DDF79526D64A29EB18
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):6448
                                        Entropy (8bit):7.897260397307811
                                        Encrypted:false
                                        SSDEEP:192:tgaoRbo1sMjb0NiJ85oPtqcS+yaXWoa8XBzdJYnLYFtWT7:LR1sk+i4o1qc1yaukzd8MK
                                        MD5:42A840DC06727E42D42C352703EC72AA
                                        SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
                                        SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
                                        SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
                                        Malicious:false
                                        Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):486596
                                        Entropy (8bit):7.668294441507828
                                        Encrypted:false
                                        SSDEEP:6144:A+JBmUx0Zo24n8z/2NSYFl2qGBuv8p6+LwwYmN59wBttsdJrmXMlP1NwQoGgeL:fNgxz/g5z2BT6+Eu0ntMcczNQG5L
                                        MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
                                        SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
                                        SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
                                        SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
                                        Malicious:false
                                        Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):274
                                        Entropy (8bit):3.535303979138867
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUX3IlVARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnynG6ymD0wbnKNAH/lMz1
                                        MD5:35AFE8D8724F3E19EB08274906926A0B
                                        SHA1:435B528AAF746428A01F375226C5A6A04099DF75
                                        SHA-256:97B8B2E246E4DAB15E494D2FB5F8BE3E6361A76C8B406C77902CE4DFF7AC1A35
                                        SHA-512:ACF4F124207974CFC46A6F4EA028A38D11B5AF40E55809E5B0F6F5DABA7F6FC994D286026FAC19A0B4E2311D5E9B16B8154F8566ED786E5EF7CDBA8128FD62AF
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.i.e.w...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):523048
                                        Entropy (8bit):7.715248170753013
                                        Encrypted:false
                                        SSDEEP:6144:WfmDdN6Zfv8q5rnM6vZ02PtMZRkfW5ipbnMHxVcsOWrCMxy0sD/mcKb4rYEY:xDdQXBrMi2YtggW5ObnMH1brJpUmBU0N
                                        MD5:C276F590BB846309A5E30ADC35C502AD
                                        SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
                                        SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
                                        SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):276
                                        Entropy (8bit):3.5159096381406645
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXQIa3ARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnygIaqymD0wbnKNAH/lMz1
                                        MD5:71CCB69AF8DD9821F463270FB8CBB285
                                        SHA1:8FED3EB733A74B2A57D72961F0E4CF8BCA42C851
                                        SHA-256:8E63D7ABA97DABF9C20D2FAC6EB1665A5D3FDEAB5FA29E4750566424AE6E40B4
                                        SHA-512:E62FC5BEAEC98C5FDD010FABDAA8D69237D31CA9A1C73F168B1C3ED90B6A9B95E613DEAD50EB8A5B71A7422942F13D6B5A299EB2353542811F2EF9DA7C3A15DC
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .F.r.a.m.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):570901
                                        Entropy (8bit):7.674434888248144
                                        Encrypted:false
                                        SSDEEP:6144:D2tTXiO/3GH5SkPQVAqWnGrkFxvay910UUTWZJarUv9TA0g8:kX32H+VWgkFxSgGTmarUv9T
                                        MD5:D676DE8877ACEB43EF0ED570A2B30F0E
                                        SHA1:6C8922697105CEC7894966C9C5553BEB64744717
                                        SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
                                        SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):282
                                        Entropy (8bit):3.5459495297497368
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXvBAuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnypJymD0wbnKNAH/lMz1
                                        MD5:76340C3F8A0BFCEDAB48B08C57D9B559
                                        SHA1:E1A6672681AA6F6D525B1D17A15BF4F912C4A69B
                                        SHA-256:78FE546321EDB34EBFA1C06F2B6ADE375F3B7C12552AB2A04892A26E121B3ECC
                                        SHA-512:49099F040C099A0AED88E7F19338140A65472A0F95ED99DEB5FA87587E792A2D11081D59FD6A83B7EE68C164329806511E4F1B8D673BEC9074B4FF1C09E3435D
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.i.v.i.d.e.n.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):558035
                                        Entropy (8bit):7.696653383430889
                                        Encrypted:false
                                        SSDEEP:12288:DQ/oYjRRRRRRRRYcdY/5ASWYqBMp8xsGGEOzI7vQQwOyP:DQ/nRRRRRRRRxY/5JWYZ3GGbI8YA
                                        MD5:3B5E44DDC6AE612E0346C58C2A5390E3
                                        SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
                                        SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
                                        SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):276
                                        Entropy (8bit):3.5361139545278144
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXeMWMluRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnycMlMymD0wbnKNAH/lMz1
                                        MD5:133D126F0DE2CC4B29ECE38194983265
                                        SHA1:D8D701298D7949BE6235493925026ED405290D43
                                        SHA-256:08485EBF168364D846C6FD55CD9089FE2090D1EE9D1A27C1812E1247B9005E68
                                        SHA-512:75D7322BE8A5EF05CAA48B754036A7A6C56399F17B1401F3F501DA5F32B60C1519F2981043A773A31458C3D9E1EF230EC60C9A60CAC6D52FFE16147E2E0A9830
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.s.i.s...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):777647
                                        Entropy (8bit):7.689662652914981
                                        Encrypted:false
                                        SSDEEP:6144:B04bNOJMngI856k0wwOGXMaXTLaTDmfBaN2Tx9iSUk1PdSnc0lnDlcGMcEFYYYYt:xbY6ngI46Aw5dmyYYYYYYYYY7p8d
                                        MD5:B30D2EF0FC261AECE90B62E9C5597379
                                        SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
                                        SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
                                        SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
                                        Malicious:false
                                        Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):290
                                        Entropy (8bit):3.5091498509646044
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUX1MiDuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyFdMymD0wbnKNAH/lMz1
                                        MD5:23D59577F4AE6C6D1527A1B8CDB9AB19
                                        SHA1:A345D683E54D04CC0105C4BFFCEF8C6617A0093D
                                        SHA-256:9ADD2C3912E01C2AC7FAD6737901E4EECBCCE6EC60F8E4D78585469A440E1E2C
                                        SHA-512:B85027276B888548ECB8A2FC1DB1574C26FF3FCA7AF1F29CD5074EC3642F9EC62650E7D47462837607E11DCAE879B1F83DF4762CA94667AE70CBF78F8D455346
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.t.r.o.p.o.l.i.t.a.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):562113
                                        Entropy (8bit):7.67409707491542
                                        Encrypted:false
                                        SSDEEP:12288:/dy5Gtyp/FZ9QqjdxDfSp424XeavSktiAVE0:/dizp1ndpqpMZnV
                                        MD5:4A1657A3872F9A77EC257F41B8F56B3D
                                        SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
                                        SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
                                        SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):278
                                        Entropy (8bit):3.535736910133401
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXeAlFkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyRGymD0wbnKNAH/lMz1
                                        MD5:487E25E610F3FC2EEA27AB54324EA8F6
                                        SHA1:11C2BB004C5E44503704E9FFEEFA7EA7C2A9305C
                                        SHA-256:022EC5077279A8E447B590F7260E1DBFF764DE5F9CDFD4FDEE32C94C66D4A1A2
                                        SHA-512:B8DF351E2C0EF101CF91DC02E136A3EE9C1FDB18294BECB13A29D676FBBE791A80A58A18FBDEB953BC21EC54EB7608154D401407C461ABD10ACB94CE8AD0E092
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.n.d.e.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):924687
                                        Entropy (8bit):7.824849396154325
                                        Encrypted:false
                                        SSDEEP:12288:lsadD3eLxI8XSh4yDwFw8oWR+6dmw2ZpQDKpazILv7Jzny/ApcWqyOpEZULn:qLxI8XSh4yUF/oWR+mLKpYIr7l3ZQ7n
                                        MD5:97EEC245165F2296139EF8D4D43BBB66
                                        SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
                                        SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
                                        SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
                                        Malicious:false
                                        Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):282
                                        Entropy (8bit):3.51145753448333
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXKsWkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6svymD0wbnKNAH/lMz1
                                        MD5:7956D2B60E2A254A07D46BCA07D0EFF0
                                        SHA1:AF1AC8CA6FE2F521B2EE2B7ABAB612956A65B0B5
                                        SHA-256:C92B7FD46B4553FF2A656FF5102616479F3B503341ED7A349ECCA2E12455969E
                                        SHA-512:668F5D0EFA2F5168172E746A6C32820E3758793CFA5DB6791DE39CB706EF7123BE641A8134134E579D3E4C77A95A0F9983F90E44C0A1CF6CDE2C4E4C7AF1ECA0
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.a.l.l.a.x...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):608122
                                        Entropy (8bit):7.729143855239127
                                        Encrypted:false
                                        SSDEEP:6144:Ckl6KRKwg9jf2q/bN69OuGFlC/DUhq68xOcJzGYnTxlLqU8dmTW:8yKwgZ2qY9kA7Uhq68H3ybmq
                                        MD5:8BA551EEC497947FC39D1D48EC868B54
                                        SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
                                        SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
                                        SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
                                        Malicious:false
                                        Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):278
                                        Entropy (8bit):3.516359852766808
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXKwRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6qymD0wbnKNAH/lMz1
                                        MD5:960E28B1E0AB3522A8A8558C02694ECF
                                        SHA1:8387E9FD5179A8C811CCB5878BAC305E6A166F93
                                        SHA-256:2707FCA8CEC54DF696F19F7BCAD5F0D824A2AC01B73815DE58F3FCF0AAB3F6A0
                                        SHA-512:89EA06BA7D18B0B1EA624BBC052F73366522C231BD3B51745B92CF056B445F9D655F9715CBDCD3B2D02596DB4CD189D91E2FE581F2A2AA2F6D814CD3B004950A
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.c.e.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):966946
                                        Entropy (8bit):7.8785200658952
                                        Encrypted:false
                                        SSDEEP:24576:qBcvGBGhXQir6H1ws6+iU0YuA35VuinHX2NPs:ccvGBGdQ5CsMxQVj3yPs
                                        MD5:F03AB824395A8F1F1C4F92763E5C5CAD
                                        SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
                                        SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
                                        SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
                                        Malicious:false
                                        Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):282
                                        Entropy (8bit):3.5323495192404475
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXhduDARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyxdumymD0wbnKNAH/lMz1
                                        MD5:BD6B5A98CA4E6C5DBA57C5AD167EDD00
                                        SHA1:CCFF7F635B31D12707DC0AC6D1191AB5C4760107
                                        SHA-256:F22248FE60A55B6C7C1EB31908FAB7726813090DE887316791605714E6E3CEF7
                                        SHA-512:A178299461015970AF23BA3D10E43FCA5A6FB23262B0DD0C5DDE01D338B4959F222FD2DC2CC5E3815A69FDDCC3B6B4CB8EE6EC0883CE46093C6A59FF2B042BC1
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .Q.u.o.t.a.b.l.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):976001
                                        Entropy (8bit):7.791956689344336
                                        Encrypted:false
                                        SSDEEP:24576:zHM7eZGgFiHMRej4N9tpytNZ+tIw5ErZBImlX0m:zHM7eZGgFiHMRej++NZ+F5WvllZ
                                        MD5:9E563D44C28B9632A7CF4BD046161994
                                        SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
                                        SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
                                        SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):278
                                        Entropy (8bit):3.5270134268591966
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXa3Y1kRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyt1mymD0wbnKNAH/lMz1
                                        MD5:327DA4A5C757C0F1449976BE82653129
                                        SHA1:CF74ECDF94B4A8FD4C227313C8606FD53B8EEA71
                                        SHA-256:341BABD413AA5E8F0A921AC309A8C760A4E9BA9CFF3CAD3FB2DD9DF70FD257A6
                                        SHA-512:9184C3FB989BB271B4B3CDBFEFC47EA8ABEB12B8904EE89797CC9823F33952BD620C061885A5C11BBC1BD3978C4B32EE806418F3F21DA74F1D2DB9817F6E167E
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.e.r.l.i.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1649585
                                        Entropy (8bit):7.875240099125746
                                        Encrypted:false
                                        SSDEEP:24576:L368X6z95zf5BbQ6U79dYy2HiTIxRboyM/LZTl5KnCc:r68kb7UTYxGIxmnp65
                                        MD5:35200E94CEB3BB7A8B34B4E93E039023
                                        SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
                                        SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
                                        SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
                                        Malicious:false
                                        Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):284
                                        Entropy (8bit):3.5552837910707304
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXtLARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnygymD0wbnKNAH/lMz1
                                        MD5:5728F26DF04D174DE9BDFF51D0668E2A
                                        SHA1:C998DF970655E4AF9C270CC85901A563CFDBCC22
                                        SHA-256:979DAFD61C23C185830AA3D771EDDC897BEE87587251B84F61776E720ACF9840
                                        SHA-512:491B36AC6D4749F7448B9A3A6E6465E8D97FB30F33EF5019AF65660E98F4570711EFF5FC31CBB8414AD9355029610E6F93509BC4B2FB6EA79C7CB09069DE7362
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .W.o.o.d._.T.y.p.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1091485
                                        Entropy (8bit):7.906659368807194
                                        Encrypted:false
                                        SSDEEP:24576:oBpmCkw3Tg/euEB+UdoC4k7ytHkHA6B/puqW2MIkTeSBmKrZHQ:MR3c/AseydwppC7veSBmWHQ
                                        MD5:2192871A20313BEC581B277E405C6322
                                        SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
                                        SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
                                        SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
                                        Malicious:false
                                        Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):280
                                        Entropy (8bit):3.5301133500353727
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXp2pRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyZ2vymD0wbnKNAH/lMz1
                                        MD5:1C5D58A5ED3B40486BC22B254D17D1DD
                                        SHA1:69B8BB7B0112B37B9B5F9ADA83D11FBC99FEC80A
                                        SHA-256:EBE031C340F04BB0235FE62C5A675CF65C5CC8CE908F4621A4F5D7EE85F83055
                                        SHA-512:4736E4F26C6FAAB47718945BA54BD841FE8EF61F0DBA927E5C4488593757DBF09689ABC387A8A44F7C74AA69BA89BEE8EA55C87999898FEFEB232B1BA8CC7086
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .G.a.l.l.e.r.y...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1204049
                                        Entropy (8bit):7.92476783994848
                                        Encrypted:false
                                        SSDEEP:24576:+3zSQBxvOUIpHLYTCEmS1Wu09jRalJP3sdgnmAOFt0zU4L0MRx5QNn5:+bvI5UTCPu09qP3JPOFoR4N5
                                        MD5:FD5BBC58056522847B3B75750603DF0C
                                        SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
                                        SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
                                        SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
                                        Malicious:false
                                        Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):276
                                        Entropy (8bit):3.5364757859412563
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXARkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnywMymD0wbnKNAH/lMz1
                                        MD5:CD465E8DA15E26569897213CA9F6BC9C
                                        SHA1:9EA9B5E6C9B7BF72A777A21EC17FD82BC4386D4C
                                        SHA-256:D4109317C2DBA1D7A94FC1A4B23FA51F4D0FC8E1D9433697AAFA72E335192610
                                        SHA-512:869A42679F96414FE01FE1D79AF7B33A0C9B598B393E57E0E4D94D68A4F2107EC58B63A532702DA96A1F2F20CE72E6E08125B38745CD960DF62FE539646EDD8D
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.a.v.o.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):1463634
                                        Entropy (8bit):7.898382456989258
                                        Encrypted:false
                                        SSDEEP:24576:75MGNW/UpLkupMAqDJhNHK4/TuiKbdhbZM+byLH/:7ZwUpLkulkHK46iiDZHeLH/
                                        MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
                                        SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
                                        SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
                                        SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):280
                                        Entropy (8bit):3.5286004619027067
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXOzXkRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny6WymD0wbnKNAH/lMz1
                                        MD5:40FF521ED2BA1B015F17F0B0E5D95068
                                        SHA1:0F29C084311084B8FDFE67855884D8EB60BDE1A6
                                        SHA-256:CC3575BA195F0F271FFEBA6F6634BC9A2CF5F3BE448F58DBC002907D7C81CBBB
                                        SHA-512:9507E6145417AC730C284E58DC6B2063719400B395615C40D7885F78F57D55B251CB9C954D573CB8B6F073E4CEA82C0525AE90DEC68251C76A6F1B03FD9943C0
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.u.i.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1750795
                                        Entropy (8bit):7.892395931401988
                                        Encrypted:false
                                        SSDEEP:24576:DyeAqDJpUDH3xk8ZKIBuX3TPtd36v4o5d4PISMETGBP6eUP+xSeW3v0HKPsc:uRqUjSTPtd36AFDM/BP6eUeW3v0Fc
                                        MD5:529795E0B55926752462CBF32C14E738
                                        SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
                                        SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
                                        SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):280
                                        Entropy (8bit):3.528155916440219
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXcmlDuRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyMmloymD0wbnKNAH/lMz1
                                        MD5:AA7B919B21FD42C457948DE1E2988CB3
                                        SHA1:19DA49CF5540E5840E95F4E722B54D44F3154E04
                                        SHA-256:5FFF5F1EC1686C138192317D5A67E22A6B02E5AAE89D73D4B19A492C2F5BE2F9
                                        SHA-512:01D27377942F69A0F2FE240DD73A1F97BB915E19D3D716EE4296C6EF8D8933C80E4E0C02F6C9FA72E531246713364190A2F67F43EDBE12826A1529BC2A629B00
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.r.o.p.l.e.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):2357051
                                        Entropy (8bit):7.929430745829162
                                        Encrypted:false
                                        SSDEEP:49152:tfVcGO3JiR6SgT7/bOCrKCsaFCX3CzwovQTSwW8nX:pVcG2iRedsaoXSzeOwWEX
                                        MD5:5BDE450A4BD9EFC71C370C731E6CDF43
                                        SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
                                        SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
                                        SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):276
                                        Entropy (8bit):3.516423078177173
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUX7kARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny5ymD0wbnKNAH/lMz1
                                        MD5:5402138088A9CF0993C08A0CA81287B8
                                        SHA1:D734BD7F2FB2E0C7D5DB8F70B897376ECA935C9A
                                        SHA-256:5C9F5E03EEA4415043E65172AD2729F34BBBFC1A1156A630C65A71CE578EF137
                                        SHA-512:F40A8704F16AB1D5DCD861355B07C7CB555934BB9DA85AACDCF869DC942A9314FFA12231F9149D28D438BE6A1A14FCAB332E54B6679E29AD001B546A0F48DE64
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.l.a.t.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):2218943
                                        Entropy (8bit):7.942378408801199
                                        Encrypted:false
                                        SSDEEP:49152:8mwK3gH/l4hM06Wqnnl1IdO9wASFntrPEWNe7:863gHt4hM9WWnMdO9w35PEWK
                                        MD5:EE33FDA08FBF10EF6450B875717F8887
                                        SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
                                        SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
                                        SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
                                        Malicious:false
                                        Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):278
                                        Entropy (8bit):3.544065206514744
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXCARELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyy6ymD0wbnKNAH/lMz1
                                        MD5:06B3DDEFF905F75FA5FA5C5B70DCB938
                                        SHA1:E441B94F0621D593DC870A27B28AC6BE3842E7DB
                                        SHA-256:72D49BDDE44DAE251AEADF963C336F72FA870C969766A2BB343951E756B3C28A
                                        SHA-512:058792BAA633516037E7D833C8F59584BA5742E050FA918B1BEFC6F64A226AB3821B6347A729BEC2DF68BB2DFD2F8E27947F74CD4F6BDF842606B9DEDA0B75CC
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.a.m.a.s.k...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):2924237
                                        Entropy (8bit):7.970803022812704
                                        Encrypted:false
                                        SSDEEP:49152:mc4NEo4XNd5wU5qTkdC4+K9u5b/i40RKRAO/cLf68wy9yxKrOUURBgmai2prH:mJef5yTSoKMF//DRGJwLx9DBaH
                                        MD5:5AF1581E9E055B6E323129E4B07B1A45
                                        SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
                                        SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
                                        SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
                                        Malicious:false
                                        Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):286
                                        Entropy (8bit):3.5434534344080606
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXIc5+RELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxny4KcymD0wbnKNAH/lMz1
                                        MD5:C9812793A4E94320C49C7CA054EE6AA4
                                        SHA1:CC1F88C8F3868B3A9DE7E0E5F928DBD015234ABA
                                        SHA-256:A535AE7DD5EDA6D31E1B5053E64D0D7600A7805C6C8F8AF1DB65451822848FFC
                                        SHA-512:D28AADEDE0473C5889F3B770E8D34B20570282B154CD9301932BF90BF6205CBBB96B51027DEC6788961BAF2776439ADBF9B56542C82D89280C0BEB600DF4B633
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.a.i.n._.E.v.e.n.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):3078052
                                        Entropy (8bit):7.954129852655753
                                        Encrypted:false
                                        SSDEEP:49152:bSEjlpY8skyFHuj2yY0ciM9U2NCVBB4YFzYFw7IaJE2VRK+Xn9DOOe9pp9N9Hu:bfp5sksA3cimUVxV05aJE2fKaDOXdN9O
                                        MD5:CDF98D6B111CF35576343B962EA5EEC6
                                        SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
                                        SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
                                        SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
                                        Malicious:false
                                        Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):274
                                        Entropy (8bit):3.5303110391598502
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXzRELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnylymD0wbnKNAH/lMz1
                                        MD5:8D1E1991838307E4C2197ECB5BA9FA79
                                        SHA1:4AD8BB98DC9C5060B58899B3E9DCBA6890BC9E93
                                        SHA-256:4ABA3D10F65D050A19A3C2F57A024DBA342D1E05706A8A3F66B6B8E16A980DB9
                                        SHA-512:DCDC9DB834303CC3EC8F1C94D950A104C504C588CE7631CE47E24268AABC18B1C23B6BEC3E2675E8A2A11C4D80EBF020324E0C7F985EA3A7BBC77C1101C23D01
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.s.h...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):3611324
                                        Entropy (8bit):7.965784120725206
                                        Encrypted:false
                                        SSDEEP:49152:ixc1kZBIabo4dTJyr3hJ50gd9OaFxTy+1Nn/M/noivF0po3M0h0Vsm:ixcaAabT83hJLdoaFxTygxcoiX3M0iCm
                                        MD5:FB88BFB743EEA98506536FC44B053BD0
                                        SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
                                        SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
                                        SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):288
                                        Entropy (8bit):3.5359188337181853
                                        Encrypted:false
                                        SSDEEP:6:Q+sxnxUXe46x8RELpmlJ0+3FbnKf68dADryMluxHFpwwl:Q+sxnyO3UymD0wbnKNAH/lMz1
                                        MD5:0FEA64606C519B78B7A52639FEA11492
                                        SHA1:FC9A6D5185088318032FD212F6BDCBD1CF2FFE76
                                        SHA-256:60059C4DD87A74A2DC36748941CF5A421ED394368E0AA19ACA90D850FA6E4A13
                                        SHA-512:E04102E435B8297BF33086C0AD291AD36B5B4A97A59767F9CAC181D17CFB21D3CAA3235C7CD59BB301C58169C51C05DDDF2D637214384B9CC0324DAB0BB1EF8D
                                        Malicious:false
                                        Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.p.o.r._.T.r.a.i.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):274
                                        Entropy (8bit):3.4699940532942914
                                        Encrypted:false
                                        SSDEEP:6:fxnxUXGWWYlIWimoa2nRE3QepmlJ0+3FbnKfZObdADxp1RDWlVwv:fxny2WzIgN2RGHmD0wbnKYZAH+Vwv
                                        MD5:55BA5B2974A072B131249FD9FD42EB91
                                        SHA1:6509F8AC0AA23F9B8F3986217190F10206A691EA
                                        SHA-256:13FFAAFFC987BAAEF7833CD6A8994E504873290395DC2BD9B8E1D7E7E64199E7
                                        SHA-512:3DFB0B21D09B63AF69698252D073D51144B4E6D56C87B092F5D97CE07CBCF9C966828259C8D95944A7732549C554AE1FF363CB936CA50C889C364AA97501B558
                                        Malicious:false
                                        Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.s.i.g.h.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):3465076
                                        Entropy (8bit):7.898517227646252
                                        Encrypted:false
                                        SSDEEP:98304:n8ItVaN7vTMZ9IBbaETXbI8ItVaN7vTMZ9IBbaEiXbY:8ItwNX9BvTvItwNX9BvoM
                                        MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
                                        SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
                                        SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
                                        SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
                                        Malicious:false
                                        Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 4091 bytes, 2 files, at 0x44 "BracketList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):20235
                                        Entropy (8bit):7.61176626859621
                                        Encrypted:false
                                        SSDEEP:384:j3W3yGyjgbA8E0GftpBjEHvFLrHRN7pDAlI66Yv1:j3WFyAA8Pi6HVpDZ66c1
                                        MD5:E3C64173B2F4AA7AB72E1396A9514BD8
                                        SHA1:774E52F7E74B90E6A520359840B0CA54B3085D88
                                        SHA-256:16C08547239E5B969041AB201EB55A3E30EAD400433E926257331CB945DFF094
                                        SHA-512:7ED618578C6517ED967FB3521FD4DBED9CDFB7F7982B2B8437804786833207D246E4FCD7B85A669C305BE3B823832D2628105F01E2CF30B494172A17FC48576D
                                        Malicious:false
                                        Preview:MSCF............D................................?..................................BracketList.glox.................Content.inf....7r...[.... G.q..@...B.....?X!.A.......!........X..Vk.JK...Z..=......PD.....P....5...jp..+..T....b.)np5.7.....Zz........... ..!.....S......1....`....h......T?.Nq../......z....[..:..5f;....O...d.FxD...4...Z....[..a...w..W.[..P...5.]...6..."...+t].!...2\%%`Q.\..)...=>.)......a.$.2.,...2,.Lw.?..+..qf....h....T/B.....}T.E...'.%.....,.......X....b..gt.hPYc|.....a...j...=...{..a.`!8!..|...L.T..k..!,.R.z/W....{..,...+..w.m..sQ..7<x..B....?....\.)..l...d...}.....v..W.C..'=p1c.Z=.W.g.e....&wm..N,..K.T../.oV../=9.}.....".28...r.Q....dzj{....S...1m...x9_...2PXpa...Q.n.$z...c..SGq...k......}kPE..*...3.|.5A.>..6.......+)qCB....q....qNkGe...W]..o..Z...J.<.i......qq.8....q..BE.(...._h.U.\@3.F...KdO..=1j+....).*Q.|B..Z..%......LDYk....j.....{klDW..#CVy}...X..O!..}..s..&..DC.....tL.j..b.......[...n.'..1..Xc...9Q..gM.....n..3...v.....~.).
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 6005 bytes, 2 files, at 0x44 "HexagonRadial.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):22149
                                        Entropy (8bit):7.659898883631361
                                        Encrypted:false
                                        SSDEEP:384:b98FG/zdCbf7BOEawSi8E0GftpBjEPTFPxFLrHRN7S5ll7PK/pA2:N/zAbDae8Pi6PFPSRIA2
                                        MD5:66C5199CF4FB18BD4F9F3F2CCB074007
                                        SHA1:BA9D8765FFC938549CC19B69B3BF5E6522FB062E
                                        SHA-256:4A7DC4ED098E580C8D623C51B57C0BC1D601C45F40B60F39BBA5F063377C3C1F
                                        SHA-512:94C434A131CDE47CB64BCD2FB8AF442482F8ECFA63D958C832ECA935DEB10D360034EF497E2EBB720C72B4C1D7A1130A64811D362054E1D52A441B91C46034B0
                                        Malicious:false
                                        Preview:MSCF....u.......D...........................u....?..................................HexagonRadial.glox.................Content.inf.........[.....`........./.mT.T6...CP..z5...0.PcUmCUSUCU.Q.P.0..f............^...H..2e.[..8...ld......*F.%.j.w!R..NA.L............ .r..z....$&.........P.=.r...O...e..dfv_.i%.C....^......?..x...+d..].B.3..EU...|Cc..z.`lQp..fr.....8!;.8.p.ZwH\.........~..T.t..]..H.]..S.2..Vt.....r.H../..-8........!:.Y&..|A..J.U...-.%..k..U...4m.. .q../..b.8.vc~......_q1.?..Bh.v.....L..I.$I..s.".u.. Y....I^5.v...3.......].^)b.t.j...=...Ze~.O...|.}T.._9c........L....BV.^......X..?.....{.>.j..5.m...d.7........g[..f.nST...i..t..|.T.jjS..4p.Pxu..*..W...|.A)..|9;....H.e.^.8D..S...M..Lj.|...M.m+..H.....8.&-....=.L.....n.v..M.9...l....=r......K.F.j.(.(xD.3..r'9.K..-...5..Z..x....._....a[...J...`.b_a\\j.ed..\.3.5....S.T...ms.....E...Xl.y.LH=...}..0.T...04.4..B[..H.....B{B9.h..=.8Mn.*.TL.c..y.s.?.c9$l...).h).6..;.X../_>Pl...O...U.R..v.dy$A
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 4313 bytes, 2 files, at 0x44 "chevronaccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):20457
                                        Entropy (8bit):7.612540359660869
                                        Encrypted:false
                                        SSDEEP:384:KyeISBuydn5rpmp77G8E0GftpBjE/kFLrHRN7ngslI66YVj:KHISBvd5rpmFG8Pi6/6nK666j
                                        MD5:4EFA48EC307EAF2F9B346A073C67FCFB
                                        SHA1:76A7E1234FF29A2B18C968F89082A14C9C851A43
                                        SHA-256:3EE9AE1F8DAB4C498BD561D8FCC66D83E58F11B7BB4B2776DF99F4CDA4B850C2
                                        SHA-512:2705644D501D85A821E96732776F61641FE82820FD6A39FFAF54A45AD126C886DC36C1398CDBDBB5FE282D9B09D27F9BFE7F26A646F926DA55DFF28E61FBD696
                                        Malicious:false
                                        Preview:MSCF............D................................?..................................chevronaccent.glox.................Content.inf..O.$N...[.........B.....?.....$Zy..Zkr...y<.....Di-.aVX/....h..-.~........#.../.Fz....T...p....A..eHMe[..p...=................f..../%o......F@..=..$.B!....}.0..g..^vlI......f.W.F...Nm..2`...)...,.HL4.nsl.F.ir.k..e.!^.j2.v.iT....t...*..!h..Y...2Q..-.x.,.Xj.U.cj,....9.....)..W..n3f.......(cH.D.4M.!.+..4..3r..y......|r..@.PD.R..#...F..nJAR..1{-.....u3..$..L.b+h....:lZ.>....q.?. ~l..^.%.m....a...cG.h.?.|.?7.'....b.G.4..'..A...o.Z...//..?...d..*.....C..Z.....]Yv.g.]..... .........]x.#=.../.7;R.j....G.....zq=O`[.'5g.D.u..)..../../.v.JmCW.da....3.f..C.z%...S=....;A.q.|....z.E.aRu........ k..J"+.f.S.@.........eD4....\0..t./U..%.H..........M:..U.......J...Z..H.DG..u^..D..P....`.^b.........`c......#.....c.?...#..C.V.&.'..f.'...f.[..F.O..a...&..{TiXg4; .X."..0...B.#..^..........N"..w.@f...gd.S..K.....E....ZR...;.twR>.z.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 5213 bytes, 2 files, at 0x44 "rings.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):21357
                                        Entropy (8bit):7.641082043198371
                                        Encrypted:false
                                        SSDEEP:384:zdx+NRrogu6fzCI7Th7G8E0GftpBjEzZq4FLrHRN7/Oll7PK/pB:/+NRrFf/G8Pi6zZb/GIB
                                        MD5:97F5B7B7E9E1281999468A5C42CB12E7
                                        SHA1:99481B2FA609D1D80A9016ADAA3D37E7707A2ED1
                                        SHA-256:1CF5C2D0F6188FFFF117932C424CC55D1459E0852564C09D7779263ABD116118
                                        SHA-512:ACE9718D724B51FE04B900CE1D2075C0C05C80243EA68D4731A63138F3A1287776E80BD67ECB14C323C69AA1796E9D8774A3611FE835BA3CA891270DE1E7FD1F
                                        Malicious:false
                                        Preview:MSCF....].......D...........................]....?..........{.......................rings.glox.................Content.inf..|^.....[......P........<.$.."..0R..xa.Ax#B..d... ....K,.....^.H.....H.........&.j.\f.. ..,....,..!k..R..e..!...E...........................><.RB.....~h...........Q................g..M|,...x.....qV7.u..\...F-N.{-..X..&Zig.~..{.A.p.Z...X..{,-n............`$.%.ND.....>].6cvZ.%d..*a.$..-.K.Hf....L..;.#...H....U,........P.@.*-$C.,.g...%YJE..$.jP........b...Y<..[U...MF]F.K...1... x.}3w.o.#,.}T.....w5+...=.=...c.F^....OM.=.......G_{n.*...WC.w!......{/.~.}..s..6_......)..Xy...4.....<..XZJ........#~._i....%..fM.V.?.q...q.....7...B..sVt...(.:..c....~.e...kGZ...C..(J..o...`...?.)-.T.l....&...gR.$.....g.:...2.e%F.....x....z0...K..a8B...........D..]....7....~.".DR...r)...}b)e.>.\h~f...(}.c........Q...o5H.........C.KC.(.L.l................R..a.pg{..\.......-b........}.C......qTS..%..r.lG..Q.1..Z.>a.D...tC..LV...Rs.C.M18x.:......%O.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 15461 bytes, 2 files, at 0x4c "gostname.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31605
                                        Entropy (8bit):7.820497014278096
                                        Encrypted:false
                                        SSDEEP:384:7SpOUxgQ9gFodHZktfHa2TSmcAg76j8/xorK0JoZgbA8E0GftpBjE2PzFLrHRN7S:OngHltf7Bcp/xoB3A8Pi625D8RA54
                                        MD5:69EDB3BF81C99FE8A94BBA03408C5AE1
                                        SHA1:1AC85B369A976F35244BEEFA9C06787055C869C1
                                        SHA-256:CEBE759BC4509700E3D23C6A5DF8D889132A60EBC92260A74947EAA1089E2789
                                        SHA-512:BEA70229A21FBA3FD6D47A3DC5BECBA3EAA0335C08D486FAB808344BFAA2F7B24DD9A14A0F070E13A42BE45DE3FF54D32CF38B43192996D20DF4176964E81A53
                                        Malicious:false
                                        Preview:MSCF....e<......L...........................e<...?...................;......................gostname.xsl."...............Content.inf.[.......[...>..|..32.E..o`h....W.>.^...v..5...m.w.$.U..U......m.mu...'4....m`.9F.. ...I..PTS..O.D...GM#...#CUE.`.`%n..N...G,.~..+.6cv.L...G.m.Y..vy.....Yh9/.m,..wtw..;....Ka.a.{.\...'.....<X....%)...G..d......R./..4$..32..@....f.h....w..ov.}w..[.....{.v.......dr..&w#G..$3.zI&f..(C..L.z5J... .`...!.!4. ...!.` .$........w.J.X7.w_..@.w..f]=.C.....I-....s.s_.x...~..A... ...z...nM..;....Z....vt....6...~.w.....*x.g.h.T.J..-.3=....G.n..ti.A...s...j$.Bf..?......6.t.<j...>.."....&=BO?w.uN.o.t.-r..K....>C..^G..p...k...>.xZ.[fL..n.."].W#...|.i.0W.q.F: ..<#w......w....s....."...n.qu.../rI.....q....P~.B..|b?.N.}..MyO..q..:q.7..-~.xa.S...|.....X.....g.W.3.mo..yy.GG.s>....qy....r........#.F.P..A.......A....b.2..14.8.i6..w.S...v~{0z.<.Z...^!.;2mSV.i....{...U...+...r.;...h.++..T6.a...$....j5F+..1t....b......|.Q\d-.S..2... ......Y..A...s....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 3749 bytes, 2 files, at 0x44 "TabbedArc.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):19893
                                        Entropy (8bit):7.592090622603185
                                        Encrypted:false
                                        SSDEEP:384:v3Zh3VlkpSIcgbA8E0GftpBjEmm3UFLrHRN7GYvlvQyUTL2mTAp:v31qp/A8Pi6mUqGGvU+mcp
                                        MD5:EF9CB8BDFBC08F03BEF519AD66BA642F
                                        SHA1:D98C275E9402462BF52A4D28FAF57DF0D232AF6B
                                        SHA-256:93A2F873ACF5BEAD4BC0D1CC17B5E89A928D63619F70A1918B29E5230ABEAD8E
                                        SHA-512:4DFBDF389730370FA142DCFB6F7E1AC1C0540B5320FA55F94164C0693DB06C21E6D4A1316F0ABE51E51BCBDAB3FD33AE882D9E3CFDB4385AB4C3AF4C2536B0B3
                                        Malicious:false
                                        Preview:MSCF............D................................?..................c...............TabbedArc.glox.....c...........Content.inf.;....Y.[.........B.....?.T..ZD...........^C...U.R<Z....z+.I.....Z..-.V...f.....lB..\P.....=.-p....w ...\.kD..x'v..T..A..............".8...d.........FD.ZL.h..T...bp.)9B.v..i..VX...&..\..7.s..qy...l........Rty.Y...rU..>.9...8....L..\.^x.kDU.|TJ..{kN.G..E..$.kvy?.. mv......P..4.....q.1.6<u....e..dD...4.1E..Xi.5.=....1.P.c.K~S...YMO:.?..cL.g.tq\.(b1....E..0A.i..C...BT.m.S......:...}.&U..#QL..O.O../..K......=..........0a..O............BYP......>f.......iu...7.K..;QO~.t....%N.s.]>~#../7YN.....C..9.=cY.......y..U5.....,.....u.....#_..SG.`NR*.....?*..d.R.k.rX$...&.... ..h.4T.D^k-xA...............Hz..ep)e..4..P."fo Ne...o.....0n.Exr.........H..v...A.."..%)2......5...".}j.o8...E.HRQ;}.. .._L.+.jz....{.U..}...=B.o.^..vZ.:5.Z.M....y{\(...N..9...EB*MG...!N.vy..^...nE..2..@.;.4..C..t.4....h..O.8.=.m./...|Lu.|mCU..b.^.n39.h[M...%D{..w.1
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 3144 bytes, 2 files, at 0x44 "VaryingWidthList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):19288
                                        Entropy (8bit):7.570850633867256
                                        Encrypted:false
                                        SSDEEP:384:5ZII4Hf+7G8E0GftpBjCwBFLrHRN7bcClvQyUTL2mH:pG8PicgbcAvU+mH
                                        MD5:B9A6FF715719EE9DE16421AB983CA745
                                        SHA1:6B3F68B224020CD4BF142D7EDAAEC6B471870358
                                        SHA-256:E3BE3F1E341C0FA5E9CB79E2739CF0565C6EA6C189EA3E53ACF04320459A7070
                                        SHA-512:062A765AC4602DB64D0504B79BE7380C14C143091A09F98A5E03E18747B2166BD862CE7EF55403D27B54CEB397D95BFAE3195C15D5516786FEBDAC6CD5FBF9CD
                                        Malicious:false
                                        Preview:MSCF....H.......D...........................H....?..................................VaryingWidthList.glox.................Content.inf...O.....[.... v.q......R.....>.%i.I.HhD.V...qt.....'....N...!..aw$(J.%(..A..h......l|.D.p9`..Y09.:.u....p. :,.*.YD=0.p. ......w.........*..<..;.....u.."......7[....8.....?^........-..;q.|.....B....PJ....r.K#.#.0'...}.........+gpR...T....5.iu.^I...A\..gK....}..z.B.nT.../.m.......N....E'1.E.\..o.....W..R.#.#...8.7...R.SbW-...%......$.obj.F..W_@....sY!........s.O..."k. ..b....j....v...P.\....7d...|"J.T...2p..m.&..r..,2.).....X.`...xt].U...b.h..V.....|L..N.Z.O#....o...1R.w30.g..?;..C.T.:$..MGY.C"i\.f..#..<.k...m..s.w. ..Ga].....wt.h|.Ta<.......(SO.]9.%a..Z... r._JH.=O...P.9a.v.....Kj.".T...m...4.?...F...$...y.....hbW.UA..u.&)....py.C{.=t.....n...}|H3A9.=..W..JJ..y./Y.E.M9..Z..w. .HB.YoIi..i.e..9;n...SpHw,....f....d>..g.m..z...... ...f...KP.M..U.....~vFD.fQ.P?......2!.n.....`@C!G...XI.].s,.X.'...u.E.o..f
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 4410 bytes, 2 files, at 0x44 "PictureFrame.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):20554
                                        Entropy (8bit):7.612044504501488
                                        Encrypted:false
                                        SSDEEP:384:zEAH676iPi8+IS5iqn7G8E0GftpBjExDxIHFLrHRN7Ke/ll7PK/pGaz6:zEhG8+ISrG8Pi6xDxCKoIGaz6
                                        MD5:486CBCB223B873132FFAF4B8AD0AD044
                                        SHA1:B0EC82CD986C2AB5A51C577644DE32CFE9B12F92
                                        SHA-256:B217393FD2F95A11E2C594E736067870212E3C5242A212D6F9539450E8684616
                                        SHA-512:69A48BF2B1DB64348C63FC0A50B4807FB9F0175215E306E60252FFFD792B1300128E8E847A81A0E24757B5F999875DA9E662C0F0D178071DB4F9E78239109060
                                        Malicious:false
                                        Preview:MSCF....:.......D...........................:....?..................................PictureFrame.glox.................Content.inf........[.... '.q..@.........<./..+./. ...."o.o./..{^a.7^.D.HA....^J... ...........T%q..b...+pz.n.=....jT.+M..=H..A...py.3.........H...N...[..%..~....>.%....3.r...wx.....0.....7..94..2..45..7f.......D.. ...[...f.:H..../N..4.....8.....:x.I....u|.`."...\..N..%.M#..^v$.*....T.m.....?.-.wki.X..8..F.G..Y.^8...-....+.&.+&.No...e!.#.8.....YF.......<w.....=.Q.S..7....MW....M..9A.3..c..L....|.E-Y....]n".|....b9..l@.d.T...a.f...~.&k.[..yS..q..]L}..)w.....$.@..v...[9..X....V...a.NK....m9.5.....Kq.;9`.U.e...8.<..)Y.H........z.G...3n.yWa.g.>.w!e.B8:......f..h..z....o.1<.RT..WK...?g .N..+..p.B.|...1pR_......@...a....aA......ye..8...+M.l..(.d..f.;....g........8R.\.w.:ba....%...|p....`lrA.|....a.U.m=ld......7....#..?Dq..D.....(.5.K.a..c.G..7..]hF..%:}......}J.j$.....4...l];..v>.&j........Y.vk..$1.@X$...k...9..?...z..![..../...).a.=....aZ^.3?....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 9170 bytes, 2 files, at 0x44 "InterconnectedBlockProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):25314
                                        Entropy (8bit):7.729848360340861
                                        Encrypted:false
                                        SSDEEP:384:75V23GNhfG/YvmBqWDP7G8E0GftpBjEB1vrFLrHRN7mKll7PK/pRU0:LS/Yvc7TG8Pi6BLm6IS0
                                        MD5:C47E3430AF813DF8B02E1CB4829DD94B
                                        SHA1:35F1F1A18AA4FD2336A4EA9C6005DBE70013C7FC
                                        SHA-256:F2DB1E60533F0D108D5FB1004904C1F2E8557D4493F3B251A1B3055F8F1507A3
                                        SHA-512:6F8904E658EB7D04C6880F7CC3EC63FCFE31EF2C3A768F4ECF40B115314F23774DAEE66DCE9C55FAF0AD31075A3AC27C8967FD341C23C953CA28BDC120997287
                                        Malicious:false
                                        Preview:MSCF.....#......D............................#...?...................#..............InterconnectedBlockProcess.glox......#..........Content.inf...<.:#.$[......O..........5f.P.5CU..6..jT..U..U..UM.T.........h................-... .......6...`.....G...........'.,DN:........... "..4..1u.....%.u..{{,....@lp..}..`.......Z...K.....Z..... Z4.<?..C.BF.....k.!Hl...]...Tvf..g....)...vny6.'..f....Z.R.`.......+....!..!.....:..4fj....."q..f..E..^!k.....M.c....R...B......g...~.........o.'.7,.e.,..7.R.e,(.+..+:....Q....f...P.H.I..U.....Jl...l...z.]7...C...<...L.,..@...i.{..e]K...2..KRW..7.-'.G.l!.n7..J.v.C...%/.....q...@..l..e..$..N..sg8]oo.(q(_.?.X.s...Ua..r0...Rz.o.eT.j...b*..}",n.qou..M.[.;%../c.x.4.z.2*.U.]..D...h...-R.$.=\3..P......N.mP......J...}BPn...g]d.5k..C.ee.ml...\.g...[.......<..6$.%.I#S9..I...6.i........_..P.n....c$.3..zw.hF......_{.+...o...[.&........&...M..m.....;....0....D7...4nQ.=/.._`._.nh.D.m..h.+....8..p..q.4.w.\...iy...*...lN6F..c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 15418 bytes, 2 files, at 0x4c "harvardanglia2008officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31562
                                        Entropy (8bit):7.81640835713744
                                        Encrypted:false
                                        SSDEEP:384:yhsBScEWkrljntbzuMmWh7ezPnGgbA8E0GftpBjohgsRFLrHRN7ybll7PK/p:MsBScwtnBmWNeTzA8PiuWsvyDI
                                        MD5:1D6F8E73A0662A48D332090A4C8C898F
                                        SHA1:CF9AD4F157772F5EDC0FDDEEFD9B05958B67549C
                                        SHA-256:8077C92C66D15D7E03FBFF3A48BD9576B80F698A36A44316EABA81EE8043B673
                                        SHA-512:5C03A99ECD747FBC7A15F082DF08C0D26383DB781E1F70771D4970E354A962294CE11BE53BECAAD6746AB127C5B194A93B7E1B139C12E6E45423B3A509D771FC
                                        Malicious:false
                                        Preview:MSCF....:<......L...........................:<...?..................D;.......V..............harvardanglia2008officeonline.xsl.L...............Content.inf.Vu......[...E..o..3D.5..nF.A..+.e.....6r..f........M3...-.s.m.... $r.b.!.q!.....G...0.\.......fd......%m...'1Y..f..O...*.#.P.,{..m...|..ww.{.m...f...n%...,..y...0y...8.Q...`.../.q....a...',.V......8.7..8t..................6.]..6..nw..ynm..-l.Y..,.I?..$....+b9$E!S@"..) .4........H...lA...@!a.F.l$..0#!.....n&.5j.t+..1f|.+....E.zDk.l8.+<q.^.........\5.l..iT.9...........Y..6.^,.o.bn.E*5w..s.../...W.gS..j9..'W.F......].4\Mzz..Td..Ho..~.Q...Z..D..O.JP..m..s.j.:..........y._.....#.*.rD....60.\!y........p.o3,..Ub,......[[L.{.5.....5.7UDB9.{;;g.z.z..jM.G.MY.oe.....(r..B6..CV.7Fl.Z/....-.O.vY.c...-..........b.T)3.u..f~x2.?.8.g.x.-.....Qt_...$e.l..jtP..b....h..*.sW0.`.....c...F_....t.........LC..*5I.X$^.;&....#.._\J..........;..wP..wX.qy.qs...}46..fK.XN.&0........k1....8...............'t.......}.......O_.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 15327 bytes, 2 files, at 0x4c "sist02.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31471
                                        Entropy (8bit):7.818389271364328
                                        Encrypted:false
                                        SSDEEP:768:eNtFWk68dbr2QxbM971RqpzAA8Pi6TlHaGRA5yr:eNtEkpGSbuHAkP7TlHaGq54
                                        MD5:91AADBEC4171CFA8292B618492F5EF34
                                        SHA1:A47DEB62A21056376DD8F862E1300F1E7DC69D1D
                                        SHA-256:7E1A90CDB2BA7F03ABCB4687F0931858BF57E13552E0E4E54EC69A27325011EA
                                        SHA-512:1978280C699F7F739CD9F6A81F2B665643BD0BE42CE815D22528F0D57C5A646FC30AAE517D4A0A374EFB8BD3C53EB9B3D129660503A82BA065679BBBB39BD8D5
                                        Malicious:false
                                        Preview:MSCF.....;......L............................;...?...................;......g...............sist02.xsl.................Content.inf....!....[...=.rF..3U.5...g.i?..w.oY..If'.......Y.;.B.....Wo.{T.TA.~......8......u.p....@Q..k.?.....G....j.|*.*J69H.2.ee..23s..;3..i..L.,...0se.%J........%.....!.....qB...SC...GAu5.P..u7....:.|.$Fo............{.......v.v.g..{o....e.....m.JeRG..,.%.1..Lh.@8.i.....l.#.HB`B....C......D@....?....P?..................|.9..q.......9.n.....F...s,....3..Q..N......y......_i..9|.<w...'q.Tq...U.E.B...q.?.4..O(_O.A.......*jC.~.21.7.....u.C...]uc.....-.g.{C~9q.q.1.1...4..=.0.Z.^....'../....-.6.K.....K...A#.GR..t.@.{.O.......Q5..=....X...^...F3.e.E.Z..b+R..?Z..0T1.....gQz.&....%y=zx.f.....6-*...u.Rm..x<...?...!g@.}..).J...:*...9.s&.v..}..'...\..Sd..F...........kQr.....h..3..1....B...B{M...%O.59.\.#....s/.pE.:}...k_.P.>.zj....5|.9+....$M..L........(...@#.....N.....N.*..........E..7..R$.:9!r>7.....v...>..S.w....9..]..n.w.;&.W..<r\S....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 6196 bytes, 2 files, at 0x44 "ThemePictureGrid.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):22340
                                        Entropy (8bit):7.668619892503165
                                        Encrypted:false
                                        SSDEEP:384:GByvLdFHny7G8E0GftpBjE8upFLrHRN778lvQyUTL2mm2y:Oy3HkG8Pi6887mvU+ma
                                        MD5:8B29FAB506FD65C21C9CD6FE6BBBC146
                                        SHA1:CE1B8A57BB3C682F6A0AFC32955DAFD360720FDF
                                        SHA-256:773AC516C9B9B28058128EC9BE099F817F3F90211AC70DC68077599929683D6F
                                        SHA-512:AFA82CCBC0AEF9FAE4E728E4212E9C6EB2396D7330CCBE57F8979377D336B4DACF4F3BF835D04ABCEBCDB824B9A9147B4A7B5F12B8ADDADF42AB2C34A7450ADE
                                        Malicious:false
                                        Preview:MSCF....4.......D...........................4....?..................1...............ThemePictureGrid.glox.....1...........Content.inf....K..5.[.... V.q......B.....?.h.i.J.D...Z...>.....i~...A...Z....H.hy.D..X.....>...L.I..`. z w0}.K`.C{h....W\../.U..p\%...B...;............9..8.^M.....].lP.p...|..?..M....E..S.`..-n........Q'.'.o..C}=..?`.bQ...J"0f.. ....k3n..F.Pu..#...w].`<...."D.].-.#+):..fe..=<.M...4..s.q.f._.=.*T.M..U.[R.kbw.,......t6_I...~.X..$_.q....}2..BR...).[...<.l.3........h%....2.$`>..hG...0.6.S......._3.d~1.c.2g....7tTO..F.D.f.Y..WCG.B..T....Gg&.U'....u.S/......&6w..[bc.4....R.e..f.,....l."........I....J.=~...$x.&2...+,-.;.v.'.AQ.fc...v._..rZ..TYR...g?..Z..!.3mP dj...../...+...q.....>..../...]P.z?DW&.p..GZ....R5n......,..]{].0m.9...o.{...e."...8VH....w"%;.g\.K..p.}....#r.u..l.vS...Y.7U.N*-E@.....~....E...x.....C.......{NP....5Ymk.*._.K...Z...f..;.......b.....,._@B..\.S..d.'\rs..].}.5"XJU.J..'.zk}.+P.)C.X.?9sx.D....(K....P^N_D...Z.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 10800 bytes, 2 files, at 0x44 "ConvergingText.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):26944
                                        Entropy (8bit):7.7574645319832225
                                        Encrypted:false
                                        SSDEEP:384:sbUX16g8/atF4NB3TJOvqeMRD/8svIZj/OwgbA8E0GftpBjEYwFLrHRN7mYll7PY:sbhg8yY4nMZK2hA8Pi6Yum4IVR
                                        MD5:F913DD84915753042D856CEC4E5DABA5
                                        SHA1:FB1E423C8D09388C3F0B6D44364D94D786E8CF53
                                        SHA-256:AA03AFB681A76C86C1BD8902EE2BBA31A644841CE6BCB913C8B5032713265578
                                        SHA-512:C48850522C809B18208403B3E721ABEB1187F954045CE2F8C48522368171CC8FAF5F30FA44F6762AFDE130EC72284BB2E74097A35FE61F056656A27F9413C6B6
                                        Malicious:false
                                        Preview:MSCF....0*......D...........................0*...?..................t,..............ConvergingText.glox.....t,..........Content.inf..C..)t-[.....@.........=...xxA. ...E^....x.x.^.......x..^^...DF.......s..d.P.....5.;..]...2.t.w.....O9.G..;.'.T....@I.,.q.u.3..P...9... ....`J.......g.(....).,.h0.....$.3..;.._.....~.de.jj.....U..K.0....`.@.H.1.x.Z.@..q....?....x.wW.....+am8A".....I..)..]...s..-z.2S+|.Cb.t6f],.n.LV......OVg....O.at|..-..x.....:....]s...u..g}.P..v.3....^.".%..%...#.2.....l00...n.......r8.p.....^.....n.)..,..t.^$b...b.q.W...F..R...n.-.+..'........Aw=._OwH....8.:s..{.#..{N.hW..`.._........Wy....>U.?....-.8tg...=..y..@.,.v|......l...t..l#{...H....9..|......~...De..#@y.&K....U...q.c.zK..D.<pV.....Ql..&Y...=#...w....r.`#2....Ug.J(..T...KmW.@...!....j:......M......!..E.7#s.t..F.aU..N....-.i......|w.lr..G.n.,.......=Kl.-m.?F.....v]?.......{q.U.t...<.|..u.....3R.`.t.T.>;v.....KQ...S...7..1...N.kN.y.)v.....3H:..D.{.+.(......u..^W&.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 12767 bytes, 2 files, at 0x4c "ieee2006officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):28911
                                        Entropy (8bit):7.7784119983764715
                                        Encrypted:false
                                        SSDEEP:384:WnJY165YD0tPYoCKa3HueqRyzVscLk1Yj2GjcgbA8E0GftpBjE2kWTpjFLrHRN7N:X4rtPzCK6uRoljXBA8Pi62ZphL0HRA5p
                                        MD5:6D787B1E223DB6B91B69238062CCA872
                                        SHA1:A02F3D847D1F8973E854B89D4558413EA2E349F7
                                        SHA-256:DA2F261C3C82E229A097A9302C8580F014BB6442825DB47C008DA097CFCE0EE4
                                        SHA-512:9856D88D5C63CD6EBCF26E5D7521F194FA6B6E7BF55DD2E0238457A1B760EB8FB0D573A6E85E819BF8E5BE596537E99BC8C2DCE7EC6E2809A43490CACCD44169
                                        Malicious:false
                                        Preview:MSCF.....1......L............................1...?...................0......"}..............ieee2006officeonline.xsl.:...............Content.inf.........[...G."...3$pE...G B....m3o[...I2&.f.,\..........}.n..{..e.8!^.3.A@...x..... .D.52gU..]..."..N8....s..CS..J3..HV...m...y..o....F.z......V.j._....=~k.....'.dY........1........#...d13.g.&C...C.xw.`f.hf..........]M....m.m....ud...,+.H~..cL...e#;(RI...eA....I.b...E...2..(...$.j...L...$..A....'[...H9..&..G.Q....".M.yl....]..?j%+....O~.*....|.se...K\.B"W..F.5.......=s...l.Y...K..yN.TBH[...sTWR.N.d...WEa....T.d.K.^sauI......m..s=.,qso5.b.V.s.]..9..,k4.\..L.;D...........;r.C...7.w.j..:N8.V6..a.3..j:A.mA..To..$.5....:./..p.x.3.=..__...8.EB.K.*..].-."..5-XU..J.....=o..K.Wavg.o].z.9.gk.._.........MZ.<.5............OY.n.o...r.9v.c.......[n.[..D...d..}.j.....LB,]_.9..St.@..C....\...^....-&.njq..!P....G^.....w.7.p~.......M..g.J............t1......q.w.rx...qp.....E.........-...2..G.........z.]B........d....C.@...@.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 5647 bytes, 2 files, at 0x44 "RadialPictureList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):21791
                                        Entropy (8bit):7.65837691872985
                                        Encrypted:false
                                        SSDEEP:384:PWew5RNDcvPgbA8E0GftpBjE0hsyaFLrHRN7BD9lI66YR:P3GRNDcEA8Pi60hsyABDo66g
                                        MD5:7BF88B3CA20EB71ED453A3361908E010
                                        SHA1:F75F86557051160507397F653D7768836E3B5655
                                        SHA-256:E555A610A61DB4F45A29A7FB196A9726C25772594252AD534453E69F05345283
                                        SHA-512:2C3DFB0F8913D1D8FF95A55E1A1FD58CE1F9D034268CD7BC0D2BF2DCEFEA8EF05DD62B9AFDE1F983CACADD0529538381632ADFE7195EAC19CE4143414C44DBE3
                                        Malicious:false
                                        Preview:MSCF............D................................?..................................RadialPictureList.glox.................Content.inf....8....[.... $nq......C...../U..........a......S.Q...Q....j............(..z,.g.........^...Y..D... #i.TH5.<.=N..$..7.p".7.............`.3..1~,=,(.d8.Z.1....4'G.....!W^gClf._j.-N..&k.....Y3` =.(S..B^...i.zB.U....0O..h...I.(.......L...5.X.8.Sc<=>w.=.?&.....mR.......x.......mpW.T..^.FU...SN.C)......vsa.,x......,....E..i>..[g...#t...M..GR.9..$/4.:..q.bc9..x{bC.0..K.)..t.Y.&.v.d.16.B..c..or..W.,.B.........O.0..k.v........*F+..U.w...d...o8......A).}...#......L.!?.U.r.^.$...e.(..PG)8..+.9.5.l}.)..b.7+. 4....-.lC...|..j..Q.,.....7.W...|;j...%...:...|H..........<..%...K.....Fy.q$.k..}..8.9.M.u.?$].......r.....e.|..._..iT.;Dq5[....f.s..P.......e.T....!Y{.....t.wm..A..w-..7...3..T.:8.4.a[.Oo.. V.l.@.}..........E.&..J.....+..+.9)9<.._R.Hb.....V..Qu....:v.t.Li.0..J..V..b...!..N....-mD..c..(.[&o>.M.b..H.q..lk../..........W.8..z..B...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 4967 bytes, 2 files, at 0x44 "TabList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):21111
                                        Entropy (8bit):7.6297992466897675
                                        Encrypted:false
                                        SSDEEP:384:wWZsOvbMZGgbA8E0GftpBjEtnFLrHRN7Dfll7PK/pirk:xZRvuzA8Pi6t9DPISk
                                        MD5:D30AD26DBB6DECA4FDD294F48EDAD55D
                                        SHA1:CA767A1B6AF72CF170C9E10438F61797E0F2E8CE
                                        SHA-256:6B1633DD765A11E7ED26F8F9A4DD45023B3E4ADB903C934DF3917D07A3856BFF
                                        SHA-512:7B519F5D82BA0DA3B2EFFAD3029C7CAB63905D534F3CF1F7EA3446C42FA2130665CA7569A105C18289D65FA955C5624009C1D571E8960D2B7C52E0D8B42BE457
                                        Malicious:false
                                        Preview:MSCF....g.......D...........................g....?..........}.......................TabList.glox.................Content.inf....t....[......@..C...../.U5...........6...`.....T..>3.................=..09`..t......a..Y..BI.Z....=.'0...%...T..........H...>.:A.r......n..p...Pf.h...I.8... ....M.]&.#.vv'.....[c......g....>"......<c..f....i...sb!Z..iu<.%|......q.....G28.h-...7.....W.v...RtdK..F~.0.3.'.e..b7.c......a.3.....a\..]...gp8.+.u/}.w.qF........8.=.=|....\~..S.-q}]0...q.B.H.^J...!...a'.2Tn!..."..%........=.e_-.....{o..%o...a`.w..L.5..r.....e.8...pO..RE.Wgr..b.%.E...O.......8s...E....Um].C..M.....[...H.FZ..4...eZI.$..v.3<]..r....B..............8i......e<.D...Q4.q.^S.....H.b.......r.q..0o.......2..PP,."...JI...xU`.6f..K..Q9.Q..h..t....AI.S6...7............X..`dv..r..S....),7ES....#.....(...\.nh...X.ps%l..F...."<_....q....v........_.e.....P.........|&..fi..4..@..^0..v.]7.......^. ."..}(...w.g.X...=<....p.......L...P..XV....@:....N...Y....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 19375 bytes, 2 files, at 0x4c "turabian.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):35519
                                        Entropy (8bit):7.846686335981972
                                        Encrypted:false
                                        SSDEEP:768:2LFougzHaUdBKUsM+Z56zBjA8Pi6bo+ld8IX:MFodzHaULR9P7bo+l6IX
                                        MD5:53EE9DA49D0B84357038ECF376838D2E
                                        SHA1:AB03F46783B2227F312187DD84DC0C517510DE20
                                        SHA-256:9E46B8BA0BAD6E534AF33015C86396C33C5088D3AE5389217A5E90BA68252374
                                        SHA-512:751300C76ECE4901801B1F9F51EACA7A758D5D4E6507E227558AAAAF8E547C3D59FA56153FEA96B6B2D7EB08C7AF2E4D5568ACE7E798D1A86CEDE363EFBECF7C
                                        Malicious:false
                                        Preview:MSCF.....K......L............................K...?...................J.......@..............turabian.xsl."...............Content.inf._.......[...T.....C4.5...E0B.]...+.-f....rc.[52.$...a..I....{z...`hx.r...!.. $...l..\....#3EF..r..c;<p...&n.\b..K..0Y..c+.2...i..B..wwY..77,...........}.q.C.......n..,.....prrx.QHy.B#..,.'....3....%1.``..hf...~...[.[n.v.s..y.vw....;..s.G293G&H....$E......m.&^..iy/.4.C...D...".(H&..&.I4._...!...... ........q.k1.d.....qc.3.c.....;.5.......y}...}&...+.WAN.,zVY.Q....V.Tz........g..H..c...E2jY...4g?.yf<....V.M.s.$..k.Id....+..?..._.\.s.k..9..I%;.yWQ..S..]..*.n<.7........=......"Q.*E.....MG..j.Yt..!U....Q.j...v.h-.~b..e&.......;...\.....:.....=..Xv1&q........6\...xw.%*.VdS..H...o...s.....+..%[../>.t..I....F.....".G|.....=....[..S..3..a.C.ZZ...tK.6N..b........)>........I..m..QE.M.nv.MVl.....vCG>,.suP.gqo.rr....J`m....J.b..},[F*....e.A.]..r....C4.?JJs6..l.].9...Q.B.~.......\d%.X ...8A....rH....&?#...^.....4.h.{>
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 14813 bytes, 2 files, at 0x4c "iso690nmerical.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 7 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):30957
                                        Entropy (8bit):7.808231503692675
                                        Encrypted:false
                                        SSDEEP:384:rKfgT03jNkAFbgUQWtxq9OGh1bBkd/1MVHb5iVOdMgbA8E0GftpBjEl8tFLrHRNF:r303jOrUQAkfhopWHbA8Pi6l8zuUIq
                                        MD5:D3C9036E4E1159E832B1B4D2E9D42BF0
                                        SHA1:966E04B7A8016D7FDAFE2C611957F6E946FAB1B9
                                        SHA-256:434576EB1A16C2D14D666A33EDDE76717C896D79F45DF56742AFD90ACB9F21CE
                                        SHA-512:D28D7F467F072985BCFCC6449AD16D528D531EB81912D4C3D956CF8936F96D474B18E7992B16D6834E9D2782470D193A17598CAB55A7F9EB0824BC3F069216B6
                                        Malicious:false
                                        Preview:MSCF.....9......L............................9...?...................8......1P..............iso690nmerical.xsl.................Content.inf...A@...[...5.....33.E...P.../..........5sv.]3srm8.T.=.......}.v.T.. ..4IH.r.%Z.(.q.\+K..[,....E....A......#CEF..}p..Y/s$...YKI.#M.?.t.1#C....I..v.vn...-...v7../S.m.Ma.....!.Y....4.......3.3....c&R9..%......(J..BDMI.>7J.....".....}.w.}w.wg.v...^.n.{....{f.mlI..%.#..I..S....D..QJ U......4........K.(@....DH.....}...8;..z...&0%e..G.OAM..x.3......\....zS9....}......89.B...e.W.p{;.....m.m3...}....../...q.~..;.,..".j.g..^N............iC.../|...g.=..9.Q].Gf.....QA....74..v.....9.n[......0.}..jo{y./.2..Ym......;u...b.(Jz^.....~..uM...{s../..#.)n2..S.S.c..6)U.V....!.'R.......P.S.D..S.p/......D.......{......?.u.",...Mp._....N..+..=Y#..&0w....r.......$.xwC......P.e7.>O....7....].y%q^S'....*.C.`.?..}Q..k../u.TK...y........S...{T.?......[.H.'L..AS.Y.|*..b...J.H-.^U>'9..uD[.".b[.l.......o..6.L).h.B0RJa.b..|m:.):......F
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 17466 bytes, 2 files, at 0x4c "chicago.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 10 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):33610
                                        Entropy (8bit):7.8340762758330476
                                        Encrypted:false
                                        SSDEEP:768:IlFYcxiahedKSDNAPk5WEEfA8Pi6xnOKMRA58:2JitdKsNAM5WBDP7xOKMq58
                                        MD5:51804E255C573176039F4D5B55C12AB2
                                        SHA1:A4822E5072B858A7CCA7DE948CAA7D2268F1BB4B
                                        SHA-256:3C6F66790C543D4E9D8E0E6F476B1ACADF0A5FCDD561B8484D8DDDADFDF8134B
                                        SHA-512:2AC8B1E433C9283377B725A03AE72374663FEC81ABBA4C049B80409819BB9613E135FCD640ED433701795BDF4D5822461D76A06859C4084E7BAE216D771BB091
                                        Malicious:false
                                        Preview:MSCF....:D......L...........................:D...?..................XC.....................chicago.xsl. ...............Content.inf.!..B...[...H."m..3C.6...WP!i/Z..vn._...^omvw+...^..L.4o...g..y......^..x...BH.B.K....w.....F........p ./gg.h.0I',.$..a.`.*...^..vi..mw..........K....oQ............P...#...3.......U(.=...q.~?..H..?.'I4'.......X...}w.vw.....f.n..f{3.....-....%dK&q..D.H.Z..h-..H.[$ %.."..e....1...$.............'.....B..%..4...&`S!DQ...M.......N~............S..'....M..4E.^..dej..i..+.`...6F%sJ....Q..d.(*.s.Z...U-5Eh.s.CK...K..X$......j..T.?.`.|...=..R...-7...*...TU.....7a...&I.noOK|.W.R-+S.d..rR.....{h.Y...)..xJ..=.XM..o...P'.I4m..~I..C..m.....f.....;{Mzg+Wm.~...z...r-.....eK...lj:^.1g5...7.h(T"..t?5......u.....G.Z<..sL.\{...8=t...Z...'tps.:...|....6.....S..X...I...6l.M.....aq.;YS....{:.&.'.&.F.l...\.[L.%.so\.v.Lo...zO.^^...p..*9k...).CC..F0>L...VUE4.......2..c..p.rCi..#...b.C@o.l.. E_b..{d...hX.\_!a#.E.....yS.H...aZ...~D3.pj: ss?.]....~
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 5731 bytes, 2 files, at 0x44 "ThemePictureAlternatingAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):21875
                                        Entropy (8bit):7.6559132103953305
                                        Encrypted:false
                                        SSDEEP:384:k73HRpZA6B3ulrnxtRT7G8E0GftpBjEdHqlFLrHRN7uhFlvQyUTL2m4c:k7XRgIkrG8Pi6dmuNvU+mp
                                        MD5:E532038762503FFA1371DF03FA2E222D
                                        SHA1:F343B559AE21DAEF06CBCD8B2B3695DE1B1A46F0
                                        SHA-256:5C70DD1551EB8B9B13EFAFEEAF70F08B307E110CAEE75AD9908A6A42BBCCB07E
                                        SHA-512:E0712B481F1991256A01C3D02ED56645F61AA46EB5DE47E5D64D5ECD20052CDA0EE7D38208B5EE982971CCA59F2717B7CAE4DFCF235B779215E7613AA5DCD976
                                        Malicious:false
                                        Preview:MSCF....c.......D...........................c....?..................................ThemePictureAlternatingAccent.glox.................Content.inf...3.....[.... .qq...........\<.^......o."......f.o...x.{..q..^.MH^...........{0.K....4pX.i...@6A4X.P.01d....'p.......zA.......... .......7.......a. `.=!@- ......>G.s.k~@.a.lfha:m....1...@.,G`....{....W..N..qs.......j.+TrsT.l.9..L...1+...d..-u..-.......).#u&...3......k.&C...DdZ.'.......8..<PF..r.eq.X6...u..v...s5.m.Q.l.G%.<.]....RV<...S..Dv..s.r.......dh.N.3-.Hf'.....3.GZ..E.kt.5......h...|...?!.L....~.)..v....:2.../F.,....o.qi.i7..E.|.mh.R_.@A.FO@i.....Feo...x.l...{E.\W9|V...=#..3..(......tP.:i....Ox.U.N...%6...p.6&.....<zh.z.|.<Z.?.k....y7m...F.Z$-.:.l.h...{T..7....?..T...d,r...z?../...`/Z......a.v@)....u......V..v.:.._.|.'..[..O.s.OAt-."b.In"..I...J*.~H.:-...?..uV....dZ;z:.l.{.E.,.Q..i]:.0r.I.y..f...../j.wN...^R.....u....>..}....f.f...]A..C~;/....%..^#..N.a..........99.....`.....%..iS....S......$....)
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 14864 bytes, 2 files, at 0x4c "mlaseventheditionofficeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31008
                                        Entropy (8bit):7.806058951525675
                                        Encrypted:false
                                        SSDEEP:768:ktH7oN/HbwiV+M+4Jc+5UrT3czi5uOHQA8Pi6DxUR/WTZIy:87sPEANXJc+eTMsuzP7DmN0ZIy
                                        MD5:E033CCBC7BA787A2F824CE0952E57D44
                                        SHA1:EEEA573BEA217878CD9E47D7EA94E56BDAFFE22A
                                        SHA-256:D250EB1F93B43EFB7654B831B4183C9CAEC2D12D4EFEE8607FEE70B9FAB20730
                                        SHA-512:B807B024B32E7F975AED408B77563A6B47865EECE32E8BA993502D9874B56580ECC9D9A3FEFA057FDD36FB8D519B6E184DB0593A65CC0ACF5E4ACCBEDE0F9417
                                        Malicious:false
                                        Preview:MSCF.....:......L............................:...?...................9......................mlaseventheditionofficeonline.xsl.L...............Content.inf.N.#.....[...>..9..3c.5...F.B.]Y.3..%d.8...v;....~Y.L.=..v..m.g...|K.B....$......s.......#CdE.p.p..@...j.Nl2'...L..N.G:-V:.d.....i..M........mK.w.....\W.<.`..b$.!..!3..rT.A..#.).;KZ...a.-..j&e`R.~7dIRS.I..f.ff....}.}....^[wo.uw..i.m7......v$.I..n....-.Z.M5...iH..Ea..., [..0.L...DH..." ..... .@...H.@..+...}.......*^..'.4*.tHa..f].gV..~.7V.....C..).(.U"..f.@l..j'..%\.u.UU.....9<13...5..=........./..Z..{..-.L].+Y.fL.<EJ.q..!.j....W..]E./.~Y>...GgQ..-....Q.C..5..T+...fO. .)..~.7..Y....+..U=.e..8w.m...._..S..v.d.* ......S3z.X)......u...t.......i.;.a...X.Ji....g.3.!.O.....T.f6..[U....O..Z.X.q.G....?.k]..?...8.u.;].8y.T.9D..!?R....:........3+.P.....7?m}..............1...y3.g.\c.ks^;?.f.U5...U.j....E.N.}.!.......).R1....~.....R.....3.J.f...l..E^:...&_..%..v...^..E...rC..O....M.#..<..H..bB.+.W..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 5864 bytes, 2 files, at 0x44 "architecture.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):22008
                                        Entropy (8bit):7.662386258803613
                                        Encrypted:false
                                        SSDEEP:384:M7FUtfIdqSHQs7G8E0GftpBjED/C4RQrFLrHRN7TT8DlvQyUTL2mH:sWgdqR2G8Pi6D6YQZTTMvU+mH
                                        MD5:ABBF10CEE9480E41D81277E9538F98CB
                                        SHA1:F4EA53D180C95E78CC1DA88CD63F4C099BF0512C
                                        SHA-256:557E0714D5536070131E7E7CDD18F0EF23FE6FB12381040812D022EC0FEE7957
                                        SHA-512:9430DAACF3CA67A18813ECD842BE80155FD2DE0D55B7CD16560F4AAEFDA781C3E4B714D850D367259CAAB28A3BF841A5CB42140B19CFE04AC3C23C358CA87FFB
                                        Malicious:false
                                        Preview:MSCF............D................................?..................................architecture.glox.................Content.inf..q5.^...[.....0y......../..CL.C5.Q..U5g.z....UUUMPC...C..P....T.....=..s..4c...-3H..E...2..2*..T...../.i.;$..............%...................'h.........#0.......[........c.h.....O...%.61...[.J..:.,^....W.]$..u...N.R.....H.......:%I.g5Kd.n6...W2.#.UL..h.8NN../.P...H.;@.N.F...v."h..K.....~.....8...{.+...&.#A.Q'..A.....[NJ.X.....|.|.G5...vp.h.p..1.....-...gECV.,o{6W.#L....4v..x..z..)[.......T.....BQ.pf..D.}...H....V..[._.'.......3..1....?m..ad..c(K.......N.N.6F%.m......9...4..]?...l6..).\p;w.s....@...I%H.....;\...R......f...3~:C...A..x....X...>...:~.+..r@..."......I..m.y..)F.l..9...6....m...=..Q.F.z..u......J].{WX...V.Z.b.A0B..!....~.;Z.....K.`c..,X.MFz....].Q.2.9..L."...]...6...JOU..6...~../......4A.|.......i.LKrY...2.R.o..X.\....0.%......>H.....8.z..^....5d|...4|...C......R28.E......a....e...J.S..Ng.]<&..mm
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 7453 bytes, 2 files, at 0x44 "pictureorgchart.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):23597
                                        Entropy (8bit):7.692965575678876
                                        Encrypted:false
                                        SSDEEP:384:y6aR//q0bJi/Uj+957G8E0GftpBj/4YOFLrHRN7LxhKll7PK/ph:y6I/Li/UjmVG8PiZ4YsLxh6Ih
                                        MD5:7C645EC505982FE529D0E5035B378FFC
                                        SHA1:1488ED81B350938D68A47C7F0BCE8D91FB1673E2
                                        SHA-256:298FD9DADF0ACEBB2AA058A09EEBFAE15E5D1C5A8982DEE6669C63FB6119A13D
                                        SHA-512:9F410DA5DB24B0B72E7774B4CF4398EDF0D361B9A79FBE2736A1DDD770AFE280877F5B430E0D26147CCA0524A54EA8B41F88B771F3598C2744A7803237B314B2
                                        Malicious:false
                                        Preview:MSCF............D................................?..................................pictureorgchart.glox.................Content.inf.W..y....[.............../.jC....U.CUUUTU.5...jjPU..MP....T..0*....o0.......Y.=....P.({.3.p..."pA!>r../3.q..7...........!...TO....(..%......6...3E?....~......CZmndse.Qy....p....h....=.:5...F..%.E.&.v.`I~. ..%._..b]..Y..Q..R.........nN.q8c..a..L..X/.M...PP.q..SpZ.K]>D"Pf..B.c....0..|I.Q.,.g/..Kev.../..=......w..}3.....(....+#T.....K`N.u..Z.....rriK.(...(...6.<R.%.]..NX..b..].C.u....++......Ia.x. .7....J.#............w>....7..R...H>....@%....~.yA.......~.UB..*. .P..$...-...v.....=M."....hw..b....{.....2pR....].C..u@=G."Y..;..gc/N.N.YB.Z.q.#....$....j.D.*.P..!.)S.{..c....&'E.lJ%.|O.a...FG.|.....A..h.=c7.)d.5...D...L...IQ..TTE.*NL-.*M..>..p0.`......m..,.w#rZ..wR\@.Wn..@Q...}..&...E...0K.NY....M.71..`.M./:.>..._L..m...,U.l....._fi...nj9..,..w.s.kJ.m.s.M.vmw.!.....B.s.%.-').h.....)c.l....F..`3r...-.....0..7..&N.....n.#H...<7
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 6450 bytes, 2 files, at 0x44 "ThemePictureAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):22594
                                        Entropy (8bit):7.674816892242868
                                        Encrypted:false
                                        SSDEEP:384:L7d2l8FbHaaIKbtv1gDISi8E0GftpBjEZRFLrHRN74bUll7PK/pd:LUlCIOt/8Pi6Zv4bMId
                                        MD5:EE0129C7CC1AC92BBC3D6CB0F653FCAE
                                        SHA1:4ABAA858176B349BDAB826A7C5F9F00AC5499580
                                        SHA-256:345AA5CA2496F975B7E33C182D5E57377F8B740F23E9A55F4B2B446723947B72
                                        SHA-512:CDDABE701C8CBA5BD5D131ABB85F9241212967CE6924E34B9D78D6F43D76A8DE017E28302FF13CE800456AD6D1B5B8FFD8891A66E5BE0C1E74CF19DF9A7AD959
                                        Malicious:false
                                        Preview:MSCF....2.......D...........................2....?..................0...............ThemePictureAccent.glox.....0...........Content.inf.o.@D..8.[.........B.....?. $...K.....~....aZ.WA"...k.......Z......."......"..X.fpB 2@d..87.[.A......p..e.'......F..P^%.%.RK...........T%0..........9..+8 ...&.q.....+.......^.fad^^n...d.....s1..... .3j.c-c7..y<.....6........C5n.KG...Rs[lt..ZkwI.!..Uj.ez_!A^: /.;.Rl4....^..<6..N...'.YY.n*.E{.`..s.7..z.......L.y.Y.....q.kx.....[5.+<to......1...L.r.m..kC.q.k.1..o.w8s.....xh.@.b.`l\...}z1.6..Y.</DY...Z5..D...0..4.;..XAA..0qD..E.....h...C..hH......S..Z.\.VBu......Rxs.+:RKzD......{......a..=......).<.....d.SM.......c!t.4.h..A=J~.>q?Hw.^.....?.....[..`....v.nl..A.u...S!...............c......b.J.I.....D...._?}..or.g.JZ#*."_``.>.....{...w......s...R.iXR..'z....S.z.\..f.....>7m..0q.c-8\..nZw.q..J.l....+..V....ZTs{.[yh..~..c........9;..D...V.s...#...JX~t8%......cP^...!.t......?..'.(.kT.T.y.I ...:..Y3..[Up.m...%.~
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 16689 bytes, 2 files, at 0x4c "iso690.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):32833
                                        Entropy (8bit):7.825460303519308
                                        Encrypted:false
                                        SSDEEP:768:+0TU06CkaUYMoi//YX428RaFA8Pi6e9iA4I3w:vICTm/QorUpP7eAA4I3w
                                        MD5:205AF51604EF96EF1E8E60212541F742
                                        SHA1:D436FE689F8EF51FBA898454CF509DDB049C1545
                                        SHA-256:DF3FFF163924D08517B41455F2D06788BA4E49C68337D15ECF329BE48CF7DA2D
                                        SHA-512:BCBA80ED0E36F7ABC1AEF19E6FF6EB654B9E91268E79CA8F421CB8ADD6C2B0268AD6C45E6CC06652F59235084ECDA3BA2851A38E6BCD1A0387EB3420C6EC94AC
                                        Malicious:false
                                        Preview:MSCF....1A......L...........................1A...?..................S@......v...............iso690.xsl.................Content.inf.B.9.....[...A.c...32.E...P..'.^}.f...ikMJ....m..s..U.w{m{{...}n.4........I. ..9..d..I.......P|....F...F.......&&J.:I.34......+*M3..4mr.........m.r..m)....dK.wiw...H,...r........y.$..Cu...L...dH.../..V......g.PG$R39...4O..............{w..^....c.m.m.o.....#..Fgs..6.....b....3.I..O....B..B..1h"....K|f .41......_..g.N.<.>........(....o3a.M)....J..}....-......8.......g.hm!r<...-..1.1....q.?....S.m...`L.g#.K.igv.].ghD....L...p5..?.......iP.[JS.J..?z~.T/.Q...E.K.......P+\LW.-.c..[9.n.7.....P...*[.A1....m...4h.9...N[....h5 n%k.~RR.*c..n..=...4....).eH.-./..>....*.r..S.*..dE.........pF..s.A..?...f..u.+.{..?>N.4].}Xb.M......y......'.2..'..........J4{r..r.3........5>..a0.>.u_.y@g....+y.yu--,ZdD.........5]3..'.s...|.....K.....T..G.G.e...)..\x..OM.g...`..j0......BfH...+.....:......l`.qU...;.@...",.."........>;P.B.^F...3!......Rx.9..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 15338 bytes, 2 files, at 0x4c "gosttitle.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31482
                                        Entropy (8bit):7.808057272318224
                                        Encrypted:false
                                        SSDEEP:768:LgHv7aLOcoLGQ4EykdrHwLa+A8Pi6Iv8ACIa:LwvWyx4EykdTwLaWP7I0ACIa
                                        MD5:F10DF902980F1D5BEEA96B2C668408A7
                                        SHA1:92D341581B9E24284B7C29E5623F8028DBBAAFE9
                                        SHA-256:E0100320A4F63E07C77138A89EA24A1CBD69784A89FE3BF83E35576114B4CE02
                                        SHA-512:00A8FBCD17D791289AC8F12DC3C404B0AFD240278492DF74D2C5F37609B11D91A26D737BE95D3FE01CDBC25EEDC6DA0C2D63A2CCC4AB208D6E054014083365FB
                                        Malicious:false
                                        Preview:MSCF.....;......L............................;...?...................;......................gosttitle.xsl.$...............Content.inf....v....[...=..Ic.32.E...`o.............m....4uk[.,.......{...}k{.R@(Hq..68nv...@.D.....$...j....8Q..........8.8........3...*.bi?Wt...:(..J.;&eii..io.w..z...`.'..i.MLR@.>....N..3`P.>$X@(r.#.D..(....P"_..I.$o.. L!y...I...H.........{.{....{.3....7..w..{w.2sn.dYn.lW...l...c$.UH....L6. .D$$...!F.!... .D............_..'.`.Q.v>..Z..f.n.l....0o.......bK...?s..eO....'.>t......S'..........~....h...v&7:q.x9|qs...%....:..D...ag.....e..'...".A.Y..?w"....p1t.9J.~.4.........~vj.n.8.;.O......../.}..io{p...e...\m.d`.gAm.......1"...N*...8..g"......~..[.e+.....\6i4.....%...Rq.U-p?..4P..4.f.?N.vI?.M\i.;.s..E.L.hu.*...\..5....N......]......\`...rS.\g.....2..!a).?.l.!i.^.t.u...x...g/.A..v.E...\.@.>kM...&.g.....%.......{.....2..E.g...'..[w...N.w..& 4M.a.cu.%:...\.D..Q..C.'fm..i....@._......QI.. ....h..|fB.il.(`..h.d;.l...`.s:
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 14939 bytes, 2 files, at 0x44 "CircleProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31083
                                        Entropy (8bit):7.814202819173796
                                        Encrypted:false
                                        SSDEEP:384:0XbSq3W46TVZb5fOFo1HtZwGqtRT44hS+nyBoiuFgbA8E0GftpBjEcBFLrHRN7Ku:0XpOflfOFo1DMr/iuuA8Pi6cfKjW66b
                                        MD5:89A9818E6658D73A73B642522FF8701F
                                        SHA1:E66C95E957B74E90B444FF16D9B270ADAB12E0F4
                                        SHA-256:F747DD8B79FC69217FA3E36FAE0AB417C1A0759C28C2C4F8B7450C70171228E6
                                        SHA-512:321782B0B633380DA69BD7E98AA05BE7FA5D19A131294CC7C0A598A6A1A1AEF97AB1068427E4223AA30976E3C8246FF5C3C1265D4768FE9909B37F38CBC9E60D
                                        Malicious:false
                                        Preview:MSCF....[:......D...........................[:...?...................A..............CircleProcess.glox......A..........Content.inf......9.B[.....@*........!...(A.D..K.W.wwpwJj\.K\w...]...K.!.....@0..?,...}won`... ....&I..(;.....X.u..^.R..^......_:....W>f\....T...B..i`|q.....................i.5....(........0q7@.@..F...?A.`.....,L.......5.+../56..a`....1C5..9.*I.N.......@|<+./......... .ya....>l.,t.......y.y5...FF.,F..jCA...SA..H....8u.L..eM?.w8.......~^.Mr.[...(.._......u..+.......j..TJ.:<.3.X`...U.bz...[...r-...[...+..B.......}...\'.i...C.8.B_...c.8</..s.....VQ.Y..m.,.j~;y ...2.5.VQ...K..jP..2..r-...HA...."..9).7.....5.E._.wq.......!.+n+.f...s].4M'.1&...5....4..k..NV.M1.7`a..<.P4.|.mrd.i.R...u...............v.}..n\.C$.....[..2c.^..W..g..._.0.C.o....%.z.!.;.@y.`\..UO#i.)...Q...........L. .\:_..H.{.W...@...T.4..A.a...Wo?o$4.....#.V.s8M.Gh..p?A...Y.....)...........r|...!..o9...8..%#.[....;...3<Z...g....~.Z....,.(...qA.'x#..xC..@...HOuW.[.[....c.........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 18672 bytes, 2 files, at 0x4c "APASixthEditionOfficeOnline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):34816
                                        Entropy (8bit):7.840826397575377
                                        Encrypted:false
                                        SSDEEP:768:i3R9VYnIYfPYmqX0CnF1SRHVnLG8Pi61YbEIFO:ih9VjYfPYlk+F1SJxP71YbEIFO
                                        MD5:62863124CDCDA135ECC0E722782CB888
                                        SHA1:2543B8A9D3B2304BB73D2ADBEC60DB040B732055
                                        SHA-256:23CCFB7206A8F77A13080998EC6EF95B59B3C3E12B72B2D2AD4E53B0B26BB8C3
                                        SHA-512:2734D1119DC14B7DFB417F217867EF8CE8E73D69C332587278C0896B91247A40C289426A1A53F1796CCB42190001273D35525FCEA8BA2932A69A581972A1EF00
                                        Malicious:false
                                        Preview:MSCF.....H......L............................H...?...................G......................APASixthEditionOfficeOnline.xsl.H...............Content.inf..h;.....[...Q..\..3S.5..oVP!i/Z.Ls...]q$...xY..+W.qm..B..y/.5.s..x$../K./.x.$.....}.......\........LNf..Hd.&."Ip.L.Mr-@.D..kW~i...^.....F.....T.U....../..0..2.{.q.T.`'{.00.{.B...>.R..2....1.~_.f..s...........~....~[..v..w..v....$[K.r$#[6...d;[...#.9.-...G..Z..eAR.0")%JI?&....$..$.H..$(........f.> k....hP...p...!j.T......l7..../3..(2^V...#..T9...3.@[0...le:...........E....YP.\.....au1...\.S|..-.duN.Z..g.O......X8....1.....|,.f/..w.|Wk]zJz.g'./7h..+.....}............x....s.2Z\..W.{...O....W.{j.U..Q....uO=.p.M k.E.S{SUd.@....S.Syo8>......r......8..............Z?>.mUAg....?o....f.7..W.n...P..........d.S?...\..W`...c.ua..........#.Y...45...F(d.o\09^..[.}...BsT.SD..[l.8..uw.7l..S.9T.KR..o......V..]...M .....t.r...:P...M....4.F.....@..t.1t..S...k.2.|5...i.%H..<.J..*.0n.....lZ.....?.*?.~..O .)..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 27509 bytes, 2 files, at 0x4c "Equations.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):43653
                                        Entropy (8bit):7.899157106666598
                                        Encrypted:false
                                        SSDEEP:768:+bjfeR1OOZvv439PlDe5/QzhgFSo0UEDmJwkqTA8Pi63Bsgn66w:IM3CN9ZzhFbUUwaP73BsB6w
                                        MD5:DA3380458170E60CBEA72602FDD0D955
                                        SHA1:1D059F8CFD69F193D363DA337C87136885018F0F
                                        SHA-256:6F8FFB225F3B8C7ADE31A17A02F941FC534E4F7B5EE678B21CD9060282034701
                                        SHA-512:17080110000C66DF2282FF4B8FD332467AF8CEFFA312C617E958FDFEBEE8EEA9E316201E8ABC8B30797BB6124A5CC7F649119A9C496316434B5AB23D2FBD5BB8
                                        Malicious:false
                                        Preview:MSCF....uk......L...........................uk...?...................j......r...............Equations.dotx.................Content.inf.94v..R..[..... .............v........." Vw.w..r.....D.V5.p...W......b;....\x.....f.-...............l.....L.F..*..@..BnF.I.....%1..0....&.X.......X-.\.\.>..A....@..:...N .G./.Sp.A0.0.`.....q....b... ......S.{K...V....J............>\....\.E.#.,$.hxu.F.Fo....<...{..6../..#..l>d...w...&...S.....L.].....^..L......;~l.......qw.o. .....v.u.W`.4Z.A.....dC..Q)9.c..qgtfJ..G.(.J....q4V.).mK4;..zY..b.5&....V...0X.].Z..U.Lx..^..:8XQh.....7yy.._5............c.W...c...xY..%..G.$....kg^.1g.9.....z^.'...q."..K)a[.pW .LS.:Q8.....2..._q.os....y...d11.*.m....8.,.^.4_?i.e.u.,....._y.....zZZA.D.D<..+....{....Sfnv...t.....0...vV..y.r..3..%.<.t......;.h.wh.-.g.>..5...R...........y..]^..R..<...>$~.'...kk.n..H.EN.eQ.Q.O./='....)t.l0,/].....FNN......?...&..'.eS....K.K.v".^L..x=.^......1x|....=}@...B.kq;_a..C.q?..Y9.v......Q..u.G..V.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 15691 bytes, 2 files, at 0x4c "gb.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):31835
                                        Entropy (8bit):7.81952379746457
                                        Encrypted:false
                                        SSDEEP:768:ltJDH8NmUekomvNufaqA8Pi6x5q3KQIGu:lvINukgzP7x5mRIGu
                                        MD5:92A819D434A8AAEA2C65F0CC2F33BB3A
                                        SHA1:85C3F1801EFFEA1EA10A8429B0875FC30893F2C8
                                        SHA-256:5D13F9907AC381D19F0A7552FD6D9FC07C9BD42C0F9CE017FFF75587E1890375
                                        SHA-512:01339E04130E08573DF7DBDFE25D82ED1D248B8D127BB90D536ECF4A26F5554E793E51E1A1800F61790738CC386121E443E942544246C60E47E25756F0C810A3
                                        Malicious:false
                                        Preview:MSCF....K=......L...........................K=...?..................q<......................gb.xsl.................Content.inf.EF/.....[...A....3D.4..oVP!i/......t.6..l&9r0.8......c..q.^........$/..(./H ...^_Z0\4.42WU......P.F..9.._....'.D..<H@..E.b,K..9o..wo..v|..[.{7m.......|}aI..|g....IF2au?.1,..3.H.......ed....-.........m....$..8&0..w........2....s....z..d.Z.e.....@$r[..r..4...."E.Q@...Hh.B"b>...$.L.$.P.._..~.?./T..@..F..?.~G...MS..O%Z3*k..:..._...!GF..U...!..W..$..7...j......xy0..../.j..~4......8...YV....Fe.LU..J.B.k%BT5.X.q.w.a4....5..r...W.6.u...]i...t.....e.\.K............#t.c5.6....j...?#..{.m3.L9...E/....B[R.k(.'....S.'.}!j.tL..v....L....{<.m4......d_kD..D.....4`aC....rg..S..F.b..^........g;.`?,......\..T.\.H.8W.!V...1.T1.....|.Uh....T..yD'..R.......,.`h..~.....=......4..6E..x#XcVlc_S54 ..Q.4!V..P...{w..z.*..u.v....DC...W.(>4..a..h.t.F.Z...C.....&..%v...kt....n..2....+.@...EW.GE..%.:R`,}v.%.nx.P.#.f.......:.5(...]...n3{...v........Q..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 26644 bytes, 2 files, at 0x4c "Element design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):42788
                                        Entropy (8bit):7.89307894056
                                        Encrypted:false
                                        SSDEEP:768:Hx+UzBiwDQTXgBm029ClGn4BZz6i5kIew/jG8Pi6lYJz1gH:0ZXc29eGn2n5klwjxP7l2z1gH
                                        MD5:21A4B7B71631C2CCDA5FBBA63751F0D2
                                        SHA1:DE65DC641D188062EF9385CC573B070AAA8BDD28
                                        SHA-256:AE0C5A2C8377DBA613C576B1FF73F01AE8EF4A3A4A10B078B5752FB712B3776C
                                        SHA-512:075A9E95C6EC7E358EA8942CF55EFB72AC797DEE1F1FFCD27AD60472ED38A76048D356638EF6EAC22106F94AFEE9D543B502D5E80B964471FA7419D288867D5D
                                        Malicious:false
                                        Preview:MSCF.....h......L............................h...?..................@g......o...............Element design set.dotx.................Content.inf.Y/..Re..[......f........,..]....D.],....]..X.......XC4pE.....p........2..u;L.N.....]G..d.^d.$).e.=..;..Kb.../.../....H.."...w$._I..5.....a..4.Gd5p......v.8..1..%H..\..e...3.e..A..).d*.. . (.8.".......(>..<...@...~*v&.f..LWhqk]+Uep.d..%...o.....k.......e...nNN.&_.>.d.?H`"...r?..Z.p..q..<M.N.t....{*.y]#...._XW"qI...x.......}.. .N...;.}:..m8...[.r.F....^?...o...u..*...J3.V....~...~tn#.Kf6.s.|*..,s...M.$.f..?Yu.pE.1_wU...%....._..'..Z......y:.{.J5..7..Q.w}/.~.-3~Ctw=..IT.....mI.u@...y.M....2.%...y...Y..j.k<-.Q.r...7m..b...+.6..|.....U..}[...,....^....5..D..qW...[3).p.Y<.Hh..t...%cw=Z..W.~W.F....zr.4.g...O...P.g_^..3.-............3s...S..y...u...N...EsJz....tT../..c[w{cG....../6.....:.W<d5}.q..s..K"$........Ne..5..#.v'..n4.rj....Fc=....5..VN.....6..9`....|..........WX..-?..........W.)^`1.......].R2..s6...H.......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 30269 bytes, 2 files, at 0x4c "Text Sidebar (Annual Report Red and Black design).docx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):46413
                                        Entropy (8bit):7.9071408623961394
                                        Encrypted:false
                                        SSDEEP:768:WaxA0CH65GY3+fvCXCttfR8JEBrkquwDn+QV5V+vNWBatX/xG8Pi65sMuMjvU+mQ:hne65GYOfKXMSEBrBtDnzFAI4JxP75sM
                                        MD5:C455C4BC4BEC9E0DA67C4D1E53E46D5A
                                        SHA1:7674600C387114B0F98EC925BE74E811FB25C325
                                        SHA-256:40E9AF9284FF07FDB75C33A11A794F5333712BAA4A6CF82FA529FBAF5AD0FED0
                                        SHA-512:08166F6CB3F140E4820F86918F59295CAD8B4A17240C206DCBA8B46088110BDF4E4ADBAB9F6380315AD4590CA7C8ECDC9AFAC6BD1935B17AFB411F325FE81720
                                        Malicious:false
                                        Preview:MSCF....=v......L...........................=v...?..................5u......................Text Sidebar (Annual Report Red and Black design).docx.v...............Content.inf..C,.zd..[............... .w.....b...wwww]r..W\ww...... .hh...........o.nz.....Ku.7..-.oH...h;.N..#.._.D,}......!Q$..Un.tI11..$w.r3... ..p...=.1....""..n...*/....h.A...Y..c,.Q.,......",..b.1.w..$.....l../;..J.....~.. ....+.R#....7.-..1.x.feH.@.......u...(.DQ%.wL.N|.xh...R..#....C...'X.m.....I{W.....5.C.....\....z.Y.)w..i...%....M..n.p.....{..-G9..k.bT.6........7....).....6..ys.....R.e.....0.Xk`.3..X\xL..4J"#.f...:....r..2..Y.uW..052.n.+ ..o..o..f&u.v.&9y.P..6.K..in.DU.#.~....4i..6;.5.w..i...g.(....../..0*Vh...C..//....W..:w......7.6....]....4.*9...sL.0k...zHh..2N.H...*..]..(.x.:..........Y.+...-.....&.*^..Q.sW...v..w.....k.L.e.^.W4iFS..u.....l.g'...b~:Zm...S.2.|......5S..=.............l.../|....G|.9 ..#.q...W.Q...G=.."W..'.6....I....D._.{.g.47....V.1._..<?....m............)..T.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 206792 bytes, 2 files, at 0x44 +A "content.inf" +A "View.thmx", flags 0x4, ID 33885, number 1, extra bytes 20 in head, 15 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):222992
                                        Entropy (8bit):7.994458910952451
                                        Encrypted:true
                                        SSDEEP:6144:k8/c2cF9GTLqsTmYstUdx+dwb2ooiVOfiI17zWbQ:jbzqGdpbZ/Mf3h68
                                        MD5:26BEAB9CCEAFE4FBF0B7C0362681A9D2
                                        SHA1:F63DD970040CA9F6CFCF5793FF7D4F1F4A69C601
                                        SHA-256:217EC1B6E00A24583B166026DEC480D447FB564CF3BCA81984684648C272F767
                                        SHA-512:2BBEA62360E21E179014045EE95C7B330A086014F582439903F960375CA7E9C0CF5C0D5BB24E94279362965CA9D6A37E6AAA6A7C5969FC1970F6C50876582BE1
                                        Malicious:false
                                        Preview:MSCF.....'......D...............]............'..H?..........z..................M{. .content.inf..l.........M{. .View.thmx......R..[...........@...G...I..(J.....B....Q!....}Ju..(BR..._|.5.%.....6m...........?.w{.rm,....#....;Ba#.:v...Dv.."u.v{!...f}......!......:.S.......".z.f.......==.n.0Km0eh.Kbm.C.r.6.........d..h.....{..w..}....2sb...rvm..x...0(..B... ...BH.r#.@..d".*..F+...Q.sx.....?...d.d.eZ2W2.2d...q.I....4.e4....#.....K...3...1.p.y......>.~V....cm....n^..b.{..._D?..AG...'...k.L&..h}=p.....Wl....(.......>.~.].....'.4.W{......../......7.....'.s...w...6..hn..e.2.).l]u.v4...GF.X..X..X....G.i.\..y.g&.<&ti......Sp,j.....>I..S..%.y..........S..-).+...>...D..............[...d...jt.~<x.a(.MDW..a..ZI.;+..!,.$...~>#...).R4...K.$.Zm......b...........{..._..A{.}..r...X...T.ZI.T.).J...$.".U,.9...r.z.)......}...()<....m....QS.p...;?..5.W~2r.EZu..P.1.%'l.........+/6.Mm.|2....Ty..f.o.S.....3J.._...X,..m....:..1.<GqFy.QA9W4.=....n...ZP...O.\.[...:8.%.^..H.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 243642 bytes, 2 files, at 0x44 +A "content.inf" +A "Metropolitan.thmx", flags 0x4, ID 19054, number 1, extra bytes 20 in head, 24 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):261258
                                        Entropy (8bit):7.99541965268665
                                        Encrypted:true
                                        SSDEEP:6144:9blShNYrHNn0JU+D+kh8CIjXHWC7X0nZLC9Ge2KY/WfI:9ZSTYrtn0Sk+CIDHWC7chVKYx
                                        MD5:65828DC7BE8BA1CE61AD7142252ACC54
                                        SHA1:538B186EAF960A076474A64F508B6C47B7699DD3
                                        SHA-256:849E2E915AA61E2F831E54F337A745A5946467D539CCBD0214B4742F4E7E94FF
                                        SHA-512:8C129F26F77B4E73BF02DE8F9A9F432BB7E632EE4ABAD560A331C2A12DA9EF5840D737BFC1CE24FDCBB7EF39F30F98A00DD17F42C51216F37D0D237145B8DE15
                                        Malicious:false
                                        Preview:MSCF............D...............nJ...............D.................."..........M. .content.inf....."......M. .Metropolitan.thmx...cVtP..[.....`Q..B.....=.T.....h.."...Z..|..}hZK.V....Z..Z................?..v...[S$."...H......^u.%.@...>....... f.........1.5......*&lm.tZ.msz:...Noc....1....D .........b..... ..3#pVp....}oo]{m......H*[%i.GNHB1D<......(*# ....H"....DP..b(B.<.....v......_..`.7..;.}............/.p}.:vp....~l0..].........S....G?.....}..U.;......dNi..?........-c..J.z....Z...._.O.....C..o.,......z....F....sOs$..w9......2G..:@...'....=.....M..am.....S......(`.._....'......[..K"....BD...D...^1k.....xi...Gt....{k@.W.....AZ+(,...+..o......I.+.....D..b. T.:..{..v.....g..........L.H.`...uU~C.d...{...4.N.N..m8..v.7..3.`.....,...W...s.;.fo.8.Y...2.i...T&.-...v8..v.U.Y=...8..F.hk..E.PlI.t.8......A.R....+.]lOei..2...... gS*.......%8H.....<.U.D..s.....>.....D_...../....l.......5O1S~.........B.g.++cV.z.f .R.Z.......@6....(..t^5"...#G...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 252241 bytes, 2 files, at 0x44 +A "content.inf" +A "Frame.thmx", flags 0x4, ID 34169, number 1, extra bytes 20 in head, 16 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):271273
                                        Entropy (8bit):7.995547668305345
                                        Encrypted:true
                                        SSDEEP:6144:zfdvQnJMwXse4Vradf3mrC7woyWbjKlCVC7K:zfJwJse4VrS1AK
                                        MD5:21437897C9B88AC2CB2BB2FEF922D191
                                        SHA1:0CAD3D026AF2270013F67E43CB44F0568013162D
                                        SHA-256:372572DCBAD590F64F5D18727757CBDF9366DDE90955C79A0FCC9F536DAB0384
                                        SHA-512:A74DA3775C19A7AF4A689FA4D920E416AB9F40A8BDA82CCF651DDB3EACBC5E932A120ABF55F855474CEBED0B0082F45D091E211AAEA6460424BFD23C2A445CC7
                                        Malicious:false
                                        Preview:MSCF....Q.......D...............y...........Q...XJ..........{..................M.. .content.inf.(..........M.. .Frame.thmx.1....b..[.........B.....6....ZZ}....BH..-D..}..V.V-........Z..O.....H.f..........;..@d.`......!..=;.,bp..K.q....s.y....D.qZ)p......D...r.S....s=B.4.).8B....4.a6 ...~........."....#.....}....n.Q.1cH.%c/.U....E..E...!..Da*.p....X..G..:.....1.@.....W.'...._........W.c...<.v.k.....&.8......?.h.>d._:-.X.......9..tL}........3.;.N3.D~......>.^?..|:...}......oT.z.......w..[..}:...._fu........Kk.......L..9..p..e..^......K.%...Mapqhvv..E&.^.....[...9|"l...9...U......!..w..Nya...~C.yx...w.K..q.z.j.W?t.......DY.x.S2.....]..na.Qj...X.K..^...S.hK.W...Z....s.0...NF...8C.......j.'Zc...k.%...l....S.....OW..o.Qf.x...X.;<.rO].....W.m.e....T.1.6........".....Q.3........l..v.."..I...&......w..4vE...c.s[.3.m..8.q$.....a...)...&:6..,..#..?....;.!.....~.UP.r=.}h.&U......X...]..X.e\u.G<....E....lG.@.*Z...10.D@.]....z+-.S....p..Y.PK.:.S..p.....1E`..-
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 279287 bytes, 2 files, at 0x44 +A "Basis.thmx" +A "content.inf", flags 0x4, ID 55632, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):295527
                                        Entropy (8bit):7.996203550147553
                                        Encrypted:true
                                        SSDEEP:6144:nwVaEqsf23c9shf6UyOGgDWDn/p3fd+zkPWnvGL3n9bQnkmVheyqtkl:MlPfW6sVEDn/pPdhWnvGL36zyyqal
                                        MD5:9A07035EF802BF89F6ED254D0DB02AB0
                                        SHA1:9A48C1962B5CF1EE37FEEC861A5B51CE11091E78
                                        SHA-256:6CB03CEBAB2C28BF5318B13EEEE49FBED8DCEDAF771DE78126D1BFE9BD81C674
                                        SHA-512:BE13D6D88C68FA16390B04130838D69CDB6169DC16AF0E198C905B22C25B345C541F8FCCD4690D88BE89383C19943B34EDC67793F5EB90A97CD6F6ECCB757F87
                                        Malicious:false
                                        Preview:MSCF.....B......D...............P............B..p?..........{.................M.. .Basis.thmx...........M.. .content.inf.`g..td..[...............5..$..WM.....R.......H\.+\./^...x.^..h..MU..\........v........+......g...$.......g.....~....U].7..T..1k.H...1...c.P.rp.6K..&......,.............U4.WoG.w.....;.....v..922.;]..5_-]..%E]b..5]... (..H..II..ttA4Q..BI!|...H.7J.2D....R.......CXhi`n....6..G.~&.[..N...v..Z"t.a..K..3..).w...._@.}.}.v.......4......h....R;.8.c&.F...B^....Q.....!Bm2...F.`.......M;...#.{....c...?...e...6t..C.-.E.V.v%I..H.....m.n...$D.....vU'.....=6}~...Gw...Y..?.@......G.....k......z...5d.h......1.}..O*;e..t......Y.0...3.v).X.-.2.....~....14.[.w=I....hN....eD..7G.u.z..7.do..!....d..o.wQ.:....@/.^..<e.-..=\.....6.C.'.rW$..Cp.M3.u6z......Q.F.9.5....juc..I...m4]7L....+n......).t......2[.3.p.:.....O5y..wA........^..!..H....{..S.3w.!&.'.;...(..|m.x.S..Z.j..3...n..WU...../w.......xe=.+.D...x..qy.S.....E..... ...uu.`.,..<.6[p
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 291188 bytes, 2 files, at 0x44 +A "Banded.thmx" +A "content.inf", flags 0x4, ID 56338, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):307348
                                        Entropy (8bit):7.996451393909308
                                        Encrypted:true
                                        SSDEEP:6144:7vH3uG+yiWx0eVJyORloyyDqnHefzOs81MrXLXx7:b36yiWH/LRS2CJl1
                                        MD5:0EBC45AA0E67CC435D0745438371F948
                                        SHA1:5584210C4A8B04F9C78F703734387391D6B5B347
                                        SHA-256:3744BFA286CFCFF46E51E6A68823A23F55416CD6619156B5929FED1F7778F1C7
                                        SHA-512:31761037C723C515C1A9A404E235FE0B412222CB239B86162D17763565D0CCB010397376FB9B61B38A6AEBDD5E6857FD8383045F924AF8A83F2C9B9AF6B81407
                                        Malicious:false
                                        Preview:MSCF....tq......D...........................tq.. ?..........|..................Mn. .Banded.thmx............Mn. .content.inf..;.u.i..[...............?....^.j.{j.B...$M/!...W....{!..^0x/.6...&............w......$.B..J.?a.$=...P..L...d..........+./.\..E:h.....-.$..u-.I..L\.M.r..Y..:rtX:....8...........+8.}{......&.-..f.f..s3-P.''.r...Z-"/E../...^%^N(,.$..$.H..O........q>...|.|......y..m.)u....`.....z.n..-.[.5....xL....M...O..3uCX..=4.....7.yh...dg.;..c.x.4..6..e..p.e"..,.!.St{..E..^I.9j....;..`.Y..#.0..f...G.....9~./....QCz.93..u%hz.........t9.""........)..7K.c~E!..x.E.p...[......o..O.j.c.......6.t{...".....t9V;xv....n<.F.S2.gI.#6...u..O..F.9.[.L.....K....#..zL..I...o....k...qog.......V..BKM..#.bET.)..&4..m.w...*....E.a[.Q.y.B...w...r.nd...)...<..#..r[4.y...#.z.....m?.2K.^...R{..m..f......r?]..>@...ra$...C+..l].9...."..rM9=......]".'...b&2e...y..a..4....ML..f...f"..l..&.Rv=2LL..4...3t_x...G....w..I.K....s.t.....).......{ur.y2...O3.K*f.*P(..F..-.y.Z...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 259074 bytes, 2 files, at 0x44 +A "content.inf" +A "Dividend.thmx", flags 0x4, ID 58359, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):276650
                                        Entropy (8bit):7.995561338730199
                                        Encrypted:true
                                        SSDEEP:6144:H2a+HFkDF8gpmMt4kzwVVqhSYO6DITxPWgJl1CFExwXyo7N:mlZgFtIVVTuDExeWuv7N
                                        MD5:84D8F3848E7424CBE3801F9570E05018
                                        SHA1:71D7F2621DA8B295CE6885F8C7C81016D583C6B1
                                        SHA-256:B4BC3CD34BD328AAF68289CC0ED4D5CF8167F1EE1D7BE20232ED4747FF96A80A
                                        SHA-512:E27873BFD95E464CB58B3855F2DA404858B935530CF74C7F86FF8B3FC3086C2FAEA09FA479F0CA7B04D87595ED8C4D07D104426FF92DFB31BED405FA7A017DA8
                                        Malicious:false
                                        Preview:MSCF............D................................D..........~..................M. .content.inf............M. .Dividend.thmx..).}.b..[.....`.........?.R...T../..............4..yy....{...f.h..\U......sy.gV0Q.@..A..@..3a.A}........7.q.......8......R....sJ)E..ENr.S*B.1..).s.r.J.D.b."..........(.....E$.V........y.5.L....;gY..QK/nni..x..3.<..Q.Q..K.I.....T.z.,F.....{.p.....;8._.&../...........X...}.;[Gk..._.i`m.u.?...s.w...4.....m......l....5..n.?..c..m...,.....{.k.?......sC.............e..1....oL.8./......1._.K:.]..&......O............qo.....Dd/c...6.q.*......V.v........h....L..h..C+..V..;O.(7Z]{I%....S3.{h....\...b.......5.ES......Z.4...o.c`..YA....9i....M.s....Z3.oq`....>.i..@.@n.a...x.3.zp.<....vU/.|^CvE...aD.P&mhvM>.p..B~....."._.......v-.m..w..?._..=...:...k....i.}x.6....Y.i..n....h...j......LZ.....fk..f0.y.T..Vl.;...s.......B6.f.'z.c.\W?...4U)..aJ.;O....L.d7.J.V#Q.....\J.F.?].d}!..y].6..%..~....|......5...'N.#.....t6.,.E.O."..0fyz....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 214772 bytes, 2 files, at 0x44 +A "content.inf" +A "Parcel.thmx", flags 0x4, ID 26500, number 1, extra bytes 20 in head, 19 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):230916
                                        Entropy (8bit):7.994759087207758
                                        Encrypted:true
                                        SSDEEP:6144:OTIPtMXmJWnzPS3pqnkeuJXW+FNx1a72rLiQxEBTR:750nz63/FJRFLISnp+Bt
                                        MD5:93FA9F779520AB2D22AC4EA864B7BB34
                                        SHA1:D1E9F53A0E012A89978A3C9DED73FB1D380A9D8A
                                        SHA-256:6A3801C1D4CF0C19A990282D93AC16007F6CACB645F0E0684EF2EDAC02647833
                                        SHA-512:AA91B4565C88E5DA0CF294DC4A2C91EAEB6D81DCA96069DB032412E1946212A13C3580F5C0143DD28B33F4849D2C2DF2214CE1E20598D634E78663D20F03C4E6
                                        Malicious:false
                                        Preview:MSCF.....F......D................g...........F...?..........|..................L.. .content.inf.zG.........L.. .Parcel.thmx.>2...R..[...0...........7....B+...BH....{...^.../.....B{...1....+".....<.....$........{.......sD"..j...}... P..w..U..f...6.x8. ...C..F.q.7....T.6p......B.P..L..g......A..43.W`.....{{...u.4...:.bb.4"X..m..)$..@(H. H.tBPTF..,.&.B.'...6..2...n..c%...Z@.(.@.......(.<i.i....P......?......o.......F.M.L......i.....C..7..../.....MQ.0..l.U.s.Fu.......1...p.;.(.}..ogd..<.._.Z......._.......O.J......97...~<...4.c....i..........'k.5.......Q.$..C..E... ..5.7....N.a.[ns6hi..kM....?....X......*9q...!O\....0....n.^s.9.6..............;. ..r...rf..C6z..v #.H...O...v/.sl....J.m%.L.Dp.e....*uO..g.y....f...].5.*........W.....h^[..w.|.=.ru.|.M..+.-.B...D.Ma....o.<X SnI....l...{..G..,..y5\W.@..y.;.y ...M..l.....e..A...d.e!.E..3.......k1.......6gY).../....pQ..?..s.W.)+R.S5..../.0..vz.^.......k.....v..9..A.NG...N~#..$.B...*s,(.o.@.ar.!.J.....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 533290 bytes, 2 files, at 0x44 +A "content.inf" +A "Parallax.thmx", flags 0x4, ID 64081, number 1, extra bytes 20 in head, 29 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):550906
                                        Entropy (8bit):7.998289614787931
                                        Encrypted:true
                                        SSDEEP:12288:N4Ar9NyDhUQM0Hk86V1YnOIxQ9e6SJbj2OjK:jAG8wa5Qw6SZ2Oj
                                        MD5:1C12315C862A745A647DAD546EB4267E
                                        SHA1:B3FA11A511A634EEC92B051D04F8C1F0E84B3FD6
                                        SHA-256:4E2E93EBAC4AD3F8690B020040D1AE3F8E7905AB7286FC25671E07AA0282CAC0
                                        SHA-512:CA8916694D42BAC0AD38B453849958E524E9EED2343EBAA10DF7A8ACD13DF5977F91A4F2773F1E57900EF044CFA7AF8A94B3E2DCE734D7A467DBB192408BC240
                                        Malicious:false
                                        Preview:MSCF....*#......D...............Q...........*#...D..........~..................M{. .content.inf............M{. .Parallax.thmx.9... y..[......(..b.P...E.Q*.R.".RTH.%.T..F......u.{.*+.P.....FK*0].F...a{...D4`D..V.../.P,....2.Mx...u......0...E...{A-"J...)jl_.A..T......u.Y....ZG:....V.A.#~.. ..6..............o..X..<.... .......C.ce.f!nA.).p...p........n..................'6w6H6s.j....l...{?.h..........]..l.....v....%..l}A..................3...W_73.j......6...F.../..qG.?........H..).........7.&km....`m2..m.W.q.<../~<..6*.78..X~.e+..CC*w...T...6....AB..l..._.f......s.e....2....H..r.R.Z....a.,..\Q.q..._SJJ....7.S.R....=f..>....9=....NnC.....].-...\..Z..q..j...q.....Nj..^'..k...Zl.~PRvpz.J..+.C...k.z.w=l.#.............n...C..s.kM.@B{..vL.e....E..(/......f...g..=..V...}...).=s.....y!.,...X.[..[.....\31}..D%...%..+G66.j.v./.e9...P;.o.y..U+...g.g.S.../..B._L..h...Oi.._...:..5ls>>........n6.F.Q..v>..P.r:.a..Z....a...x..D....N...i..=L.u......<;Nv.X/*.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 624532 bytes, 2 files, at 0x44 +A "content.inf" +A "Quotable.thmx", flags 0x4, ID 13510, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):640684
                                        Entropy (8bit):7.99860205353102
                                        Encrypted:true
                                        SSDEEP:12288:eV7ivfl+kbkIrWu+2aoRjwv/cSUWauGPo2v65s4QqcT3ZCCz6CSj8aC:fdhr1+3y4MWaC2CO4V+3ZCCDsO
                                        MD5:F93364EEC6C4FFA5768DE545A2C34F07
                                        SHA1:166398552F6B7F4509732E148F93E207DD60420B
                                        SHA-256:296B915148B29751E68687AE37D3FAFD9FFDDF458C48EB059A964D8F2291E899
                                        SHA-512:4F0965B4C5F543B857D9A44C7A125DDD3E8B74837A0FDD80C1FDC841BF22FC4CE4ADB83ACA8AA65A64F8AE6D764FA7B45B58556F44CFCE92BFAC43762A3BC5F4
                                        Malicious:false
                                        Preview:MSCF............D................4...............?..........~..................M. .content.inf."..........M. .Quotable.thmx..^.u.n..[...............&...U..F.......UU.M.T5.UUQS..j..#>43fD.....`....Vr......19'...P..j.-...6n.0c....4$.c....$.4.k3aQ$.lCN.#.[.."qc....,Z...,Qt@!.@...... ...H.......9.9.y.{....[.`..s3.5.....B....W.g.d...[uv.UW..............P.8.(.?......3.....'/F...0...8.P. .O..B....K...g..L.......#s...%..|4.i....?.3b.".....g...?.........2.O23..'..O~.+..{...C.n.L......3......Y.L...?K...o......g....@.]...T..sU.....<.._.<G.......Tu.U2..v.&..<..^..e.].cY;..9.%..}...I.y.;...WM...3>.:.=.|.-.AtT2OJ.I.#...#.y....A....\]$r...lM.%5.."...+7M..J.....c...".&$.... Y.r.B;..81B. +H...b....@7K.*.F.Z...v..=..ES.f.~.."...f..ho.X.E.a`~*...C>.&..@\.[....(.....h..]...9&...sd.H .1.x.2..t.rj..o..A..^qF.S9.5.....E.{...C|.w.c/V...0Q.M...........O.7;A4u...R..Z.B.7a.C`....p.z.....f!|.u.3t....2e.wWH..'7p....E_...e.._;..k....*&E.^.f=V..{*..al.y:.4a...+.g...-..>e
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 682092 bytes, 2 files, at 0x44 +A "Berlin.thmx" +A "content.inf", flags 0x4, ID 46672, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):698244
                                        Entropy (8bit):7.997838239368002
                                        Encrypted:true
                                        SSDEEP:12288:bUfKzAwwP7XAMWtr4FvMRt4lX0hnBdThiSb32+TdysrQgn7v4EemC6:sr7AMkJ34xu1bm4ZrQaY6
                                        MD5:E29CE2663A56A1444EAA3732FFB82940
                                        SHA1:767A14B51BE74D443B5A3FEFF4D870C61CB76501
                                        SHA-256:3732EB6166945DB2BF792DA04199B5C4A0FB3C96621ECBFDEAF2EA1699BA88EE
                                        SHA-512:6BC420F3A69E03D01A955570DC0656C83C9E842C99CF7B429122E612E1E54875C61063843D8A24DB7EC2035626F02DDABF6D84FC3902184C1EFF3583DBB4D3D8
                                        Malicious:false
                                        Preview:MSCF....lh......D...............P...........lh...?..........|..................M. .Berlin.thmx............M. .content.inf..lH.lj..[...............7.I..)........P..5x.B/^y5.xk^^......D.F........s....y...?D.....*.....&....".o..pl..Q.jm?_...6......=%.p.{.)S..y...$......,4..>#.........)..."-....K....4.E...L=.......4..p.c..nQ.0..ZO.#.....e.N..`U......oS....V..X[t.E)|.h..R....$..}.{.F.7....^.....w.,...5rBR.....{.......mi...h.b......w+..;.hV......q..(.7&.Z.l...C."j........[-E4h.....v&..~.p$|\X...8.....Fj'%,.)6w...u|C..,y..E..`*Up../(....2.(....Z.....,.'...d..s..Z....5.g.?Nq..04...f...D.x....q+.b.."v`{.NL....C..... ..n......1N+.I.{W9....2r.0...BaC.....O..=...k..."..8.D\jK.B...Aj....6,B..2...I.. B..^.4..1.K+.....DP...Mr....9..x[...>........?.Zd..'._2.._..>..'.F..#.w...2..~.|........q_Wy.W.....~..Qex.km/..f......t.q..p..gm.|.x.... ,.#\Z....p....a.}...%..v.J.Es......I.b.P?...0......F.x....E..j..6.%..E..-O.k...b .^.h.Cv...Z....D.n.d:.d.F..x...[1...B..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 704319 bytes, 2 files, at 0x44 +A "content.inf" +A "Wood_Type.thmx", flags 0x4, ID 5778, number 1, extra bytes 20 in head, 51 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):723359
                                        Entropy (8bit):7.997550445816903
                                        Encrypted:true
                                        SSDEEP:12288:NPnBZX7wR3tMwYqNDQGnXTtfzO5U7yo6O7bLhe8yE3LLDok4a:JBMbYE7xzO5U917bLh/DL3oJa
                                        MD5:748A53C6BDD5CE97BD54A76C7A334286
                                        SHA1:7DD9EEDB13AC187E375AD70F0622518662C61D9F
                                        SHA-256:9AF92B1671772E8E781B58217DAB481F0AFBCF646DE36BC1BFFC7D411D14E351
                                        SHA-512:EC8601D1A0DBD5D79C67AF2E90FAD44BBC0B890412842BF69065A2C7CB16C12B1C5FF594135C7B67B830779645801DA20C9BE8D629B6AD8A3BA656E0598F0540
                                        Malicious:false
                                        Preview:MSCF....?.......D...........................?...`J..............3..............M.. .content.inf..+.........M.. .Wood_Type.thmx......r..[.........................!.wwwwqwwwwwwwwwww..."....+......nR..x..\..w..r.5R.....(|.>.$e3.!..g....f..`9NL......o./.O.bxI...7.....|........6.n."J.....4^g.........?...................o.......s3.....8. .T.j...._.Z.Q.t.k,(o.c.t.......?Z....`o........?.a....6.)....6b..../.t...........Mz....q}......C.......+{.......o...K.tQjt............7.._....O.....\....` ..............@..`....%..t....V.]........m..m....u..1.yr;..t..F.'..+{....zqvd.g._..$H..Vl...m..../....g..rG.....:*......8....h...[...a06...U.W....5.Z.W..1I..#.2.....B3...x....$PRh...\{J.c.v.y..5+Y.W.N..hG......<..F..W.d8_....c...g....p|7.]..^.o.H.[$Zj..{4......m.KZ..n.T%...4.Z..Y."q7?kuB......U....).~.......W%..!.e.U.mp.o...h...?.w...T.s.YG#......Y.}....Z.O.i.r,...n..4.\....P..m..=....f........v....g....j...*.wP..4.VK.y.z...C..oum.b.1......?.Z.>.7.!?......A..Q>..Z....-
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 937309 bytes, 2 files, at 0x44 +A "content.inf" +A "Gallery.thmx", flags 0x4, ID 44349, number 1, extra bytes 20 in head, 34 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):953453
                                        Entropy (8bit):7.99899040756787
                                        Encrypted:true
                                        SSDEEP:24576:9B1Onw3vg7aeYPagzbJ5Vhv6LnV2Dhl7GEYqVjcyd:vww3o7BYPJbJ5Vh6UCqZfd
                                        MD5:D4EAC009E9E7B64B8B001AE82B8102FA
                                        SHA1:D8D166494D5813DB20EA1231DA4B1F8A9B312119
                                        SHA-256:8B0631DA4DC79E036251379A0A68C3BA977F14BCC797BA0EB9692F8BB90DDB4D
                                        SHA-512:561653F9920661027D006E7DEF7FB27DE23B934E4860E0DF78C97D183B7CEBD9DCE0D395E2018EEF1C02FC6818A179A661E18A2C26C4180AFEE5EF4F9C9C6035
                                        Malicious:false
                                        Preview:MSCF....]M......D...............=...........]M...?..........}..."..............Li. .content.inf............Li. .Gallery.thmx.].(.Vq..[.....0Y..........v.....w.wwwww.wwwwww.w.....".83....y8..mg...o*..U..N(..@uD.:O<........{.G....~~.....c.c.5..6./|G .@#1O.B.............PT@...b.d.~..U....B.{.........0.H.....`.H.`..'S.......Ic..W..x...z....... .........g......._....o......S......p...$....._........._...K......x..?.6.U~...'./.r.................../.......5.8..2........2b.@j ....0.........``....H... ,5...........X........|..Y.QoiW..*|.......x.sO8...Yb....7...m..b.f.hv..b......=...:Ar.-...[..A\.D..g..u....].9..M...'.R-`.....<..+.....]...1.^..I.z..W{.._....L.. ...4;..6O.....9,.-.Vt+b/$7..}.O05.Y...-..S.....$*.....1."Z.r;.!..E.mMN..s .U...P%.[.P...cU...j...h.d.../.s..N/..:..X*...p5.7\}h.Q ..._.F.X.C..z$.nV..+.k..|.@.L...&.........^#.G.a..x..w!wx.8e+..E. i..$?9..8...:......|..[."..y..&y..?...W....s..._...3Z0c.....i.q.........1c.jI....W..^%xH.._...n.......&J..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 1049713 bytes, 2 files, at 0x44 +A "content.inf" +A "Savon.thmx", flags 0x4, ID 60609, number 1, extra bytes 20 in head, 37 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):1065873
                                        Entropy (8bit):7.998277814657051
                                        Encrypted:true
                                        SSDEEP:24576:qehtHA3nsAOx7yN7THwxdGpkw8R60aTcua5U4c:hhmnsBMNAxdGpV5za5Uv
                                        MD5:E1101CCA6E3FEDB28B57AF4C41B50D37
                                        SHA1:990421B1D858B756E6695B004B26CDCCAE478C23
                                        SHA-256:69B2675E47917A9469F771D0C634BD62B2DFA0F5D4AF3FD7AFE9196BF889C19E
                                        SHA-512:B1EDEA65B6D0705A298BFF85FC894A11C1F86B43FAC3C2149D0BD4A13EDCD744AF337957CBC21A33AB7A948C11EA9F389F3A896B6B1423A504E7028C71300C44
                                        Malicious:false
                                        Preview:MSCF....q.......D...........................q... ?..........{...%..............M. .content.inf.Q_.........M. .Savon.thmx...O>.o..[..............&.5....UUcC.C....A...`TU...F....".54.E.....g.-.7-D....1g...p.6......@..w(....h'?.....(..........p..J.2n$4.........A......?...........@.C.W.R.5X..:..*..I..?....r.y..~!.....!.A.a...!........O.........5.x<C...?.?....C.C.......'....F../....../.$................4.7...................P...(.w.}6.........7.....01.1r........._..?.............'.._..JOx.CFA<.........*0..2.?...>F.../...;..6-8..4...8&yb....".1%..v'..N...x......}.gYb..~L.....f[..!......Y.G.....p..r...?.p...F.Vy.....o.Whll...+...M.V...:.]...B.%.H....n..@.].zaVxf...y{.@....V.t.W....$Kp-.....7W.J..h..0A3mK.=.ub..R...W......*'T2..G#G,.^..T..XZu...U. ...76.d..#.I.JB.v...d...%.....6..O.K.[.:.L.\.....1.D..2a.>f......X...b5...ZgN.u.f...a!..."...sx....>..?.a.3.8.^._q..JS1.E..9..Lg.n.+....lE.f:j.9)Q..H1=..<.R.......{c>:.p[..S.9h.a.gL.U....8.z..z.!.....2I.~.b..2..c...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 1081343 bytes, 2 files, at 0x44 +A "Circuit.thmx" +A "content.inf", flags 0x4, ID 11309, number 1, extra bytes 20 in head, 45 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):1097591
                                        Entropy (8bit):7.99825462915052
                                        Encrypted:true
                                        SSDEEP:24576:UE9BMy98gA4cDWHkSrDans3MfEE6w8OaVuCibol0j41dwD:UE9Bdy3D4keQWt7w85VuVoaj4/Q
                                        MD5:BF95E967E7D1CEC8EFE426BC0127D3DE
                                        SHA1:BA44C5500A36D748A9A60A23DB47116D37FD61BC
                                        SHA-256:4C3B008E0EB10A722D8FEDB325BFB97EDAA609B1E901295F224DD4CB4DF5FC26
                                        SHA-512:0697E394ABAC429B00C3A4F8DB9F509E5D45FF91F3C2AF2C2A330D465825F058778C06B129865B6107A0731762AD73777389BB0E319B53E6B28C363232FA2CE8
                                        Malicious:false
                                        Preview:MSCF............D...............-,..............x?..........}...-...RU.........M. .Circuit.thmx.....RU.....M. .content.inf.g...&|..[......=..R.....=.*,.!QA?h..Q.!....Uk!.HJ.......VKuk.....q.w.w.U.....;...K.@.URA..0..B..|rv.ND(.`{..@.1.}...s?.....-...O.(V.w..1..a.....aW...a.Z..aX....5.I...!..........(. ./.d...me.( ..f.........w.......Xp.s....c..vB.98.....C.J......V ..ML.M...B.n.>...|....u!.5@t..q4....(K...u qL.S....>/%v%.2..TF.].e..'..-..L.N..c].a..(WU\o.%^..;...|o.6..L..[..;&....^p.Lu.sr,-.R=.:.8.>VOB...:.?$.*h.o....Zh.h....`.B.c.../K......b^...;2..bY.[.V.Q8....@..V7....I0c.cQN7..I.p..}..!..M....1K....+....9.2......a..W.V..........;.J .i......]%O.-......CeQ.0.c....MbP3.0.w..8w..Y...|...H;#.J.+M......>.`y..aWk|.i.BF.pJv;.....S..6....F.....RLG~..........J.=......"..........H.....h..o...u........M.6F?.F.p.B.>./*l....J.R..#P.....K......<iu..gm^..n...#c..zO"7M.O......4'>A..(.E.Cy.N.)....6.tx.r[.....7.......m.t..E?.....5.5.6.\..{.V.T.D.j..=~a^.I
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 1291243 bytes, 2 files, at 0x44 +A "content.inf" +A "Droplet.thmx", flags 0x4, ID 47417, number 1, extra bytes 20 in head, 54 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):1310275
                                        Entropy (8bit):7.9985829899274385
                                        Encrypted:true
                                        SSDEEP:24576:NN3M9UHpHZE4aubaPubP3M6d71FdtmFAjq+54/79LVzG+VnS:NN3M9UJHZE4abPyU4JtmFCq+q/7JlVS
                                        MD5:9C9F49A47222C18025CC25575337A965
                                        SHA1:E42EDB33471D7C1752DCC42C06DD3F9FDA8B25F0
                                        SHA-256:ADA7EFF0676D9CCE1935D5485F3DDE35C594D343658FB1DA42CB5A48FC3FC16A
                                        SHA-512:9FDCBAB988CBE97BFD931B727D31BA6B8ECF795D0679A714B9AFBC2C26E7DCF529E7A51289C7A1AE7EF04F4A923C2D7966D5AF7C0BC766DCD0FCA90251576794
                                        Malicious:false
                                        Preview:MSCF...........D...............9..............XJ..........}...6..............M.. .content.inf............M.. .Droplet.thmx..m7.>J..[...............2.QQPIj.*.."o^R.H5*^...^(e.W...R..x..^`..m...."..+.....{o.......Q.-....$V.N>...T]..L.... ..N.h..dOY.......S......N.%.d..d....Y.....e..$...<.m...`............@....=.z..n..[...,G..1Fn.qPDH{C<...3.Q...2..r..*...E.E.E.ErM"&a..'..W....:...?I..<.I..6o.`.d.?!..!..._.4\.._.E..).._O.S....; ..#..p.H.....c....o\.K..?$U.e.........!...J.v.....gNe._..[....#A.O.n_.....gm:P._.........{@..-g..j.69b.NH.I.$Hk?.6.n...@......'.C.._.U..:*,j.-G.....e.#.Sr.t.L......d[.[...s.....rx.3.F[.5o..:....K*.x..)M.fb...3IP.&h.Q.VX^%U.......x..l......@6.k.P..zSW.?....F..[L...4..b.l.w."&.....`.j...i.5}".~.-.....{\.:...o.'H\*+)....3.Y......\...f:.;....e........4't7..f...w..j...3....N..9`.J...P..?.....=3_.y]...f.<.......JM5.}Q/ .F.a..Z.._yh......V..>m .......a....f....!.hz..\.....F_..'z...,....h.=.......=.o..T....3.e..........$..g.2.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 1750009 bytes, 2 files, at 0x44 +A "content.inf" +A "Slate.thmx", flags 0x4, ID 28969, number 1, extra bytes 20 in head, 72 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):1766185
                                        Entropy (8bit):7.9991290831091115
                                        Encrypted:true
                                        SSDEEP:24576:O/gjMj+RP9Q07h9F75a0BXjBccHMVk2Hq2SkGa0QglyZtxmdPP2LcSUtfgfp16Yx:kJ6RP9Q07/X5V7yVF0QgktxAPutUt0zP
                                        MD5:828F96031F40BF8EBCB5E52AAEEB7E4C
                                        SHA1:CACC32738A0A66C8FE51A81ED8E27A6F82E69EB2
                                        SHA-256:640AD075B555D4A2143F909EAFD91F54076F5DDE42A2B11CD897BC564B5D7FF7
                                        SHA-512:61F6355FF4D984931E79624394CCCA217054AE0F61B9AF1A1EDED5ACCA3D6FEF8940E338C313BE63FC766E6E7161CAFA0C8AE44AD4E0BE26C22FF17E2E6ABAF7
                                        Malicious:false
                                        Preview:MSCF............D...............)q..............0?..........{...H..............M.. .content.inf.;.#........M.. .Slate.thmx.p.+..P..[......U..............p..K.!.......*...K..w..v........=....D$r...B....6 ...X.F0..d..m.s...$$r........m.)6.m3....vXn.l..o...a...V......Ru.:=2M.........T.....4S`EP......\..r,..v...G.P......'._H0]..%_............X.P.,.............H.?.-.H..".......M..&..o....R........<......`...D.H.._.G.Qv..(.*.U,.9..D...."..T..i.e../.e.."....,S...o.X.....c./..V....Z..o.O..2....{...+... ....0.@J.R.Q.m.....{.....h?u.q.O{...l.d)..Yk`.....#...u.-.m..#CXwrz4..7.>......v.E:.#.oGSKS.TX.Chm.4aQ......avH..{..j+@6[k].....`c..W8..j.v.Zh.]....4......K..#Hzyd..K}.....H|<H..\(l...+..%Z......~.S:^..d>..1..H%..7N-v.....Wu.*..b^.B.....k0gc.2.{.!...E7.}3.d...{.Ye...&#f6...:2......v..&!..k0d.p.b...,..$.....Y..60...h.N}.r...<[./........{...Es..&.nf.....2.@Fh3.9.G....l.[.C..SD/6.H.K....}..m....M..........gl.P.]..I......5....e.c...V....P...[.=.......O.eq+
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 1865728 bytes, 2 files, at 0x44 +A "content.inf" +A "Damask.thmx", flags 0x4, ID 63852, number 1, extra bytes 20 in head, 68 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):1881952
                                        Entropy (8bit):7.999066394602922
                                        Encrypted:true
                                        SSDEEP:49152:6Wp9u/ZAvKz7ZFCejPiSmYXKIr6kBwBUA:6W6Bn7ZFNiiKo2l
                                        MD5:53C5F45B22E133B28D4BD3B5A350FDBD
                                        SHA1:D180CFB1438D27F76E1919DA3E84F307CB83434F
                                        SHA-256:8AF4C7CAC47D2B9C7ADEADF276EDAE830B4CC5FFE7E765E3C3D7B3FADCB5F273
                                        SHA-512:46AD3DA58C63CA62FCFC4FAF9A7B5B320F4898A1E84EEF4DE16E0C0843BAFE078982FC9F78C5AC6511740B35382400B5F7AC3AE99BB52E32AD9639437DB481D1
                                        Malicious:false
                                        Preview:MSCF.....x......D...............l............x..`?..........|...D..............M[. .content.inf...!........M[. .Damask.thmx...o.PI..[.............../.TU.jj0..3jCUPU.jF...m.UU.P}.....PU..*........w..#....E..].................A.. w.$..@..'g.......6%:..r9..d.M;M+.r.8[d{.s..dh..(P..........!.. ..ne..f.Nc..#..Y..q....KB}..b].@..F.&.t....E.........@&.m......$w......q...:.H....p.p.....?.9x.. .....?...ao....I....................o......g.u..;."....O;....{..(k..._.w/.Z......Jb..P.O?...........?....F....ty..72......! #....v..J......?.....!,.5.7..Em.....is.h.. \.H*)i1v..zwp.....P.....x].X{O//..\....Z>z....6...+..a.c...;.K..+...?014..p.w%o^.....]...MguF...`....r.S.......eF..):.dnk#.p{..<..{..Ym...>...H......x.}.hI..M....e......*G.&.?..~.~G6.....+...D..p...._...T....F6.[Cx./Q..Xe.>.;.}>.^..:..SB.X..2.......(A..&j9....\\.......Haf+]Y...$t^Y=........><.w....tL../E...%6.Vr~MI...l.....<.0.I....7.Q8y.f.uu...I.p..O..eYYS.O......9..Qo.......:..........o.............{
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 2511552 bytes, 2 files, at 0x44 +A "content.inf" +A "Main_Event.thmx", flags 0x4, ID 59889, number 1, extra bytes 20 in head, 90 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):2527736
                                        Entropy (8bit):7.992272975565323
                                        Encrypted:true
                                        SSDEEP:49152:NFXdpz4d98p/q5jA4q+9Uf5kx6wHR8WfPJZVhWzH4dRze76YP9nJ7yyAInT76nSY:NFXdKx5sM9SmxHKexZVhutJJVpCSqa0Z
                                        MD5:F256ACA509B4C6C0144D278C7036B0A8
                                        SHA1:93F6106D0759AFD0061F73B876AA9CAB05AA8EF6
                                        SHA-256:AD26761D59F1FA9783C2F49184A2E8FE55FCD46CD3C49FFC099C02310649DC67
                                        SHA-512:08C57661F8CC9B547BBE42B4A5F8072B979E93346679ADE23CA685C0085F7BC14C26707B3D3C02F124359EBB640816E13763C7546FF095C96D2BB090320F3A95
                                        Malicious:false
                                        Preview:MSCF.....R&.....D............................R&.8?..............Z..............M). .content.inf..,........M). .Main_Event.thmx......R..[...............=.1.^xa..^...../..^x....QA^"....^/.I.{/F..F..........6Vn. ..._Hmc......<....#.{.@.....Xl../Y....Ye..'V.f.S.Vf.T..0t+..y...5O...{.....-.dT...........!...[ .ns..k.....QAA.. ....B..u.`.....{.\u8.0.....@t........K....@..w.......>...-1F...........1.E....O............_M.m..CP.O......X......g......].../..:C...Q...i.._"...M..1o...S../...9....k;...}S........y..;1o....1h......t.CL.3...].@...T...4.6.}.....M...f...[.s.."f....nZ.W......0.c.{.`.^..Oo.[.JT.2].^.f..a....kO......Q..G..s.5...V.Wj.....e...I,]...SHa..U.N.N.....v.C.....x..J{.Z.t...]WN...77BO-J......g......3:i..2..EFeL.,n..t:..,~4gt.w...M.5.'h.L..#..A&.O.ys%K.Z....F.PW..=jH...jGB.i..j.J.^.#.\n...J@.....-5.f.1jZ68.o...H2.......$O...>..ld&,#$.&_....yl.fkP$.........l....s....i.tx.~<.z...>..2.Gx..B..z.E.3.N<....`$.....b..?.w.[.X..1.=q!.s......v.......r.w
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 2573508 bytes, 2 files, at 0x44 +A "content.inf" +A "Mesh.thmx", flags 0x4, ID 62129, number 1, extra bytes 20 in head, 94 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):2591108
                                        Entropy (8bit):7.999030891647433
                                        Encrypted:true
                                        SSDEEP:49152:ZSBBeAefkpB5iXfQJgi7JBaCCRZ3cM2VDHkvSJO6qzI1tE9Rn:EBI6gbCkMPDHKSJO6qsP6n
                                        MD5:BEB12A0464D096CA33BAEA4352CE800F
                                        SHA1:F678D650B4A41676BA05C836D462F34BDC5BF648
                                        SHA-256:A44166F5C9F2553555A43586BA5DB1C1DE54D72D308A48268F27C6A00076B1CA
                                        SHA-512:B6E7CCD1ECBB9A49FC72E40771725825DAF41DDB2FF8EA4ECCE18B8FA1A59D3B2C474ADD055F30DA58C7E833A6E6555EBB77CCC324B61CA337187B4B41F7008B
                                        Malicious:false
                                        Preview:MSCF.....D'.....D............................D'..D..........z...^..............M7. .content.inf............M7. .Mesh.thmx....&~j..[.....0.................]............ww,v.\....D......3m..m!f..0..E{..?..`..A...k.:....I..........|bmG.FS...f.;.J.vzb.......R.......-....|.......ESD.....".4M..M..t.N....y..,..#.4.5.2.......'.8.Q..3.D..T....!.......&rJg...s........(..9........Dw..'....9.-..G.c............E.. .O.....a..O.._..s..)7Wz~....bJ..D...o....0..R/.#...?.......~6.Q?....?y...g.?............TP..r-...>....-..!.6...B.....\../...2....4...p$...Oge.G.?.....S.#x(..$.A~.U.%f....dJ..S.f{.g.._..3{.fm2.....Z.\o&.[k.m....ko.8..r.-.Go.OQ..'!6..f.L...Ud.$.q*.L.....R.. J.T&4g...7.2K...#k.[.].:....lk.....;c..DRx.`..&L..cpv*.>.Ngz~.{..v5.\...'C.<R:.C8.|.fE{......K...).....T...gz}..rF..Q.dof7.....D.f=cm...U|.O.]F...5zg(.. ....S..._?D....^..+.i...Z.....+X..U!4qy..._..`I..>./.W.7......=.O....BG..=..%9|...3.?...}.$"..H..u...0.......a..:t?.....8...Z..#g.=<.e.`\......KQ..U....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 3239239 bytes, 2 files, at 0x44 +A "content.inf" +A "Vapor_Trail.thmx", flags 0x4, ID 19811, number 1, extra bytes 20 in head, 111 datablocks, 0x1503 compression
                                        Category:dropped
                                        Size (bytes):3256855
                                        Entropy (8bit):7.996842935632312
                                        Encrypted:true
                                        SSDEEP:98304:wh7I1aeH9YvgK+A+a7GiiQzP4YZDpQ2+Sd6Y:w21ay93aypQzzhpBL/
                                        MD5:8867BDF5FC754DA9DA6F5BA341334595
                                        SHA1:5067CCE84C6C682B75C1EF3DEA067A8D58D80FA9
                                        SHA-256:42323DD1D3E88C3207E16E0C95CA1048F2E4CD66183AD23B90171DA381D37B58
                                        SHA-512:93421D7FE305D27E7E2FD8521A8B328063CD22FE4DE67CCCF5D3B8F0258EF28027195C53062D179CD2EBA3A7E6F6A34A7A29297D4AF57650AA6DD19D1EF8413D
                                        Malicious:false
                                        Preview:MSCF....Gm1.....D...............cM..........Gm1..D..............o... ..........MP. .content.inf...7. ......MP. .Vapor_Trail.thmx..n...N..[......L........7...+I..x...P7/...BH..Rm.\yqi.x..B....{.m.............=.....p.%.@......BpV.[......C.4..X./..Y.'SB..........0.Gr.FG.).....R\...2..Jt..1..._.4_B..................cn7H.-.....Q...1..G{G.~.. '.$......@.(....=@=..`....@.@.A. ....'.4`. .@....D...'....S.s..9.7" /....?.aY.c.........LG....k...?_.....P.....?.1.....FB..m..t...['......:...?...W..../~..z.Tr...X.@...._....3..N..p.....b...t.....^..t...~..t.8A...t_....D..3R.Z.=..{.A.8).3-5..v.isz....0A~%.s.D.4....k.K......8......)R.}f.E..n.g&:W...'E....4%T..>......b.y..[..zI....e...j.s....F.....|7826U.C.,..BY.U.F.f......"..#.m..,..._...#.\.....gPP.2.}Kas......g..3.d0.Z.Z.]..n......MY]6.....].m..D.6...?.n.20.,.#...S...JK..#.W.%.Z4.....i..CBf...../..z......n.N...U.....8t...ny...=.!..#..SF..e...1.P..@.Qx*.f.;..t..S.>..... F..)...@.Y..5j....x....vI.mM....Z.W..77...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Cabinet archive data, many, 3400898 bytes, 2 files, at 0x4c "Insight design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 106 datablocks, 0x1203 compression
                                        Category:dropped
                                        Size (bytes):3417042
                                        Entropy (8bit):7.997652455069165
                                        Encrypted:true
                                        SSDEEP:98304:1YYkj2mRz6vkkB15AW4QD0ms+FdniD60bDUpS:qYkj7d6vP7NZDLn+PM8
                                        MD5:749C3615E54C8E6875518CFD84E5A1B2
                                        SHA1:64D51EB1156E850ECA706B00961C8B101F5AC2FC
                                        SHA-256:F2D2DF37366F8E49106980377D2448080879027C380D90D5A25DA3BDAD771F8C
                                        SHA-512:A5F591BA5C31513BD52BBFC5C6CAA79C036C7B50A55C4FDF96C84D311CCDCF1341F1665F1DA436D3744094280F98660481DCA4AA30BCEB3A7FCCB2A62412DC99
                                        Malicious:false
                                        Preview:MSCF......3.....L.............................3..?..............j.....3.....t.4.............Insight design set.dotx.................Content.inf...QJ.N..[.........R.....L....N).J|E.B.$.B).3,...n.....JW....k.U1..M...3#.5....$^.....;vR...Z.nj...#......^*......a.{..(..o.v...!L`...T.-&jZ`.\.*0.....G.."b.m..F.X......$>%..?.D..H.l.j....$.......MrQ......q-....hx...6.D.3...j....n..U#R..3....sm?..xJr..............$G8..t.g...?.g.}......$P._...7.#..w..9DR....*lu....?..'.Ai..v.vl..`......B..N_....W./.;...c=oYW.lL'bv.......+...9.P..B=...*Y.SX=EL.5o....?H.e|.Fn.M[...d.v.....i......9..U..H....uq.Nrn..@..e...3....8.....s8}z..$........B....26...d..?.l....=.aeM.[..|n....H.;..7A.`....=.F...V.Y.l..8.........%e.x0S.....~..2..%.....U..#.r_.0V.v.6w.l.......Y.........v..o+....*sn.$^'.Il...akUU....w....~.....&8.Vwj.....Q.uQ..&..G.($.2.s.?m.B.~j.*..+G.W..qi..g..5.)){O........o.ow.(;.{...y;n...J...&.F2.@.;......[{'w..........`....czW.........?W...}..w....x..........
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):30
                                        Entropy (8bit):1.2389205950315936
                                        Encrypted:false
                                        SSDEEP:3:D6c7l/l/:mc7l/
                                        MD5:90C38A520C32224DD2C88496508A2FF6
                                        SHA1:3F22C7960F974F6F357B0EF619A261600681BA10
                                        SHA-256:67E3AF96D9875D3DEC649DCA32331B1D918D2C8715132242C956F6FF8E993EFB
                                        SHA-512:3236A1C23FCD2E137ED920570EFA9A77A93727144785784FEDE8C94A624497738CE32082329E9430E69A23F5AF22E0AFC50487A8D92683917FC43B9CC2A5F967
                                        Malicious:false
                                        Preview:....4_........................
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Dec 9 15:24:42 2024, mtime=Tue Dec 17 11:14:21 2024, atime=Tue Dec 17 11:14:13 2024, length=45976, window=hide
                                        Category:dropped
                                        Size (bytes):630
                                        Entropy (8bit):4.759065095477602
                                        Encrypted:false
                                        SSDEEP:12:8jKXDA3XgeY6C/AtYjAO/Mcv/nZmPXgeY6C/Kwdmo:82Tawb6qA8A5cv/nZAwb6qKwdm
                                        MD5:32E703119CEF67E51AB3A1D742926C1C
                                        SHA1:356CFB7D18FB59F7E30773553B670E021DAC94BB
                                        SHA-256:C4229D3F0647B98C38F8A5A99DDE2FF42F8F507D615D4D416236F5099AAFF9A2
                                        SHA-512:08261FB5013A756F2701CEE96B77CDCB70154EC80802FDB4FDCFA6F2C951A47BD6A91A04FBA7495C0B6D9A9118ACBCBA77EA73974BDA377EC8DE3AC259E234B6
                                        Malicious:false
                                        Preview:L..................F.... .....<.VJ....94}P...s~/}P..............................2......Y.a .174POW~1.DOC..|......Y...Y.a....k.....................#{D.1.7.4. .P.o.w.e.r. .G.l.o.b.a.l._.E.n.r.o.l.l.m.e.n.t._...d.o.c.x...d.o.c.......k...............-.......j...................C:\Users\user\Desktop\174 Power Global_Enrollment_.docx.doc..<.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.1.7.4. .P.o.w.e.r. .G.l.o.b.a.l._.E.n.r.o.l.l.m.e.n.t._...d.o.c.x...d.o.c.`.......X.......579569..........R/U....G.........A.G.......n...R/U....G.........A.G.......n...E.......9...1SPS..mD..pH.H@..=x.....h....H....g(....M....k_..............
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Tue Dec 17 11:14:14 2024, mtime=Tue Dec 17 11:15:38 2024, atime=Tue Dec 17 11:15:38 2024, length=0, window=hide
                                        Category:dropped
                                        Size (bytes):1164
                                        Entropy (8bit):4.654678548712881
                                        Encrypted:false
                                        SSDEEP:24:8i+7xRweY4CenQARwwuTqTrwD+w/Ykvsm:8i+7xRwblenRwwuTgrqYkU
                                        MD5:7ED75F6FE4F3904478752E5F02E1016B
                                        SHA1:580EADECE6A5CA81D3DA03AAA2F2F55D828CBD98
                                        SHA-256:72D3D30767D64EF313147FAE3CECC8E6EF663FE4CB34B2AFFBE9AF2B838F7D87
                                        SHA-512:13DEA84C98E70446E0B87DABA7A12D8C49B69539C2DC66B63C14848EDE298204B4B6B97E1ABE292873BBD63514020FAA9BCF6AE3497AA2303EC7E656CB5FB3B7
                                        Malicious:false
                                        Preview:L..................F........^..0}P..O4.a}P...H.a}P..........................[....P.O. .:i.....+00.../C:\...................x.1......YS...Users.d......T,*.Y.a....................:......\6.U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1......Y.a..user.<......Y...Y.a..............................M.a.o.g.a.....V.1......Y....AppData.@......Y...Y.a..............................A.p.p.D.a.t.a.....V.1......Y.a..Roaming.@......Y...Y.a..............................R.o.a.m.i.n.g.....\.1......Y.a..MICROS~1..D......Y...Y.a..............................M.i.c.r.o.s.o.f.t.....\.1......Y.a..TEMPLA~1..D......Y.a.Y.a..............................T.e.m.p.l.a.t.e.s.......a...............-.......`...................C:\Users\user\AppData\Roaming\Microsoft\Templates........\.....\.T.e.m.p.l.a.t.e.s...........................>.e.L.:..er.=....`.......X.......579569..........R/U....G............p.......n...R/U....G............p.......n...............1SPS.XF.L8C....&.m.q............/...S
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Generic INItialization configuration [folders]
                                        Category:dropped
                                        Size (bytes):117
                                        Entropy (8bit):4.8932485164264055
                                        Encrypted:false
                                        SSDEEP:3:M1USESAXkKkJ/XKJXLcjrSm4TRySAXkKkJ/XKJXLcjrSpnbJlv:MecRJ/dERJ/dAv
                                        MD5:6CA5E1C21E2B60AC5003D572DBF6E040
                                        SHA1:D90A330C2986497681C907B4F7C64984A5CBCA2A
                                        SHA-256:E156317566E87676F6EF649F4DE2B769C9B210559E2E5600E082EA16CF9B7534
                                        SHA-512:330859EF5E74996E913518094FC27DF21B678347607A04FAFDDE1D176FC88390521FF49CDDFBDB51F489D0D72DF3775217B9DC7468AD2AAA8A8D861F5573D291
                                        Malicious:false
                                        Preview:[doc]..174 Power Global_Enrollment_.docx.LNK=0..[folders]..174 Power Global_Enrollment_.docx.LNK=0..Templates.LNK=0..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):562113
                                        Entropy (8bit):7.67409707491542
                                        Encrypted:false
                                        SSDEEP:12288:/dy5Gtyp/FZ9QqjdxDfSp424XeavSktiAVE0:/dizp1ndpqpMZnV
                                        MD5:4A1657A3872F9A77EC257F41B8F56B3D
                                        SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
                                        SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
                                        SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1649585
                                        Entropy (8bit):7.875240099125746
                                        Encrypted:false
                                        SSDEEP:24576:L368X6z95zf5BbQ6U79dYy2HiTIxRboyM/LZTl5KnCc:r68kb7UTYxGIxmnp65
                                        MD5:35200E94CEB3BB7A8B34B4E93E039023
                                        SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
                                        SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
                                        SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
                                        Malicious:false
                                        Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):558035
                                        Entropy (8bit):7.696653383430889
                                        Encrypted:false
                                        SSDEEP:12288:DQ/oYjRRRRRRRRYcdY/5ASWYqBMp8xsGGEOzI7vQQwOyP:DQ/nRRRRRRRRxY/5JWYZ3GGbI8YA
                                        MD5:3B5E44DDC6AE612E0346C58C2A5390E3
                                        SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
                                        SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
                                        SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):570901
                                        Entropy (8bit):7.674434888248144
                                        Encrypted:false
                                        SSDEEP:6144:D2tTXiO/3GH5SkPQVAqWnGrkFxvay910UUTWZJarUv9TA0g8:kX32H+VWgkFxSgGTmarUv9T
                                        MD5:D676DE8877ACEB43EF0ED570A2B30F0E
                                        SHA1:6C8922697105CEC7894966C9C5553BEB64744717
                                        SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
                                        SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):523048
                                        Entropy (8bit):7.715248170753013
                                        Encrypted:false
                                        SSDEEP:6144:WfmDdN6Zfv8q5rnM6vZ02PtMZRkfW5ipbnMHxVcsOWrCMxy0sD/mcKb4rYEY:xDdQXBrMi2YtggW5ObnMH1brJpUmBU0N
                                        MD5:C276F590BB846309A5E30ADC35C502AD
                                        SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
                                        SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
                                        SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
                                        Malicious:false
                                        Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):3078052
                                        Entropy (8bit):7.954129852655753
                                        Encrypted:false
                                        SSDEEP:49152:bSEjlpY8skyFHuj2yY0ciM9U2NCVBB4YFzYFw7IaJE2VRK+Xn9DOOe9pp9N9Hu:bfp5sksA3cimUVxV05aJE2fKaDOXdN9O
                                        MD5:CDF98D6B111CF35576343B962EA5EEC6
                                        SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
                                        SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
                                        SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
                                        Malicious:false
                                        Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):777647
                                        Entropy (8bit):7.689662652914981
                                        Encrypted:false
                                        SSDEEP:6144:B04bNOJMngI856k0wwOGXMaXTLaTDmfBaN2Tx9iSUk1PdSnc0lnDlcGMcEFYYYYt:xbY6ngI46Aw5dmyYYYYYYYYY7p8d
                                        MD5:B30D2EF0FC261AECE90B62E9C5597379
                                        SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
                                        SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
                                        SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
                                        Malicious:false
                                        Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):924687
                                        Entropy (8bit):7.824849396154325
                                        Encrypted:false
                                        SSDEEP:12288:lsadD3eLxI8XSh4yDwFw8oWR+6dmw2ZpQDKpazILv7Jzny/ApcWqyOpEZULn:qLxI8XSh4yUF/oWR+mLKpYIr7l3ZQ7n
                                        MD5:97EEC245165F2296139EF8D4D43BBB66
                                        SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
                                        SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
                                        SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
                                        Malicious:false
                                        Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):966946
                                        Entropy (8bit):7.8785200658952
                                        Encrypted:false
                                        SSDEEP:24576:qBcvGBGhXQir6H1ws6+iU0YuA35VuinHX2NPs:ccvGBGdQ5CsMxQVj3yPs
                                        MD5:F03AB824395A8F1F1C4F92763E5C5CAD
                                        SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
                                        SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
                                        SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
                                        Malicious:false
                                        Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1204049
                                        Entropy (8bit):7.92476783994848
                                        Encrypted:false
                                        SSDEEP:24576:+3zSQBxvOUIpHLYTCEmS1Wu09jRalJP3sdgnmAOFt0zU4L0MRx5QNn5:+bvI5UTCPu09qP3JPOFoR4N5
                                        MD5:FD5BBC58056522847B3B75750603DF0C
                                        SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
                                        SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
                                        SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
                                        Malicious:false
                                        Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):486596
                                        Entropy (8bit):7.668294441507828
                                        Encrypted:false
                                        SSDEEP:6144:A+JBmUx0Zo24n8z/2NSYFl2qGBuv8p6+LwwYmN59wBttsdJrmXMlP1NwQoGgeL:fNgxz/g5z2BT6+Eu0ntMcczNQG5L
                                        MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
                                        SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
                                        SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
                                        SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
                                        Malicious:false
                                        Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):976001
                                        Entropy (8bit):7.791956689344336
                                        Encrypted:false
                                        SSDEEP:24576:zHM7eZGgFiHMRej4N9tpytNZ+tIw5ErZBImlX0m:zHM7eZGgFiHMRej++NZ+F5WvllZ
                                        MD5:9E563D44C28B9632A7CF4BD046161994
                                        SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
                                        SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
                                        SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):1463634
                                        Entropy (8bit):7.898382456989258
                                        Encrypted:false
                                        SSDEEP:24576:75MGNW/UpLkupMAqDJhNHK4/TuiKbdhbZM+byLH/:7ZwUpLkulkHK46iiDZHeLH/
                                        MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
                                        SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
                                        SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
                                        SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):2218943
                                        Entropy (8bit):7.942378408801199
                                        Encrypted:false
                                        SSDEEP:49152:8mwK3gH/l4hM06Wqnnl1IdO9wASFntrPEWNe7:863gHt4hM9WWnMdO9w35PEWK
                                        MD5:EE33FDA08FBF10EF6450B875717F8887
                                        SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
                                        SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
                                        SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
                                        Malicious:false
                                        Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1750795
                                        Entropy (8bit):7.892395931401988
                                        Encrypted:false
                                        SSDEEP:24576:DyeAqDJpUDH3xk8ZKIBuX3TPtd36v4o5d4PISMETGBP6eUP+xSeW3v0HKPsc:uRqUjSTPtd36AFDM/BP6eUeW3v0Fc
                                        MD5:529795E0B55926752462CBF32C14E738
                                        SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
                                        SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
                                        SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):2924237
                                        Entropy (8bit):7.970803022812704
                                        Encrypted:false
                                        SSDEEP:49152:mc4NEo4XNd5wU5qTkdC4+K9u5b/i40RKRAO/cLf68wy9yxKrOUURBgmai2prH:mJef5yTSoKMF//DRGJwLx9DBaH
                                        MD5:5AF1581E9E055B6E323129E4B07B1A45
                                        SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
                                        SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
                                        SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
                                        Malicious:false
                                        Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):2357051
                                        Entropy (8bit):7.929430745829162
                                        Encrypted:false
                                        SSDEEP:49152:tfVcGO3JiR6SgT7/bOCrKCsaFCX3CzwovQTSwW8nX:pVcG2iRedsaoXSzeOwWEX
                                        MD5:5BDE450A4BD9EFC71C370C731E6CDF43
                                        SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
                                        SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
                                        SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):3611324
                                        Entropy (8bit):7.965784120725206
                                        Encrypted:false
                                        SSDEEP:49152:ixc1kZBIabo4dTJyr3hJ50gd9OaFxTy+1Nn/M/noivF0po3M0h0Vsm:ixcaAabT83hJLdoaFxTygxcoiX3M0iCm
                                        MD5:FB88BFB743EEA98506536FC44B053BD0
                                        SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
                                        SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
                                        SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
                                        Malicious:false
                                        Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):1091485
                                        Entropy (8bit):7.906659368807194
                                        Encrypted:false
                                        SSDEEP:24576:oBpmCkw3Tg/euEB+UdoC4k7ytHkHA6B/puqW2MIkTeSBmKrZHQ:MR3c/AseydwppC7veSBmWHQ
                                        MD5:2192871A20313BEC581B277E405C6322
                                        SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
                                        SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
                                        SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
                                        Malicious:false
                                        Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):608122
                                        Entropy (8bit):7.729143855239127
                                        Encrypted:false
                                        SSDEEP:6144:Ckl6KRKwg9jf2q/bN69OuGFlC/DUhq68xOcJzGYnTxlLqU8dmTW:8yKwgZ2qY9kA7Uhq68H3ybmq
                                        MD5:8BA551EEC497947FC39D1D48EC868B54
                                        SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
                                        SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
                                        SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
                                        Malicious:false
                                        Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):5783
                                        Entropy (8bit):7.88616857639663
                                        Encrypted:false
                                        SSDEEP:96:CDG4D+8VsXzXc2zLXTJ2XFY47pk2G7HVlwFzTXNbMfmn2ivLZcreFWw5fc9ADdZm:CDG4DRGY23l2Xu47GL7YtT9V29yWvWdk
                                        MD5:8109B3C170E6C2C114164B8947F88AA1
                                        SHA1:FC63956575842219443F4B4C07A8127FBD804C84
                                        SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
                                        SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
                                        Malicious:false
                                        Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):4026
                                        Entropy (8bit):7.809492693601857
                                        Encrypted:false
                                        SSDEEP:96:VpDCBFLhxaUGm5EWA07yNdKH1FQpy8tnX8Iz3b7TrT502+fPD:VpDYFFRMNU+RtXzLf35t+3D
                                        MD5:5D9BAD7ADB88CEE98C5203883261ACA1
                                        SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
                                        SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
                                        SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
                                        Malicious:false
                                        Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):4243
                                        Entropy (8bit):7.824383764848892
                                        Encrypted:false
                                        SSDEEP:96:22MQe4zHye8/djzF+JjvtmMkkBpF7e0LTkaf:22De4zHHCvF+nRBDXoaf
                                        MD5:7BC0A35807CD69C37A949BBD51880FF5
                                        SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
                                        SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
                                        SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
                                        Malicious:false
                                        Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):16806
                                        Entropy (8bit):7.9519793977093505
                                        Encrypted:false
                                        SSDEEP:384:eSMjhqgJDGwOzHR3iCpK+QdLdfufFJ9aDn9LjDMVAwHknbz7OW:eSkhqglGwERSAHQdLhDn9AKokv7H
                                        MD5:950F3AB11CB67CC651082FEBE523AF63
                                        SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
                                        SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
                                        SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):11380
                                        Entropy (8bit):7.891971054886943
                                        Encrypted:false
                                        SSDEEP:192:VJcnLYnAVbOFLaCPLrGGbhaWEu6d3RmryqLkeAShObPb1AYcRMMXjkfa0nYBwggD:VcMC8lLrRbhy1ZqLyShYb1FHQ4C0nYQJ
                                        MD5:C9F9364C659E2F0C626AC0D0BB519062
                                        SHA1:C4036C576074819309D03BB74C188BF902D1AE00
                                        SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
                                        SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):6024
                                        Entropy (8bit):7.886254023824049
                                        Encrypted:false
                                        SSDEEP:96:bGa2onnLYHTSSxpHVTSH1bywZKmpRqiUtFvS9xrPooBpni6eDa16MUELHsrKjRBA:SJonLYzSSr1TuZNwtFZKpiiyrKXuCUd
                                        MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
                                        SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
                                        SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
                                        SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):9191
                                        Entropy (8bit):7.93263830735235
                                        Encrypted:false
                                        SSDEEP:192:oeAMExvPJMg+yE+AfJLi3+Xoj7F3sPgMG61J88eDhFWT7hFNsdJtnLYJ7tSh:v2d+hnfJLi3+4ja4WqhFWT7FsdHMA
                                        MD5:08D3A25DD65E5E0D36ADC602AE68C77D
                                        SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
                                        SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
                                        SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
                                        Malicious:false
                                        Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):4326
                                        Entropy (8bit):7.821066198539098
                                        Encrypted:false
                                        SSDEEP:96:+fF+Jrp7Yo5hnJiGa24TxEcpUeONo1w2NFocy2LQi33Z:2+f7YuhJdJ4TxEcmKwGkk3Z
                                        MD5:D32E93F7782B21785424AE2BEA62B387
                                        SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
                                        SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
                                        SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
                                        Malicious:false
                                        Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):7370
                                        Entropy (8bit):7.9204386289679745
                                        Encrypted:false
                                        SSDEEP:192:fYa+ngK2xG6HvLvoUnXxO+blKO1lt2Zg0AV:fYVn8Y6Hv3XxO+8uQZCV
                                        MD5:586CEBC1FAC6962F9E36388E5549FFE9
                                        SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
                                        SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
                                        SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
                                        Malicious:false
                                        Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):5596
                                        Entropy (8bit):7.875182123405584
                                        Encrypted:false
                                        SSDEEP:96:dGa2unnLYEB2EUAPOak380NQjqbHaPKJebgrEVws8Vw+BMa0EbdLVQaZJgDZh0pJ:UJunLYEB2EUAxk3pIYaScgYwsV4bdS0X
                                        MD5:CDC1493350011DB9892100E94D5592FE
                                        SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
                                        SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
                                        SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
                                        Malicious:false
                                        Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):3683
                                        Entropy (8bit):7.772039166640107
                                        Encrypted:false
                                        SSDEEP:96:GyfQZd6ZHNCWl9aXFkZwIq/QDsRYPf8P9QtDIs5r:G6wYtNZS1k99AmPfSOtD5r
                                        MD5:E8308DA3D46D0BC30857243E1B7D330D
                                        SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
                                        SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
                                        SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
                                        Malicious:false
                                        Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):4888
                                        Entropy (8bit):7.8636569313247335
                                        Encrypted:false
                                        SSDEEP:96:StrFZ23/juILHPzms5UTuK9CuZGEoEuZ28H1HiGa2RnnLY+tUb:SPZQ7uCHPzms5UTlqauZVHdJRnLY+tUb
                                        MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
                                        SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
                                        SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
                                        SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
                                        Malicious:false
                                        Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):6448
                                        Entropy (8bit):7.897260397307811
                                        Encrypted:false
                                        SSDEEP:192:tgaoRbo1sMjb0NiJ85oPtqcS+yaXWoa8XBzdJYnLYFtWT7:LR1sk+i4o1qc1yaukzd8MK
                                        MD5:42A840DC06727E42D42C352703EC72AA
                                        SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
                                        SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
                                        SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
                                        Malicious:false
                                        Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):5630
                                        Entropy (8bit):7.87271654296772
                                        Encrypted:false
                                        SSDEEP:96:n5ni6jKZWsD+QJaUQ7R6qYFF5QS+BEgeJam6S7ZCHuKViGa2CnnLYLt/ht:nccqxIBdQ1QS+uDJanS7ZCHHVdJCnLY5
                                        MD5:2F8998AA9CF348F1D6DE16EAB2D92070
                                        SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
                                        SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
                                        SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
                                        Malicious:false
                                        Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                        Category:dropped
                                        Size (bytes):6193
                                        Entropy (8bit):7.855499268199703
                                        Encrypted:false
                                        SSDEEP:192:WavHMKgnU2HUGFhUnkbOKoztj1QfcnLYut3d8:YKeUlGXUnC+HQSMp
                                        MD5:031C246FFE0E2B623BBBD231E414E0D2
                                        SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
                                        SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
                                        SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
                                        Malicious:false
                                        Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):3075
                                        Entropy (8bit):7.716021191059687
                                        Encrypted:false
                                        SSDEEP:48:96yn4sOBoygpySCCxwKsZCB2oLEIK+aQpUNLRQWtmMamIZxAwCC2QnyODhVOzP4:l0vCxJsZQ2ofpKvtmMdIZxAwJyODhVOE
                                        MD5:67766FF48AF205B771B53AA2FA82B4F4
                                        SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
                                        SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
                                        SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
                                        Malicious:false
                                        Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):5151
                                        Entropy (8bit):7.859615916913808
                                        Encrypted:false
                                        SSDEEP:96:WkV3UHhcZDEteEJqeSGzpG43GUR8m8b6dDLiCTfjKPnD6H5RhfuDKNtxx3+7tDLp:Wq3UBc9EJqIpGgD5dDL1DjKvDKhfnNti
                                        MD5:6C24ED9C7C868DB0D55492BB126EAFF8
                                        SHA1:C6D96D4D298573B70CF5C714151CF87532535888
                                        SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
                                        SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
                                        Malicious:false
                                        Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):333258
                                        Entropy (8bit):4.654450340871081
                                        Encrypted:false
                                        SSDEEP:6144:ybW83Zb181+MKHZR5D7H3hgtfL/8mIDbEhPv9FHSVsioWUyGYmwxAw+GIfnUNv5J:i
                                        MD5:5632C4A81D2193986ACD29EADF1A2177
                                        SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
                                        SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
                                        SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):296658
                                        Entropy (8bit):5.000002997029767
                                        Encrypted:false
                                        SSDEEP:6144:RwprAMk0qvtfL/vF/bkWPz9yv7EOMBPitjASjTQQr7IwR0TnyDkJb78plJwf33iV:M
                                        MD5:9AC6DE7B629A4A802A41F93DB2C49747
                                        SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
                                        SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
                                        SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):268317
                                        Entropy (8bit):5.05419861997223
                                        Encrypted:false
                                        SSDEEP:6144:JwprAJLR95vtfb8p4bgWPzDCvCmvQursq7vImej/yQzSS1apSiQhHDOruvoVeMUh:N9
                                        MD5:51D32EE5BC7AB811041F799652D26E04
                                        SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
                                        SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
                                        SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):255948
                                        Entropy (8bit):5.103631650117028
                                        Encrypted:false
                                        SSDEEP:6144:gwprAm795vtfb8p4bgWPWEtTmtcRCDPThNPFQwB+26RxlsIBkAgRMBHcTCwsHe5a:kW
                                        MD5:9888A214D362470A6189DEFF775BE139
                                        SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
                                        SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
                                        SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):251032
                                        Entropy (8bit):5.102652100491927
                                        Encrypted:false
                                        SSDEEP:6144:hwprA5R95vtfb8p4bgWPwW6/m26AnV9IBgIkqm6HITUZJcjUZS1XkaNPQTlvB2zr:JA
                                        MD5:F425D8C274A8571B625EE66A8CE60287
                                        SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
                                        SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
                                        SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):284415
                                        Entropy (8bit):5.00549404077789
                                        Encrypted:false
                                        SSDEEP:6144:N9G5o7Fv0ZcxrStAtXWty8zRLYBQd8itHiYYPVJHMSo27hlwNR57johqBXlwNR2b:y
                                        MD5:33A829B4893044E1851725F4DAF20271
                                        SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
                                        SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
                                        SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):294178
                                        Entropy (8bit):4.977758311135714
                                        Encrypted:false
                                        SSDEEP:6144:ydkJ3yU0orh0SCLVXyMFsoiOjWIm4vW2uo4hfhf7v3uH4NYYP4BpBaZTTSSamEUD:b
                                        MD5:0C9731C90DD24ED5CA6AE283741078D0
                                        SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
                                        SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
                                        SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):270198
                                        Entropy (8bit):5.073814698282113
                                        Encrypted:false
                                        SSDEEP:6144:JwprAiaR95vtfb8pDbgWPzDCvCmvQursq7vImej/yQ4SS1apSiQhHDOruvoVeMUX:We
                                        MD5:FF0E07EFF1333CDF9FC2523D323DD654
                                        SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
                                        SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
                                        SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):217137
                                        Entropy (8bit):5.068335381017074
                                        Encrypted:false
                                        SSDEEP:6144:AwprA3Z95vtf58pb1WP2DCvCmvQursq7vIme5QyQzSS1apSiQhHDlruvoVeMUwFj:4P
                                        MD5:3BF8591E1D808BCCAD8EE2B822CC156B
                                        SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
                                        SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
                                        SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):254875
                                        Entropy (8bit):5.003842588822783
                                        Encrypted:false
                                        SSDEEP:6144:MwprAnniNgtfbzbOWPuv7kOMBLitjAUjTQLrYHwR0TnyDkHqV3iPr1zHX5T6SSXj:a
                                        MD5:377B3E355414466F3E3861BCE1844976
                                        SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
                                        SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
                                        SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):344303
                                        Entropy (8bit):5.023195898304535
                                        Encrypted:false
                                        SSDEEP:6144:UwprANnsqvtfL/vF/bkWPRMMv7EOMBPitjASjTQQr7IwR0TnyDk1b78plJwf33iD:6
                                        MD5:F079EC5E2CCB9CD4529673BCDFB90486
                                        SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
                                        SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
                                        SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):250983
                                        Entropy (8bit):5.057714239438731
                                        Encrypted:false
                                        SSDEEP:6144:JwprA6OS95vtfb8p4bgWPzkhUh9I5/oBRSifJeg/yQzvapSiQhHZeruvoXMUw3im:uP
                                        MD5:F883B260A8D67082EA895C14BF56DD56
                                        SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
                                        SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
                                        SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):51826
                                        Entropy (8bit):5.541375256745271
                                        Encrypted:false
                                        SSDEEP:384:erH5dYPCA4t3aEFGiSUDtYfEbi5Ry/AT7/6tHODaFlDSomurYNfT4A0VIwWNS89u:Q6Cbh9tENyWdaFUSYNfZS89/3qtEu
                                        MD5:2AB22AC99ACFA8A82742E774323C0DBD
                                        SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
                                        SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
                                        SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
                                        Malicious:false
                                        Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):47296
                                        Entropy (8bit):6.42327948041841
                                        Encrypted:false
                                        SSDEEP:768:ftjI1BT8N37szq00s7dB2wMVJGHR97/RDU5naXUsT:fJIPTfq0ndB2w1bpsE
                                        MD5:5A53F55DD7DA8F10A8C0E711F548B335
                                        SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
                                        SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
                                        SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
                                        Malicious:false
                                        Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):34415
                                        Entropy (8bit):7.352974342178997
                                        Encrypted:false
                                        SSDEEP:768:ev13NPo9o5NGEVIi3kvH+3SMdk7zp3tE2:ev13xoOE+R3BkR7
                                        MD5:7CDFFC23FB85AD5737452762FA36AAA0
                                        SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
                                        SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
                                        SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
                                        Malicious:false
                                        Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):3465076
                                        Entropy (8bit):7.898517227646252
                                        Encrypted:false
                                        SSDEEP:98304:n8ItVaN7vTMZ9IBbaETXbI8ItVaN7vTMZ9IBbaEiXbY:8ItwNX9BvTvItwNX9BvoM
                                        MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
                                        SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
                                        SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
                                        SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
                                        Malicious:false
                                        Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):19560
                                        Entropy (8bit):7.476801086955001
                                        Encrypted:false
                                        SSDEEP:384:JQybf+BNxt/ZtNNf10PuJx9ILgq9Q4kvaQRI5bwhT6lwm3Sd7XKKN9aGM:QxllN90mv9ILZ92+xTlwmuDMGM
                                        MD5:58688C455E7915C6493E57B0445FE1A5
                                        SHA1:D8F20C3C67085EB90C265CDB38DBBD509D0A773F
                                        SHA-256:37814CA17C5CB73E4FFF44CF53F5979601310FE154C8CD0B519B7B6FB5586F77
                                        SHA-512:EB442368EA1110D087A7B64100B2C8396447450D4FCE6AE37FC9BD72D45FCAF6D0C6AD1792396CD07ABB5A8ED138383EF4DF9AB29E8B34082851985C9BD7BAE8
                                        Malicious:false
                                        Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):162
                                        Entropy (8bit):2.876668760038439
                                        Encrypted:false
                                        SSDEEP:3:blRmMgWVl//nuO2lP9kXkTeG/M:bzmMgWVl/D2llXH0
                                        MD5:FF59391B14B6F8E09FF4184353A5B461
                                        SHA1:0202D90697BEECE50AA68E38BA354798DBA811CE
                                        SHA-256:89C0B5CAD46AFE20FC549197B03F8C41D80386AD0C5BF45DAEF9949023B1A088
                                        SHA-512:195A78977C43B25523AA21BB3D3BCAD665705BE9065011F8334D6BD5002469D3B282AF10968661BAF05BBD79A71A726B5B4B2EB538BA583E39B46449DC87A164
                                        Malicious:false
                                        Preview:.user..................................................M.a.o.g.a..............[.3.............s.3......O|r...+..1....0f.ur...0f.ur....E.5.....q.3..............3
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Microsoft Word 2007+
                                        Category:dropped
                                        Size (bytes):19560
                                        Entropy (8bit):7.476801086955001
                                        Encrypted:false
                                        SSDEEP:384:JQybf+BNxt/ZtNNf10PuJx9ILgq9Q4kvaQRI5bwhT6lwm3Sd7XKKN9aGM:QxllN90mv9ILZ92+xTlwmuDMGM
                                        MD5:58688C455E7915C6493E57B0445FE1A5
                                        SHA1:D8F20C3C67085EB90C265CDB38DBBD509D0A773F
                                        SHA-256:37814CA17C5CB73E4FFF44CF53F5979601310FE154C8CD0B519B7B6FB5586F77
                                        SHA-512:EB442368EA1110D087A7B64100B2C8396447450D4FCE6AE37FC9BD72D45FCAF6D0C6AD1792396CD07ABB5A8ED138383EF4DF9AB29E8B34082851985C9BD7BAE8
                                        Malicious:false
                                        Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:Unicode text, UTF-16, little-endian text, with no line terminators
                                        Category:dropped
                                        Size (bytes):2
                                        Entropy (8bit):1.0
                                        Encrypted:false
                                        SSDEEP:3:Qn:Qn
                                        MD5:F3B25701FE362EC84616A93A45CE9998
                                        SHA1:D62636D8CAEC13F04E28442A0A6FA1AFEB024BBB
                                        SHA-256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
                                        SHA-512:98C5F56F3DE340690C139E58EB7DAC111979F0D4DFFE9C4B24FF849510F4B6FFA9FD608C0A3DE9AC3C9FD2190F0EFAF715309061490F9755A9BFDF1C54CA0D84
                                        Malicious:false
                                        Preview:..
                                        Process:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):162
                                        Entropy (8bit):2.8855365754976177
                                        Encrypted:false
                                        SSDEEP:3:blRmMyx3/3qVlsFukLpAI+E9Dxx:bzmMu/qU96Dm/
                                        MD5:9E090330D5B066294EBF0C2314DD4EFC
                                        SHA1:2F1D5C33C8FEF91827573E33FE18986554331450
                                        SHA-256:1299BB5BC748CAF553F18C6DCEFA1C98FB9AFE6EF97F5399CD1F47D070154EBD
                                        SHA-512:470EC717A0F6243676714E72E93DE642A12A5D102059524A2DDA55A5DBB350B649A8792E4BF368B6637DE84986FF2F27A1A1BC2A3A920F29582977EFA51BA384
                                        Malicious:false
                                        Preview:.user..................................................M.a.o.g.a........{r....6.......6.......................................s~/}P..Y$.x.....a2}P..........6..3
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:ASCII text, with no line terminators
                                        Category:downloaded
                                        Size (bytes):9
                                        Entropy (8bit):2.94770277922009
                                        Encrypted:false
                                        SSDEEP:3:OFB:OFB
                                        MD5:9E076F5885F5CC16A4B5AEB8DE4ADFF5
                                        SHA1:475C848673A3F79FA778F01C2BD5A721D4C41707
                                        SHA-256:E3EBAA16DD9D9B9FC107C42183FB6CF9D22927E1AF03DBBDFA0CCC38E4E4AC31
                                        SHA-512:4D384838C78C74F56DE20DE3FE125B9FE4D40B7C9FB5D767B647F05AEDE6BF63431F4F08AC464E188E77B227BECC3AB4BA86272F30B53D91B15003D814E06D2E
                                        Malicious:false
                                        URL:https://nhlnkc.com/favicon.ico
                                        Preview:Not found
                                        File type:Microsoft Word 2007+
                                        Entropy (8bit):6.9045339858894765
                                        TrID:
                                        • Word Microsoft Office Open XML Format document (27504/1) 77.45%
                                        • ZIP compressed archive (8000/1) 22.53%
                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.02%
                                        File name:174 Power Global_Enrollment_.docx.doc
                                        File size:45'976 bytes
                                        MD5:6c8a333d687e2fa1f33743f871bb91da
                                        SHA1:707b8e6335ae0bab3c1655fa6171cd9c40a5b9ed
                                        SHA256:8793e8d51991da9adf6b67071cc9086dd80bd246fc06fb7edd15770eb05f4d2a
                                        SHA512:c13fa85b57b8f904219d83618d6edc5261fd96d2d344f4f154bf861e9f4c177095a843c1feb3fd97ef755363dfd0d4d406f4f08d6db5cb24036190fc3e4f7af2
                                        SSDEEP:768:C7NGvv4j46QmESr1A0KrNLOFZyc4IAUnfF5Xgd+F+X59DYxAKl+mDGjmBGgYl8dg:C7svAj461EShADrNLObyc4Ih+X59Dsdo
                                        TLSH:C723E7E2E9F2485DD34005F052A06202BF6CB0D753E56546B28EDFE9AF8BD91399B3C4
                                        File Content Preview:PK...........Y................word/PK...........Y................word/media/PK...........Y.B..ZL..ZL..+...word/media/image-jBwky4LB7UeCGjcQ_-u9z.jpeg......JFIF..............Compressed by jpeg-recompress.....................................................
                                        Icon Hash:35e1cc889a8a8599
                                        TimestampSource PortDest PortSource IPDest IP
                                        Dec 17, 2024 13:14:06.897303104 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:06.898040056 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:06.898092031 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:06.898180962 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:06.898498058 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:06.898518085 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:06.908195019 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.908320904 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.908359051 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.908412933 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.912420034 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.912508965 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.912517071 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.912564039 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.920847893 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.920960903 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.920981884 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.921031952 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.929344893 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.929457903 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.929467916 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.929518938 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.937742949 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.937865973 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.937894106 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.937954903 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.941376925 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:06.945334911 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:06.945952892 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.946070910 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.946135044 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.946135044 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.954384089 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.954464912 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.954503059 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.954550982 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:06.962780952 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:06.962868929 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:07.013036966 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:07.013123035 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:07.013148069 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:07.013175964 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:07.017165899 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:07.017241955 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:07.017324924 CET4434974820.223.36.55192.168.2.24
                                        Dec 17, 2024 13:14:07.017369986 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:07.046377897 CET49731443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.046478987 CET49729443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.046597004 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.046737909 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.046799898 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.061456919 CET4434975220.189.173.11192.168.2.24
                                        Dec 17, 2024 13:14:07.061614990 CET49752443192.168.2.2420.189.173.11
                                        Dec 17, 2024 13:14:07.166363955 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.166399956 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.166517973 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.166579008 CET4434973172.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.166636944 CET49731443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.167262077 CET4434972972.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.167347908 CET49729443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.255161047 CET4434975220.189.173.11192.168.2.24
                                        Dec 17, 2024 13:14:07.255321980 CET49752443192.168.2.2420.189.173.11
                                        Dec 17, 2024 13:14:07.255449057 CET49752443192.168.2.2420.189.173.11
                                        Dec 17, 2024 13:14:07.362126112 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.375436068 CET4434975220.189.173.11192.168.2.24
                                        Dec 17, 2024 13:14:07.414062023 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.450082064 CET4434975220.189.173.11192.168.2.24
                                        Dec 17, 2024 13:14:07.450191975 CET49752443192.168.2.2420.189.173.11
                                        Dec 17, 2024 13:14:07.557326078 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.557391882 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.557518005 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.592724085 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.592758894 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.625116110 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.625149965 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.716459036 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.716484070 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.748610973 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.748630047 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.762300014 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:07.763221979 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:07.763242960 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:07.764734983 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:07.764817953 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:07.767057896 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:07.767154932 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:07.820796013 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:07.820821047 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:07.867676020 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:07.905824900 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:07.905966997 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:07.905980110 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:07.905996084 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:07.906019926 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:07.906035900 CET8049761199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:14:07.906049013 CET4976180192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:14:07.906049013 CET4976180192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:14:07.906086922 CET4976180192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:14:07.908890963 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.909221888 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.909291029 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.913110971 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.913146019 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.913203001 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.921500921 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.921617985 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.921684027 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.929956913 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.930145979 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.930202007 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.938579082 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.938600063 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.938673019 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.946728945 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.946908951 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.946975946 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.955161095 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.955393076 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.955465078 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.963901043 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.963927984 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.964013100 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.972090006 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.972264051 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:07.972338915 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:07.980535984 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.023880005 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.101294994 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.101320028 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.101393938 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.104505062 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.104738951 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.104813099 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.111922026 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.111941099 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.112029076 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.118921995 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.119102955 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.119141102 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.126045942 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.126184940 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.126239061 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.133143902 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.133435965 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.133497953 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.140225887 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.140296936 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.140352964 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.147296906 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.147399902 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.147459030 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.154498100 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.154557943 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.154612064 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.161582947 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.161616087 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.161708117 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.168662071 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.168823004 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.168884993 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.175795078 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.175929070 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.175983906 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.182944059 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.183034897 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.183089972 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.190061092 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.190152884 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.190208912 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.197221041 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.197305918 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.197370052 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.204368114 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.204459906 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.204515934 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.211582899 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.211622000 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.211705923 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.218600988 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.218688011 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.218744040 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.225719929 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.273895979 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.293427944 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.293453932 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.293562889 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.296153069 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.296236038 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.296294928 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.302227974 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.302315950 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.302448034 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.308182001 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.308309078 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.308367968 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.314145088 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.314248085 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.314301968 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.319931984 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.320029974 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.320085049 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.325299978 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.325546980 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.325608969 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.330545902 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.330646992 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.330703974 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.336016893 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.336102962 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.336162090 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.340516090 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.340601921 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.340646029 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.345568895 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.345650911 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.345706940 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.350179911 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.350274086 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.350326061 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.354831934 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.355035067 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.355093002 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.359452009 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.359549046 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.359599113 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.364053965 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.364166021 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.364223003 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.368714094 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.368818045 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.368871927 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.373393059 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.373459101 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.373516083 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.377952099 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.378051996 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.378104925 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.382572889 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.382687092 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.382740021 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.387247086 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.387361050 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.387419939 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.391896963 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.392000914 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.392054081 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.396543026 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.396642923 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.396693945 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.432780027 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:08.435139894 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:08.435174942 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:08.436780930 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:08.436887026 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:08.439177036 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:08.439284086 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:08.485234976 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.485279083 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.485337019 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.486778975 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.486874104 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.486921072 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.490061045 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.490159035 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.490206003 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.493331909 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.493654013 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.493706942 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.496681929 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.496764898 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.496812105 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.499844074 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.499943972 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.499993086 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.502983093 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.503021955 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.503068924 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.506001949 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.506104946 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.506160021 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.509264946 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.509398937 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.509449005 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.512074947 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.512165070 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.512212992 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.514956951 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.515065908 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.515121937 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.517826080 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.517935038 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.517983913 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.520592928 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.520706892 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.520756960 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.523449898 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.523525000 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.523570061 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.526185989 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.526309967 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.526360035 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.528990984 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.529192924 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.529242992 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.531754971 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.531857967 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.531908989 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.533200979 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:08.534526110 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.534612894 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.534660101 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.537301064 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.537369013 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.537426949 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.540160894 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.540271044 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.540319920 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.542802095 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.542902946 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.542968035 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.545588970 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.545672894 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.545718908 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.548350096 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.548468113 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.548516989 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.551148891 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.551209927 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.551258087 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.553890944 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.554012060 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.554064035 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.556708097 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.556791067 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.556843042 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.559462070 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.559652090 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.559705019 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.562179089 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.562266111 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.562314987 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.564968109 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.565083981 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.565134048 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.567774057 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.567878962 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.567923069 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.570537090 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.570646048 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.570717096 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.573369980 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.573390007 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.573451996 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.576004028 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:08.585165977 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:08.617657900 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:08.651352882 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:08.651479006 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:08.653199911 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:08.704881907 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:08.849211931 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:08.849235058 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:08.849287033 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:09.036484957 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.036582947 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.042305946 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:09.042330027 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:09.042427063 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:09.156816959 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.156833887 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.189860106 CET4976180192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:14:09.352924109 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.353425980 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.354187012 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.354266882 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.354341984 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.354381084 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.361473083 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.361602068 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.361612082 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.361659050 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.368679047 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.368702888 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.368802071 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.376351118 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.376374006 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.376477957 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.384985924 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.385086060 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.385122061 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.385154963 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.393202066 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.393224001 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.393357992 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.401370049 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.401463032 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.401518106 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.401536942 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.410561085 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.410586119 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.410701990 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.418272018 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.418525934 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.473298073 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.546345949 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.546485901 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.546592951 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.550265074 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.550298929 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.550334930 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.557282925 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.557365894 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.557454109 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.564323902 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.564418077 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.564481974 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.571609020 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.571683884 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.571724892 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.578787088 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.578852892 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.578860998 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.586014032 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.586095095 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.586112022 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.593339920 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.593411922 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.593561888 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.600492954 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.600559950 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.600574017 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.608721972 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.608800888 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.608808041 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.614943027 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.615014076 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.615040064 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.622143984 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.622221947 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.622335911 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.629353046 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.629400015 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.629412889 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.636600018 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.636668921 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.636715889 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.643898964 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.643913984 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.643971920 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.651070118 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.651151896 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.651194096 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.658437967 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.658507109 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.658533096 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.665503979 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.665579081 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.738481998 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.738610029 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.738692045 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.741662025 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.741727114 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.741775990 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.747885942 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.747980118 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.748156071 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.754129887 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.754236937 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.754291058 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.760596037 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.760627031 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.760685921 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.766870975 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.766928911 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.766982079 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.773591042 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.773658991 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.773710966 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.778623104 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.778707027 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.778763056 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.783873081 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.784003973 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.784053087 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.790713072 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.790823936 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.790884972 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.794745922 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.794856071 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.794909000 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.798362017 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.798379898 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.798433065 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.802745104 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.802854061 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.802900076 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.808520079 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.808624983 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.808686972 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.812549114 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.812644005 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.812695026 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.817567110 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.817713022 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.817770004 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.822830915 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.822849989 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.822931051 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.827059031 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.827130079 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.827198029 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.831674099 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.831804037 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.831854105 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.836505890 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.836580992 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.836627960 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.841236115 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.841303110 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.841346025 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.847649097 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.847770929 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.847812891 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.851097107 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.851212978 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.851253986 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.855658054 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.855773926 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.855814934 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.860611916 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.860722065 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.860761881 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.865314007 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.932077885 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:09.932161093 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:09.967350960 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:10.088275909 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:10.283278942 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:10.444988012 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:10.445019007 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:10.477024078 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:10.565145969 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:10.565409899 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:10.613070965 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.613182068 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.613308907 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.613480091 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.613503933 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.670650005 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:10.763942957 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:10.764028072 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:10.790757895 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:11.841011047 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.841393948 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.841461897 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.842940092 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.843034983 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.844855070 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.844952106 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.977030039 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.977072954 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:12.093662977 CET49745443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:12.093806982 CET49748443192.168.2.2420.223.36.55
                                        Dec 17, 2024 13:14:12.093858957 CET4974680192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:14:12.094028950 CET4975180192.168.2.24192.229.221.95
                                        Dec 17, 2024 13:14:12.164516926 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:12.531383991 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.531430960 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.531517982 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.531624079 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.531702995 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.531764984 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.531807899 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.531871080 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.531929970 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.531982899 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.532006979 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.532058954 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.532255888 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.532273054 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.532320976 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.534216881 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.534241915 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.534984112 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.534998894 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.535711050 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.535773993 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.536438942 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.536458015 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:12.537168980 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:12.537221909 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:13.262162924 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:14:13.262162924 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:14:13.262226105 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:14:13.382075071 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.382138968 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.382170916 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.382301092 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.382395983 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.382446051 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.616080046 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.758328915 CET49712443192.168.2.24104.126.37.201
                                        Dec 17, 2024 13:14:13.774478912 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:14:13.808005095 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:13.809108019 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:14:13.928946018 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:14:14.076709986 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.076805115 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.076822042 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.076915979 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.077553988 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.077660084 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.079138041 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.079216003 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.079257965 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.079339981 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.113920927 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.113946915 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.115642071 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.115794897 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.116950989 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.116980076 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.118704081 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.118772030 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.293565035 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.294013977 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.294106960 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.294152021 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.294209003 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.294672012 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.294950008 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.294975996 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.295025110 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.295036077 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.295068026 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.295123100 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.298964977 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.299088955 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.299300909 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.299340010 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.300292969 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.300327063 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.300415039 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.300479889 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.302596092 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.302721977 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.302787066 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.302809954 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.302860975 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.304297924 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.304367065 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.309561014 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.309679985 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.309753895 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.309770107 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.310039043 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.310066938 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.310267925 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.310326099 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.310343027 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.310400963 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.324906111 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.326351881 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.327109098 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.327786922 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.329130888 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.367338896 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.367340088 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.367378950 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.371332884 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.371398926 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.686870098 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.686933994 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687002897 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687031031 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.687062979 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687109947 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687127113 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687146902 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.687156916 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.687172890 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.687175035 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687201023 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.687227011 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.687256098 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.687278032 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.690090895 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.690115929 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.690130949 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.690179110 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.690222025 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.690237999 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.690459013 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.776370049 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.776403904 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.776449919 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.776465893 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.776482105 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.776515961 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.785702944 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.785726070 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.785742044 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.785810947 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.785842896 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.785866022 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.785912991 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.808645964 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.808662891 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.808801889 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.808825970 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.808875084 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.817257881 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.817346096 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889413118 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889432907 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889447927 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889493942 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889513016 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889522076 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889594078 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889606953 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889658928 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889686108 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889703989 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889725924 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889725924 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889733076 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889755964 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.889786959 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.889808893 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.930424929 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.930463076 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.930529118 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.930553913 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.930604935 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.930628061 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.942637920 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.942682981 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.942701101 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.942708969 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.942744970 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.942806959 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.942816973 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.942823887 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:14.942868948 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.942884922 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:14.944335938 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.011766911 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.011782885 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.011815071 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.011869907 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.011940002 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.011981010 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.012003899 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.020067930 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.020145893 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.020170927 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.020323038 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.042366982 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.042450905 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.042459965 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.042509079 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.056044102 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.056071043 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.056174040 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.056232929 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.056817055 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.064582109 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.064677954 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.064687967 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.064732075 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.094572067 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.094652891 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.094665051 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.094707012 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.094831944 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.094866037 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.094913960 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.094979048 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.095009089 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.095025063 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.096642971 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.096709967 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.096739054 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.096765995 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.096807003 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.096807003 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.100780010 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.100812912 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.100866079 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.100918055 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.100951910 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.101037979 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.115164042 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.115189075 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.115245104 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.115277052 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.115350962 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.115350962 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.120923996 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.120949030 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.121012926 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.121061087 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.121094942 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.121115923 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.122369051 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.122400045 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.122467041 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.122514963 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.122548103 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.123327971 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.134751081 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.134773970 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.134829044 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.134856939 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.134872913 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.135014057 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.137628078 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.137653112 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.137711048 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.137751102 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.137783051 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.137805939 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.141906977 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.141937971 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.141999960 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.142008066 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.142033100 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.142047882 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.154274940 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.154294014 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.154356003 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.154427052 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.154467106 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.154603004 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.158096075 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.158185005 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.158224106 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.158269882 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.158298969 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.158322096 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.161449909 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.161488056 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.161549091 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.161618948 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.161678076 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.161678076 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.186875105 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.186907053 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.186954975 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.186986923 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.187011003 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.187210083 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.199019909 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.199095964 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.199121952 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.199163914 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.217053890 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.217158079 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.217183113 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.217221975 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.218497992 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.218528986 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.218590975 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.218626976 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.218650103 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.218674898 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.233999014 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.234091043 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.234113932 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.234155893 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.242372036 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.242393017 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.242460012 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.242499113 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.242521048 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.242538929 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.253844023 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.253942013 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.253948927 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.253994942 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.259855032 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.259877920 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.259955883 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.259988070 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.262548923 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.262726068 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.262732029 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.262747049 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.263282061 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.271393061 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.271471024 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.271493912 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.271533966 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.283231020 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.283297062 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.283325911 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.283361912 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.284573078 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.284652948 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.284661055 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.284684896 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.284717083 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.284730911 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.286082029 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.286144018 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.286164999 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.286191940 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.286207914 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.286231041 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.286587954 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.286642075 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.286665916 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.286681890 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.286722898 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.286741018 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.291531086 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.291620016 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.291644096 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.291691065 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.301995039 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.302026987 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.302088022 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.302109957 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.302135944 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.302158117 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.303806067 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.303828955 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.303889990 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.303946018 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.303985119 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.304292917 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.304486036 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.304512978 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.304544926 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.304564953 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.304600954 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.304620981 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.316849947 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.316869020 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.316916943 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.316936970 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.316962004 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.316984892 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.318995953 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.319017887 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.319065094 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.319083929 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.319104910 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.319128036 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.319571972 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.319597960 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.319632053 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.319639921 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.319670916 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.319684982 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.333920956 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.333945036 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.333993912 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.334016085 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.334034920 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.334054947 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.336611032 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.336638927 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.336678982 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.336699009 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.336719990 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.336736917 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.337143898 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.337169886 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.337205887 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.337213993 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.337239981 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.337271929 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.351206064 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.351231098 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.351288080 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.351332903 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.351361036 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.351385117 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.353110075 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.353131056 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.353205919 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.353229046 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.353269100 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.354469061 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.354491949 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.354525089 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.354537010 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.354562044 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.354584932 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.367372990 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.367423058 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.367474079 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.367496967 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.367511034 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.367532969 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.367852926 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.367903948 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.367928028 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.367934942 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.367958069 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.367976904 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.370668888 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.370692015 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.370734930 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.370760918 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.370780945 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.370799065 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.370923996 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.370949030 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.370982885 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.370991945 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.371011972 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.371040106 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.371834993 CET4434974923.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:15.372004032 CET4434974923.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:15.372049093 CET49749443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:15.383718967 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.383742094 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.383779049 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.383797884 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.383866072 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.383866072 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.384682894 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.384733915 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.384752989 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.384762049 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.384794950 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.384818077 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.388395071 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.388425112 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.388463974 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.388480902 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.388519049 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.392488003 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.392556906 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.392585039 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.392626047 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.399708033 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.399732113 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.399795055 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.399816036 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.399857044 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.403625011 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.403695107 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.403716087 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.403759003 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.411690950 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.411761999 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.411783934 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.411824942 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.415361881 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.415386915 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.415452957 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.415472031 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.415487051 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.415515900 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.418473959 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.418530941 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.418545961 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.418576956 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.427709103 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.427788973 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.427823067 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.427874088 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.429940939 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.429965973 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.430017948 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.430036068 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.430064917 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.430080891 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.434776068 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.434850931 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.434859991 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.434917927 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.441639900 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.441714048 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.441730976 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.441782951 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.445540905 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.445568085 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.445619106 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.445636988 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.445653915 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.445681095 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.450834990 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.450907946 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.450913906 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.450954914 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.457854986 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.457947969 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.457983971 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.458256960 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.459043026 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.459063053 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.459136009 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.459155083 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.459239006 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.465831041 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.465913057 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.465940952 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.465996981 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.470585108 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.470618963 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.470659018 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.470676899 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.470693111 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.470710993 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.472918034 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.472991943 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.473012924 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.473069906 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.475902081 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.475945950 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.475979090 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.476006985 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.476027012 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.476063967 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.480338097 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.480401993 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.480427027 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.480447054 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.480473995 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.480496883 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.482048988 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.482142925 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.482157946 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.482211113 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.484848976 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.484869957 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.484910011 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.484924078 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.484967947 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.484978914 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.488974094 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.489073038 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.489087105 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.489142895 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.489811897 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.489846945 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.489887953 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.489908934 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.489933968 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.489953041 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.494517088 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.494570017 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.494604111 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.494625092 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.494648933 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.494739056 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.496035099 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.496057034 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.496093035 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.496105909 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.496124983 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.496144056 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.502533913 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.502551079 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.502607107 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.502636909 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.502655029 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.502693892 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.505574942 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.505625010 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.505650043 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.505673885 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.505692959 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.505719900 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.508644104 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.508665085 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.508717060 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.508732080 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.508754015 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.508773088 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.512943029 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.512962103 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.513004065 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.513022900 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.513044119 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.513063908 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.517870903 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.517924070 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.517941952 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.517963886 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.517985106 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.518021107 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.520636082 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.520657063 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.520745039 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.520765066 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.520828009 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.524883986 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.524926901 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.524950981 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.524976015 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.524996996 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.525012970 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.529328108 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.529381037 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.529397964 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.529411077 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.529437065 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.529453993 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.531779051 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.531800985 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.531832933 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.531841040 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.531872988 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.531935930 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.535765886 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.535810947 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.535834074 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.535854101 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.535871983 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.535907984 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.541492939 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.541515112 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.541575909 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.541591883 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.541623116 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.541636944 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.543868065 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.543889046 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.543932915 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.543940067 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.543972969 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.543987989 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.547586918 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.547645092 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.547732115 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.547758102 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.547781944 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.547806025 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.553885937 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.553913116 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.553971052 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.553992987 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.554012060 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.554040909 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.554335117 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.554356098 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.554394007 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.554404020 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.554426908 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.554451942 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.558816910 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.558840036 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.558919907 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.558939934 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.558955908 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.558981895 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.559346914 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.559392929 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.559422970 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.559432983 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.559457064 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.559473991 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.560873032 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.560934067 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.560959101 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.560983896 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.561001062 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.561002970 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.561028957 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.561057091 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.570336103 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.570354939 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.570502996 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.570523024 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.570566893 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.581094027 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.581113100 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.581211090 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.581235886 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.581285000 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.581636906 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.581726074 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.581779003 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.581837893 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.587455034 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.587538958 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.587554932 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.587609053 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.590049982 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.590068102 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.590147018 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.590172052 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.590214968 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.592792034 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.592875004 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.592889071 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.592945099 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.600043058 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.600136042 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.600150108 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.600214958 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.601854086 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.601867914 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.601941109 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.601969957 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.602016926 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.605875969 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.605966091 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.605972052 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.606015921 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.610270977 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.610290051 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.610348940 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.610368013 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.610382080 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.610398054 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.611491919 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.611562014 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.611568928 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.611609936 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.615899086 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.615972042 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.615978003 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.616020918 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.620100975 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.620117903 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.620186090 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.620206118 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.620255947 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.620688915 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.620750904 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.620758057 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.620795965 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.626743078 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.626846075 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.626859903 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.626913071 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.630244970 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.630265951 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.630322933 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.630343914 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.630359888 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.630381107 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.630691051 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.630764961 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.630779028 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.630835056 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.636857986 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.636996031 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.637008905 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.637068033 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.641596079 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.641676903 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.641695976 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.641748905 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.647766113 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.647844076 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.647859097 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.647907019 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.652462006 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.652555943 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.652573109 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.652626991 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.657130003 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.657212973 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.657233000 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.657290936 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.663405895 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.663440943 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.663506985 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.663541079 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.663569927 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.663583994 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.667011976 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.667038918 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.667088985 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.667109966 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.667131901 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.667150021 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.669476032 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.669549942 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.669568062 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.669581890 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.669606924 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.669636965 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.672554970 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.672576904 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.672672987 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.672708035 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.672765017 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.680078983 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.680099010 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.680195093 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.680231094 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.680291891 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.683729887 CET4434975023.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:15.683868885 CET4434975023.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:15.683979988 CET49750443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:15.688323021 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.688347101 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.688467026 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.688483953 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.688529968 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.696513891 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.696535110 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.696608067 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.696624041 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.696651936 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.696671009 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.704029083 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.704046965 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.704096079 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.704108953 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.704140902 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.704159021 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.712265015 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.712286949 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.712342978 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.712356091 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.712388992 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.712405920 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.719345093 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.719367027 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.719408989 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.719422102 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.719456911 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.719476938 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.724692106 CET49774443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.724723101 CET44349774150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.728717089 CET49775443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.728740931 CET44349775150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.750368118 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.750395060 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.750463009 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.750485897 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.750503063 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.750526905 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.758153915 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.758178949 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.758244991 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.758270025 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.758294106 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.758311033 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.765922070 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.765945911 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.765989065 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.766007900 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.766036987 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.766047001 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.770682096 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.770765066 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.770790100 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.770842075 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.772658110 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.772677898 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.772743940 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.772763968 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.772783995 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.772802114 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.773771048 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.773854017 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.773860931 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.773914099 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.777450085 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.777513027 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.777520895 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.777579069 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.779993057 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.780016899 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.780055046 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.780073881 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.780096054 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.780114889 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.782077074 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.782139063 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.782145023 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.782191992 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.785619974 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.785681963 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.785690069 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.785731077 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.787759066 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.787784100 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.787825108 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.787843943 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.787868977 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.787889004 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.790035963 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.790108919 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.790115118 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.790174961 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.793468952 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.793545961 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.793555021 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.793593884 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.795447111 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.795473099 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.795510054 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.795528889 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.795552969 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.795577049 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.796993017 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.797054052 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.797060013 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.797100067 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.801393986 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.801454067 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.801462889 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.801520109 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.804836035 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.804898977 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.804908991 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.804966927 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.808813095 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.808882952 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.808891058 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.809015036 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.812361002 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.812423944 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.812431097 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.812470913 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.816854000 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.816914082 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.816920996 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.816979885 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.820184946 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.820255041 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.820262909 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.820313931 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.823702097 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.823764086 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.823771954 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.823811054 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.828320026 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.828385115 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.828391075 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.828428984 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.855412006 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.855454922 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.855499029 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.855518103 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.855545044 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.855561018 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.862912893 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.862935066 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.862982988 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.862997055 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.863038063 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.863050938 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.870584965 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.870605946 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.870647907 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.870661974 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.870697021 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.870723963 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.876193047 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.876213074 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.876251936 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.876260996 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.876292944 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.883440971 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.883462906 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.883528948 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.883539915 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.883570910 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.883665085 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.890367985 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.890393019 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.890455008 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.890466928 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.890506983 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.897675991 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.897711992 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.897749901 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.897759914 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.897792101 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.897809029 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.898783922 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.898860931 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.898868084 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.898876905 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.898907900 CET44349773150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.898919106 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.898951054 CET49773443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.936395884 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.936422110 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.936525106 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.936554909 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.936602116 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.942506075 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.942528009 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.942580938 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.942600965 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.942617893 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.942645073 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.944591045 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.944672108 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.944684029 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.944696903 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.944734097 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.962836981 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.962910891 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.962937117 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.962985992 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.963654041 CET49772443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.963684082 CET44349772150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.965331078 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.965406895 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.965432882 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.965476990 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.969670057 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.969741106 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.969759941 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.969804049 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.972892046 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.972980022 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.972999096 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.973047018 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.973989010 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.974044085 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.974050045 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.974083900 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.974083900 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.974097013 CET44349771150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:15.974108934 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.974134922 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:15.974189043 CET49771443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:18.305027962 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:18.305082083 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:18.305165052 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:18.306839943 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:18.306854010 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:19.834125996 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:19.834721088 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:19.856950998 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:19.856977940 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:19.857398033 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:19.857470989 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:19.858968973 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:19.859056950 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:19.859110117 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:19.859231949 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:19.903342962 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.315563917 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.315589905 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.315606117 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.315638065 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.315670967 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.315682888 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.315730095 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.502742052 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.502774000 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.502832890 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.502865076 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.502881050 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.502906084 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.558037996 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.558058977 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.558123112 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.558140993 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.558182955 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.675929070 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.675955057 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.676006079 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.676029921 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.676059008 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.676083088 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.710464001 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.710480928 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.710529089 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.710541010 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.710570097 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.710585117 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.736352921 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.736380100 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.736439943 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.736466885 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.736502886 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.736502886 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.757342100 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.757360935 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.757426023 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.757443905 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.757491112 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.858688116 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.858751059 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.858794928 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.858824968 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.858841896 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.858861923 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.877566099 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.877590895 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.877664089 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.877686024 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.877729893 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.891326904 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.891345024 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.891412973 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.891428947 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.891477108 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.891499043 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.906696081 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.906716108 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.906799078 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.906820059 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.906861067 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.921938896 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.921961069 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.922004938 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.922022104 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.922060966 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.922080994 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.936184883 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.936204910 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.936256886 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.936270952 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.936310053 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.936327934 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.951682091 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.951702118 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.951766968 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:20.951783895 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:20.951822042 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.044749975 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.044787884 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.044830084 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.044857979 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.044879913 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.044907093 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.057653904 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.057677031 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.057765961 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.057780981 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.057817936 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.069773912 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.069793940 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.069844961 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.069864988 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.069888115 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.069895983 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.080210924 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.080239058 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.080282927 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.080291033 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.080329895 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.080346107 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.092462063 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.092497110 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.092529058 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.092535019 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.092592955 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.103082895 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.103108883 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.103144884 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.103152037 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.103185892 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.103204966 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.113668919 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.113689899 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.113749981 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.113759041 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.113955975 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.124394894 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.124423027 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.124471903 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.124480009 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.124521017 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.237654924 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.237692118 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.237739086 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.237767935 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.237797022 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.237818956 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.245908022 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.245949984 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.245979071 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.245986938 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.246026993 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.252791882 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.252825022 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.252865076 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.252876997 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.252904892 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.252918959 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.260611057 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.260639906 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.260679007 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.260685921 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.260715961 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.260730028 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.268207073 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.268234015 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.268263102 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.268279076 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.268295050 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.268317938 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.275952101 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.275975943 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.276005030 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.276012897 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.276045084 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.276062965 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.283238888 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.283267021 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.283380985 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.283380985 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.283411026 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.283509016 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.300271988 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.300298929 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.300340891 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.300363064 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.300378084 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.300399065 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.426640987 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.426716089 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.426747084 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.426788092 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.426795006 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.426827908 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:21.426836967 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.426876068 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.455506086 CET49777443192.168.2.24150.171.27.10
                                        Dec 17, 2024 13:14:21.455533981 CET44349777150.171.27.10192.168.2.24
                                        Dec 17, 2024 13:14:22.556543112 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:22.556615114 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:22.556737900 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:31.144623041 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:31.144718885 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:31.144938946 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:36.869055986 CET49764443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:36.869082928 CET4434976423.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:36.869231939 CET49749443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:36.869262934 CET49750443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:36.869313002 CET49760443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:36.869335890 CET44349760172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:36.989167929 CET4434975023.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:36.989181995 CET4434974923.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:37.503330946 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:37.503371954 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:37.503628969 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:37.505661011 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:37.505675077 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:38.721007109 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:38.755338907 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:38.755351067 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:38.756468058 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:38.756526947 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:38.804366112 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:38.804672003 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:38.804797888 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:38.804807901 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:38.852509975 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:39.163017988 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:39.163119078 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:39.163172007 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:39.163357019 CET49844443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:39.163372040 CET44349844104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.243663073 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.243704081 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.243768930 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.243968010 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.243980885 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:41.474775076 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:41.475182056 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:41.475215912 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:41.475553989 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:41.476506948 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:41.476564884 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:41.524400949 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:45.430669069 CET49724443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:45.550542116 CET44349724204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:47.430707932 CET49740443192.168.2.2420.110.205.119
                                        Dec 17, 2024 13:14:47.550496101 CET4434974020.110.205.119192.168.2.24
                                        Dec 17, 2024 13:14:47.680706978 CET49739443192.168.2.24108.139.47.50
                                        Dec 17, 2024 13:14:47.801533937 CET44349739108.139.47.50192.168.2.24
                                        Dec 17, 2024 13:14:47.915169001 CET49744443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:48.035089970 CET44349744204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:48.102897882 CET49743443192.168.2.24204.79.197.237
                                        Dec 17, 2024 13:14:48.222913027 CET44349743204.79.197.237192.168.2.24
                                        Dec 17, 2024 13:14:49.508622885 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:49.508662939 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:49.508827925 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:49.512343884 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:49.512376070 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.235397100 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.235534906 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.237029076 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.237040043 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.238490105 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.238643885 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.242228985 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.242326975 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.242393017 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.242402077 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.242551088 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.287287951 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.331332922 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.987972021 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.988043070 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.988121033 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.988158941 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.991333961 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:51.991468906 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.991647005 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:51.991699934 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:52.041161060 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:52.041193962 CET4434984913.107.246.63192.168.2.24
                                        Dec 17, 2024 13:14:52.041210890 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:52.041263103 CET49849443192.168.2.2413.107.246.63
                                        Dec 17, 2024 13:14:53.587397099 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:14:53.665747881 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:14:53.665766954 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:14:53.707195044 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:14:54.945822954 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:14:55.068469048 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:14:55.289568901 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:14:55.410166025 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:14:55.977071047 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:56.097332001 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:58.442656994 CET4985480192.168.2.24142.250.181.99
                                        Dec 17, 2024 13:14:58.507833958 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:14:58.507894993 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:14:58.507987976 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:14:58.508374929 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:14:58.508398056 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:14:58.562510967 CET8049854142.250.181.99192.168.2.24
                                        Dec 17, 2024 13:14:58.562753916 CET4985480192.168.2.24142.250.181.99
                                        Dec 17, 2024 13:14:58.562788963 CET4985480192.168.2.24142.250.181.99
                                        Dec 17, 2024 13:14:58.682627916 CET8049854142.250.181.99192.168.2.24
                                        Dec 17, 2024 13:14:58.728832960 CET4972280192.168.2.24192.229.221.95
                                        Dec 17, 2024 13:14:58.728918076 CET49720443192.168.2.2413.87.96.169
                                        Dec 17, 2024 13:14:58.849164963 CET8049722192.229.221.95192.168.2.24
                                        Dec 17, 2024 13:14:58.849253893 CET4972280192.168.2.24192.229.221.95
                                        Dec 17, 2024 13:14:58.849597931 CET4434972013.87.96.169192.168.2.24
                                        Dec 17, 2024 13:14:58.852087975 CET49720443192.168.2.2413.87.96.169
                                        Dec 17, 2024 13:14:58.977138042 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:14:59.099361897 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:15:00.021048069 CET8049854142.250.181.99192.168.2.24
                                        Dec 17, 2024 13:15:00.073223114 CET4985480192.168.2.24142.250.181.99
                                        Dec 17, 2024 13:15:00.116432905 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:00.116466045 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:00.116585970 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:00.117204905 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:00.117238045 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:00.117307901 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:00.120841026 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:00.120853901 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:00.121589899 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:00.121599913 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:00.169281006 CET4985880192.168.2.2423.195.39.65
                                        Dec 17, 2024 13:15:00.289091110 CET804985823.195.39.65192.168.2.24
                                        Dec 17, 2024 13:15:00.289179087 CET4985880192.168.2.2423.195.39.65
                                        Dec 17, 2024 13:15:00.289349079 CET4985880192.168.2.2423.195.39.65
                                        Dec 17, 2024 13:15:00.409035921 CET804985823.195.39.65192.168.2.24
                                        Dec 17, 2024 13:15:00.424349070 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:00.424643993 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:00.424669981 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:00.428014040 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:00.428097010 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:00.429064035 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:00.429155111 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:00.527091980 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:00.527115107 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:00.635051012 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:00.790025949 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:15:00.790117979 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:15:00.790221930 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:15:01.547336102 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.547801971 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.547817945 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.548881054 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.548930883 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.550451994 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.550519943 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.550573111 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.550904989 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.550913095 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.551058054 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.551068068 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.554348946 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.554409981 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.555877924 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.556041956 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.634208918 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.634227037 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:01.664887905 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.747108936 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:01.763266087 CET804985823.195.39.65192.168.2.24
                                        Dec 17, 2024 13:15:01.868796110 CET4985880192.168.2.2423.195.39.65
                                        Dec 17, 2024 13:15:02.008013964 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:02.008133888 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:02.008178949 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:02.009493113 CET49857443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:02.009515047 CET4434985734.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:02.076018095 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:02.123327971 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:02.422178030 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:02.422460079 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:02.422590971 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:02.423302889 CET49856443192.168.2.2434.117.42.160
                                        Dec 17, 2024 13:15:02.423326969 CET4434985634.117.42.160192.168.2.24
                                        Dec 17, 2024 13:15:10.143460989 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:10.143569946 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:10.143625021 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:10.775867939 CET49855443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:10.775899887 CET44349855142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:30.565951109 CET49724443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:15:30.685626030 CET44349724204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:15:32.566008091 CET49740443192.168.2.2420.110.205.119
                                        Dec 17, 2024 13:15:32.685803890 CET4434974020.110.205.119192.168.2.24
                                        Dec 17, 2024 13:15:32.817343950 CET49739443192.168.2.24108.139.47.50
                                        Dec 17, 2024 13:15:32.937299967 CET44349739108.139.47.50192.168.2.24
                                        Dec 17, 2024 13:15:33.050564051 CET49744443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:15:33.170893908 CET44349744204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:15:33.238503933 CET49743443192.168.2.24204.79.197.237
                                        Dec 17, 2024 13:15:33.367417097 CET44349743204.79.197.237192.168.2.24
                                        Dec 17, 2024 13:15:36.344458103 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:36.344515085 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:36.344588995 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:36.347372055 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:36.347394943 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:37.725755930 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:37.725826979 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.727032900 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.727046013 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:37.729130030 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:37.729191065 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.735750914 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.735878944 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:37.735935926 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.735944033 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:37.736721992 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.742724895 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:37.787339926 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:38.250157118 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:38.250221968 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:38.250235081 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:38.250250101 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:38.250283003 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:38.250309944 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:38.251893997 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:38.251980066 CET443498632.19.198.224192.168.2.24
                                        Dec 17, 2024 13:15:38.252080917 CET49863443192.168.2.242.19.198.224
                                        Dec 17, 2024 13:15:38.675350904 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:15:38.675375938 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:15:38.722233057 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:15:38.842185974 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:15:40.076209068 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:15:40.199140072 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:15:40.419945002 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:15:40.539630890 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:15:41.107431889 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:15:41.228418112 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:15:44.107420921 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:15:44.218843937 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:15:45.529613018 CET4972580192.168.2.24192.229.221.95
                                        Dec 17, 2024 13:15:45.529666901 CET4972380192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:15:45.640984058 CET8049725192.229.221.95192.168.2.24
                                        Dec 17, 2024 13:15:45.641041994 CET4972580192.168.2.24192.229.221.95
                                        Dec 17, 2024 13:15:45.641531944 CET8049723199.232.214.172192.168.2.24
                                        Dec 17, 2024 13:15:45.641695976 CET4972380192.168.2.24199.232.214.172
                                        Dec 17, 2024 13:15:45.794938087 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:15:45.794966936 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:15:52.999980927 CET49747443192.168.2.2423.218.208.109
                                        Dec 17, 2024 13:15:53.111865044 CET4434974723.218.208.109192.168.2.24
                                        Dec 17, 2024 13:15:53.112036943 CET49747443192.168.2.2423.218.208.109
                                        Dec 17, 2024 13:15:57.490201950 CET44349719104.126.37.201192.168.2.24
                                        Dec 17, 2024 13:15:57.490344048 CET44349719104.126.37.201192.168.2.24
                                        Dec 17, 2024 13:15:57.490391016 CET49719443192.168.2.24104.126.37.201
                                        Dec 17, 2024 13:15:57.490426064 CET49719443192.168.2.24104.126.37.201
                                        Dec 17, 2024 13:15:57.490546942 CET49719443192.168.2.24104.126.37.201
                                        Dec 17, 2024 13:15:57.601376057 CET44349719104.126.37.201192.168.2.24
                                        Dec 17, 2024 13:15:58.423650026 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:58.423675060 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:15:58.423763037 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:58.424273014 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:15:58.424284935 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:00.331800938 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:00.332573891 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:00.332583904 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:00.332945108 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:00.333329916 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:00.333395004 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:00.375402927 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:00.437655926 CET49673443192.168.2.2420.198.118.190
                                        Dec 17, 2024 13:16:00.437675953 CET4434967320.198.118.190192.168.2.24
                                        Dec 17, 2024 13:16:01.185014009 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:01.185055971 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:01.185178041 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:01.186192036 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:01.186207056 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:03.499973059 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:03.500065088 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:03.507400990 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:03.507414103 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:03.507745028 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:03.562613964 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:03.614979029 CET44349724204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:03.615051985 CET49724443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:16:03.615283966 CET49724443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:16:03.726268053 CET44349724204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:04.828463078 CET4434974020.110.205.119192.168.2.24
                                        Dec 17, 2024 13:16:04.828891039 CET49740443192.168.2.2420.110.205.119
                                        Dec 17, 2024 13:16:04.926022053 CET44349743204.79.197.237192.168.2.24
                                        Dec 17, 2024 13:16:04.926160097 CET49743443192.168.2.24204.79.197.237
                                        Dec 17, 2024 13:16:05.928936005 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:05.928936958 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:05.928936958 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:05.929002047 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:05.975328922 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:06.584531069 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:06.584615946 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:06.584753036 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:06.585179090 CET49866443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:06.585201025 CET4434986620.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:06.591619968 CET44349744204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:06.591712952 CET49744443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:16:07.196676970 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:07.196716070 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:07.196918011 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:07.197748899 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:07.197763920 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:08.625261068 CET4985880192.168.2.2423.195.39.65
                                        Dec 17, 2024 13:16:08.625318050 CET4985480192.168.2.24142.250.181.99
                                        Dec 17, 2024 13:16:08.736676931 CET804985823.195.39.65192.168.2.24
                                        Dec 17, 2024 13:16:08.736742973 CET4985880192.168.2.2423.195.39.65
                                        Dec 17, 2024 13:16:08.737426043 CET8049854142.250.181.99192.168.2.24
                                        Dec 17, 2024 13:16:08.737489939 CET4985480192.168.2.24142.250.181.99
                                        Dec 17, 2024 13:16:09.375088930 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:16:09.375363111 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:16:09.375488043 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:16:09.375669956 CET49732443192.168.2.2423.199.50.102
                                        Dec 17, 2024 13:16:09.403197050 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:09.403350115 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:09.406681061 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:09.406693935 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:09.406929016 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:09.411215067 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:09.411286116 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:09.411292076 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:09.411436081 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:09.455334902 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:09.486922026 CET4434973223.199.50.102192.168.2.24
                                        Dec 17, 2024 13:16:10.050914049 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:10.051052094 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:10.051259041 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:10.062215090 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:10.062412977 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:10.062587976 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:10.062705994 CET49868443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:10.062727928 CET4434986820.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:10.284018993 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:16:10.284184933 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:16:10.284184933 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:16:10.284223080 CET49728443192.168.2.24104.117.182.56
                                        Dec 17, 2024 13:16:10.395217896 CET44349728104.117.182.56192.168.2.24
                                        Dec 17, 2024 13:16:10.655167103 CET4434975220.189.173.11192.168.2.24
                                        Dec 17, 2024 13:16:10.655338049 CET49752443192.168.2.2420.189.173.11
                                        Dec 17, 2024 13:16:10.655395985 CET49752443192.168.2.2420.189.173.11
                                        Dec 17, 2024 13:16:10.767472982 CET4434975220.189.173.11192.168.2.24
                                        Dec 17, 2024 13:16:10.768043041 CET49865443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:10.768066883 CET44349865142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:11.415138960 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:11.415210009 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:11.415258884 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:16:13.572974920 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:13.573034048 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:13.573116064 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:13.573980093 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:13.574001074 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:14.916333914 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:16:14.916482925 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:16:14.916706085 CET49737443192.168.2.2413.89.179.8
                                        Dec 17, 2024 13:16:15.027818918 CET4434973713.89.179.8192.168.2.24
                                        Dec 17, 2024 13:16:15.778043985 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:15.778176069 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:15.780586004 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:15.780607939 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:15.781387091 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:15.784379005 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:15.784429073 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:15.784442902 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:15.784568071 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:15.831335068 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:16.457281113 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:16.457372904 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:16.457438946 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:16.460740089 CET49869443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:16.460768938 CET4434986920.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:17.937906027 CET49739443192.168.2.24108.139.47.50
                                        Dec 17, 2024 13:16:18.049120903 CET44349739108.139.47.50192.168.2.24
                                        Dec 17, 2024 13:16:23.846060038 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:16:23.957350016 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:16:26.236650944 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:16:26.348104954 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:16:29.057341099 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:29.057378054 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:29.057444096 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:29.058355093 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:29.058370113 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:30.799187899 CET49845443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:16:30.799211025 CET44349845104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:16:31.271209002 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.271272898 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.273588896 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.273606062 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.273814917 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.277437925 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.277503967 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.277513027 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.277625084 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.323338985 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.820960045 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.821067095 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:31.821124077 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.821427107 CET49871443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:31.821449995 CET4434987120.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:48.887208939 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:48.887243032 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:48.887341022 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:48.888233900 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:48.888251066 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:49.831511974 CET49740443192.168.2.2420.110.205.119
                                        Dec 17, 2024 13:16:49.940707922 CET49743443192.168.2.24204.79.197.237
                                        Dec 17, 2024 13:16:49.951400042 CET4434974020.110.205.119192.168.2.24
                                        Dec 17, 2024 13:16:50.060759068 CET44349743204.79.197.237192.168.2.24
                                        Dec 17, 2024 13:16:51.111824989 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.111896992 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.114070892 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.114080906 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.114305973 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.117722988 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.117769957 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.117777109 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.117878914 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.163340092 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.596966982 CET49744443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:16:51.662571907 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.662647009 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.662698030 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.662870884 CET49872443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:16:51.662879944 CET4434987220.198.119.84192.168.2.24
                                        Dec 17, 2024 13:16:51.716950893 CET44349744204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:56.419780970 CET49762443192.168.2.24204.79.197.203
                                        Dec 17, 2024 13:16:56.419800997 CET44349762204.79.197.203192.168.2.24
                                        Dec 17, 2024 13:16:58.488893986 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:58.488953114 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:16:58.489131927 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:58.489438057 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:16:58.489456892 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:00.385905027 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:00.386928082 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:17:00.386944056 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:00.387304068 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:00.390762091 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:17:00.390871048 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:00.446366072 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:17:03.061877012 CET49739443192.168.2.24108.139.47.50
                                        Dec 17, 2024 13:17:03.181682110 CET44349739108.139.47.50192.168.2.24
                                        Dec 17, 2024 13:17:08.390494108 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:17:08.390683889 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:17:08.390758991 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:17:08.390881062 CET49730443192.168.2.2472.21.81.200
                                        Dec 17, 2024 13:17:08.510718107 CET4434973072.21.81.200192.168.2.24
                                        Dec 17, 2024 13:17:10.090605974 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:10.090698004 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:10.090837955 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:17:10.697438955 CET49873443192.168.2.24142.250.181.100
                                        Dec 17, 2024 13:17:10.697464943 CET44349873142.250.181.100192.168.2.24
                                        Dec 17, 2024 13:17:11.352919102 CET49753443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:17:11.472798109 CET44349753172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:17:13.049269915 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:13.049312115 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:13.049416065 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:13.050335884 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:13.050350904 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.298001051 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.298084021 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.300235987 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.300255060 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.300580025 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.304065943 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.304126024 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.304131985 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.304239035 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.347381115 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.972987890 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.973093987 CET4434987420.198.119.84192.168.2.24
                                        Dec 17, 2024 13:17:15.973215103 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.973511934 CET49874443192.168.2.2420.198.119.84
                                        Dec 17, 2024 13:17:15.973563910 CET4434987420.198.119.84192.168.2.24
                                        TimestampSource PortDest PortSource IPDest IP
                                        Dec 17, 2024 13:14:08.585001945 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.595608950 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.899971962 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.904901028 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905189991 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905267000 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905280113 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905353069 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905565977 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905622959 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905635118 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905780077 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905843973 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.905855894 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906021118 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906034946 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906047106 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906059027 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906245947 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906291008 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906310081 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.906323910 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.907083988 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.907164097 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.910279036 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916129112 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916184902 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916198015 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916344881 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916357040 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916368008 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916379929 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916390896 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916567087 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.916579962 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923120022 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923199892 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923217058 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923310041 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923331022 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923343897 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923357010 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923568010 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.923579931 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:08.924873114 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.924921989 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.924983025 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.937164068 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.942708015 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:08.952141047 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.246577024 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.253976107 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.259979010 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260288954 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260467052 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260483980 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260638952 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260653019 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260665894 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260791063 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.260992050 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261006117 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261018991 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261293888 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261307955 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261321068 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261471033 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261491060 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261502981 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261512041 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.261516094 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.270441055 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.270533085 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.273567915 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.273874044 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.273885012 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.273899078 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274063110 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274076939 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274089098 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274228096 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274241924 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274252892 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274266005 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.274750948 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.278045893 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.278150082 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.282210112 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282542944 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282557964 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282571077 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282584906 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282711029 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282725096 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282888889 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282901049 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.282912970 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.284209013 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.292143106 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292162895 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292177916 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292187929 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292198896 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292228937 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292249918 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292263031 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.292269945 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.294711113 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.301517963 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.595947981 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.596045017 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.609622955 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.616221905 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.624051094 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.624305964 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.624546051 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.624566078 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.624696970 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.624779940 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.624790907 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625045061 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625055075 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625066996 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625078917 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625318050 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625330925 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625353098 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625365019 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625375986 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625386000 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625391960 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625401974 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625412941 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.625426054 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.632631063 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.632652998 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.632664919 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.632841110 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.654602051 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:09.662281990 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.915937901 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.915961027 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.919930935 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.920783997 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.920830011 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.920945883 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921025038 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921036005 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921220064 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921230078 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921241999 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921435118 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921447039 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.921825886 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.921935081 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.933320999 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933331966 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933343887 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933420897 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933430910 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933443069 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933454990 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933562040 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933572054 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.933583021 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.935447931 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.938532114 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.959556103 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.963335991 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:09.967001915 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.993659973 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:09.995215893 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.263248920 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.310348988 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.310394049 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.317416906 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.317490101 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.317502975 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.317513943 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.324352980 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.325849056 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.325946093 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.325958014 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.326073885 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.328176975 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.328519106 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.648621082 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.648689032 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.673648119 CET6108253192.168.2.241.1.1.1
                                        Dec 17, 2024 13:14:10.680389881 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.690754890 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.690825939 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.690865040 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.690999031 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691054106 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691097975 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691150904 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691183090 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691216946 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691256046 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691340923 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691370010 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.691673040 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.705509901 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.705543995 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.705578089 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.705605984 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:10.705956936 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.733180046 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:10.740643024 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:10.740834951 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:10.740935087 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:10.741417885 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:10.746892929 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:10.746963978 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:11.031514883 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.057342052 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.057496071 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.057677984 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.057712078 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.061584949 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:11.061691046 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:11.061737061 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:11.061764956 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:11.066234112 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.066751957 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:11.066783905 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.066795111 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:11.067187071 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.360529900 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.361047029 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.380942106 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:11.381828070 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.381860971 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.381951094 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.381978989 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.382013083 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.382080078 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.382117033 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.382891893 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.392113924 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.392473936 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.396821976 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.421133995 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:11.429311991 CET62861443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:11.675977945 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:11.707158089 CET4436286123.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:12.209594011 CET6108253192.168.2.241.1.1.1
                                        Dec 17, 2024 13:14:13.218334913 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:13.554910898 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571263075 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571305037 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571373940 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571408033 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571440935 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571564913 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571599960 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571634054 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571664095 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:13.571748972 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:13.596985102 CET62248443192.168.2.2423.209.72.4
                                        Dec 17, 2024 13:14:13.930753946 CET4436224823.209.72.4192.168.2.24
                                        Dec 17, 2024 13:14:15.285847902 CET137137192.168.2.24192.168.2.255
                                        Dec 17, 2024 13:14:16.039580107 CET137137192.168.2.24192.168.2.255
                                        Dec 17, 2024 13:14:16.790076017 CET137137192.168.2.24192.168.2.255
                                        Dec 17, 2024 13:14:36.870234013 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:37.184693098 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:37.185322046 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:37.212061882 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:37.500509977 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:37.502000093 CET44365143172.64.41.3192.168.2.24
                                        Dec 17, 2024 13:14:37.540230036 CET65143443192.168.2.24172.64.41.3
                                        Dec 17, 2024 13:14:39.164254904 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.269129992 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.269145012 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.269165039 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.269206047 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.269627094 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.274713993 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.286633015 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.286734104 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.286948919 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.286969900 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.286984921 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.568079948 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.568401098 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.600996971 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601011038 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601103067 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601111889 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601129055 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601203918 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601216078 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.601417065 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.601417065 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.614455938 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.614855051 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.614855051 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.615009069 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.615519047 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.649830103 CET60625443192.168.2.24104.117.182.75
                                        Dec 17, 2024 13:14:40.882745028 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.929387093 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:40.929399014 CET44360625104.117.182.75192.168.2.24
                                        Dec 17, 2024 13:14:54.010868073 CET53618951.1.1.1192.168.2.24
                                        Dec 17, 2024 13:14:54.139833927 CET53588901.1.1.1192.168.2.24
                                        Dec 17, 2024 13:14:57.145750046 CET53554691.1.1.1192.168.2.24
                                        Dec 17, 2024 13:14:58.368746996 CET5854353192.168.2.241.1.1.1
                                        Dec 17, 2024 13:14:58.368951082 CET6462453192.168.2.241.1.1.1
                                        Dec 17, 2024 13:14:58.506740093 CET53585431.1.1.1192.168.2.24
                                        Dec 17, 2024 13:14:58.506763935 CET53646241.1.1.1192.168.2.24
                                        Dec 17, 2024 13:14:59.861413956 CET5223353192.168.2.241.1.1.1
                                        Dec 17, 2024 13:14:59.861984968 CET5510153192.168.2.241.1.1.1
                                        Dec 17, 2024 13:15:00.098093987 CET53522331.1.1.1192.168.2.24
                                        Dec 17, 2024 13:15:00.115880966 CET53551011.1.1.1192.168.2.24
                                        Dec 17, 2024 13:15:14.050481081 CET53538911.1.1.1192.168.2.24
                                        Dec 17, 2024 13:15:23.411344051 CET53570931.1.1.1192.168.2.24
                                        Dec 17, 2024 13:15:32.768626928 CET53628541.1.1.1192.168.2.24
                                        Dec 17, 2024 13:15:53.914829016 CET53627141.1.1.1192.168.2.24
                                        Dec 17, 2024 13:15:55.633775949 CET53642621.1.1.1192.168.2.24
                                        Dec 17, 2024 13:16:26.220292091 CET53637141.1.1.1192.168.2.24
                                        Dec 17, 2024 13:17:10.836018085 CET53644611.1.1.1192.168.2.24
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Dec 17, 2024 13:14:10.673648119 CET192.168.2.241.1.1.10x6befStandard query (0)cxcs.microsoft.netA (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:12.209594011 CET192.168.2.241.1.1.10x51dcStandard query (0)tse1.mm.bing.netA (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:58.368746996 CET192.168.2.241.1.1.10xe5fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:58.368951082 CET192.168.2.241.1.1.10x4990Standard query (0)www.google.com65IN (0x0001)false
                                        Dec 17, 2024 13:14:59.861413956 CET192.168.2.241.1.1.10x768fStandard query (0)nhlnkc.comA (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:59.861984968 CET192.168.2.241.1.1.10x8ad6Standard query (0)nhlnkc.com65IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Dec 17, 2024 13:14:10.813822031 CET1.1.1.1192.168.2.240x6befNo error (0)cxcs.microsoft.netcxcs.microsoft.net.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                        Dec 17, 2024 13:14:12.529825926 CET1.1.1.1192.168.2.240x51dcNo error (0)tse1.mm.bing.netmm-mm.bing.net.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                        Dec 17, 2024 13:14:12.529825926 CET1.1.1.1192.168.2.240x51dcNo error (0)ax-0001.ax-msedge.net150.171.27.10A (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:12.529825926 CET1.1.1.1192.168.2.240x51dcNo error (0)ax-0001.ax-msedge.net150.171.28.10A (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:23.019028902 CET1.1.1.1192.168.2.240xd38bNo error (0)scdn1cc4b.wpc.9aea3.sigmacdn.netsni1gl.wpc.sigmacdn.netCNAME (Canonical name)IN (0x0001)false
                                        Dec 17, 2024 13:14:23.019028902 CET1.1.1.1192.168.2.240xd38bNo error (0)sni1gl.wpc.sigmacdn.net152.199.21.175A (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:27.241822958 CET1.1.1.1192.168.2.240xa22dNo error (0)templatesmetadata.office.nettemplatesmetadata.office.net.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                        Dec 17, 2024 13:14:58.506740093 CET1.1.1.1192.168.2.240xe5fNo error (0)www.google.com142.250.181.100A (IP address)IN (0x0001)false
                                        Dec 17, 2024 13:14:58.506763935 CET1.1.1.1192.168.2.240x4990No error (0)www.google.com65IN (0x0001)false
                                        Dec 17, 2024 13:15:00.098093987 CET1.1.1.1192.168.2.240x768fNo error (0)nhlnkc.com34.117.42.160A (IP address)IN (0x0001)false
                                        • tse1.mm.bing.net
                                        • res.public.onecdn.static.microsoft
                                        • nhlnkc.com
                                        • https:
                                        • assets.msn.com
                                        • c.pki.goog
                                        • x1.c.lencr.org
                                        Session IDSource IPSource PortDestination IPDestination Port
                                        0192.168.2.2449761199.232.214.17280
                                        TimestampBytes transferredDirectionData
                                        Dec 17, 2024 13:14:07.905824900 CET440INHTTP/1.1 200 OK
                                        Connection: keep-alive
                                        Content-Length: 4761
                                        Cache-Control: public,max-age=900
                                        Content-Type: application/vnd.ms-cab-compressed
                                        Last-Modified: Thu, 05 Dec 2024 19:42:09 GMT
                                        ETag: "06cfcc54d47db1:0"
                                        Accept-Ranges: bytes
                                        Date: Tue, 17 Dec 2024 12:14:07 GMT
                                        Via: 1.1 varnish
                                        Age: 420
                                        X-Served-By: cache-ewr-kewr1740067-EWR
                                        X-Cache: HIT
                                        X-Cache-Hits: 8601
                                        X-Timer: S1734437648.754109,VS0,VE0
                                        X-CID: 3
                                        X-CCC: US
                                        Dec 17, 2024 13:14:07.905966997 CET1236INData Raw: 4d 53 43 46 00 00 00 00 99 12 00 00 00 00 00 00 2c 00 00 00 00 00 00 00 03 01 01 00 01 00 00 00 00 00 00 00 4f 00 00 00 01 00 01 00 cc 16 00 00 00 00 00 00 00 00 84 59 57 50 20 00 64 69 73 61 6c 6c 6f 77 65 64 63 65 72 74 2e 73 74 6c 00 6c 4a a4
                                        Data Ascii: MSCF,OYWP disallowedcert.stllJBCKwTS{&UzI"E"HS@ P!*E DQ EDAH E""/s<s9&#{~kVV7@bRMdTBL%C" %4%%*BTdS
                                        Dec 17, 2024 13:14:07.905980110 CET224INData Raw: 35 40 7d ab d3 60 3f 07 bd 83 87 1b ae ac 6a fe 18 35 59 2d 7e 77 fb 44 33 c8 88 ef cf 1c 39 60 f2 4c be 50 5f 61 f8 ec f1 82 da fd bc 6c 7e eb b7 1a 7c fb 7d d9 8d 73 4d e3 c5 b7 f7 d7 a0 4e cf 72 f3 d1 1b a9 6b 52 c7 2d 67 19 b6 51 2f f7 63 6d
                                        Data Ascii: 5@}`?j5Y-~wD39`LP_al~|}sMNrkR-gQ/cm11tiH>>Hh,.[]:{^a>A[ 3_#G~lbP|XEXs5`z;L?m,,VQC- w
                                        Dec 17, 2024 13:14:07.905996084 CET1236INData Raw: 62 df 7f a7 90 69 de d3 12 0e 72 d9 af 11 99 9e e8 93 bc f1 81 d2 be 39 ea ce be 3b fd fb 63 38 8d 7f f6 39 1e 33 18 07 2f 28 10 69 73 92 d9 8f c9 50 35 bf 74 3e 86 52 e4 83 08 b4 97 94 3e 09 03 b2 92 f5 fa b8 5c 76 a9 bd 84 5e d5 13 13 3b 7d 5c
                                        Data Ascii: bir9;c893/(isP5t>R>\v^;}\EAW]ZZ+f/J\@l`lk(C4f-tHnqrBj`syj+|:Qq<h{m}5}&7\;|VQj;zvgfv5F(z@rSTnm$
                                        Dec 17, 2024 13:14:07.906019926 CET1236INData Raw: 07 70 21 b1 0a bb 45 70 9a 43 70 6f 6b 7e e1 ce 6b 89 44 e3 c5 1d 77 1b fa 6f ad 7a 72 14 53 5e d2 8c c4 ec b3 51 02 f7 e4 bc 16 ef 94 0e 4c 07 24 47 40 9a 55 ab 54 18 fd 8d 3a 6e 3d 98 89 15 36 31 d4 39 f4 aa a5 ce 75 99 de 4b a5 9d 6b 67 25 6e
                                        Data Ascii: p!EpCpok~kDwozrS^QL$G@UT:n=619uKkg%n*D+<.*_K:!t{r-(-k|C2j;9>U4I~~V!A<!\Srf;vYqJBO qiS-shaLe{TO&(,
                                        Dec 17, 2024 13:14:07.906035900 CET829INData Raw: 68 18 d0 64 cb e1 83 28 19 46 7a 60 6b 79 88 99 aa 1e 81 dd 73 0a 63 1a 93 36 34 e5 43 ad b7 ab 3b a9 71 33 ba 5d a8 35 d1 05 3a 3a 73 d6 f4 b5 58 76 ee 97 d3 42 6f 94 5e 54 dd 54 b0 13 91 84 c3 7d 7c de f3 4c 69 03 21 04 9e 2b 97 db b7 35 b6 2b
                                        Data Ascii: hd(Fz`kysc64C;q3]5::sXvBo^TT}|Li!+5+{*JPU*}mb\uQ[FwhVL4c>zU\+r[e6} D7#rsb|XjV8&0ej)r/nQ|DY


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        1192.168.2.2449854142.250.181.9980
                                        TimestampBytes transferredDirectionData
                                        Dec 17, 2024 13:14:58.562788963 CET200OUTGET /r/r1.crl HTTP/1.1
                                        Cache-Control: max-age = 3000
                                        Connection: Keep-Alive
                                        Accept: */*
                                        If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                                        User-Agent: Microsoft-CryptoAPI/10.0
                                        Host: c.pki.goog
                                        Dec 17, 2024 13:15:00.021048069 CET223INHTTP/1.1 304 Not Modified
                                        Date: Tue, 17 Dec 2024 11:30:10 GMT
                                        Expires: Tue, 17 Dec 2024 12:20:10 GMT
                                        Age: 2689
                                        Last-Modified: Thu, 25 Jul 2024 14:48:00 GMT
                                        Cache-Control: public, max-age=3000
                                        Vary: Accept-Encoding


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        2192.168.2.244985823.195.39.6580
                                        TimestampBytes transferredDirectionData
                                        Dec 17, 2024 13:15:00.289349079 CET227OUTGET / HTTP/1.1
                                        Cache-Control: max-age = 3600
                                        Connection: Keep-Alive
                                        Accept: */*
                                        If-Modified-Since: Mon, 12 Feb 2024 22:07:27 GMT
                                        If-None-Match: "65ca969f-2cd"
                                        User-Agent: Microsoft-CryptoAPI/10.0
                                        Host: x1.c.lencr.org
                                        Dec 17, 2024 13:15:01.763266087 CET1023INHTTP/1.1 200 OK
                                        Server: nginx
                                        Content-Type: application/pkix-crl
                                        Last-Modified: Fri, 13 Dec 2024 18:01:23 GMT
                                        ETag: "675c7673-2de"
                                        Cache-Control: max-age=3600
                                        Expires: Tue, 17 Dec 2024 13:15:01 GMT
                                        Date: Tue, 17 Dec 2024 12:15:01 GMT
                                        Content-Length: 734
                                        Connection: keep-alive
                                        Data Raw: 30 82 02 da 30 81 c3 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 4f 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 29 30 27 06 03 55 04 0a 13 20 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 52 65 73 65 61 72 63 68 20 47 72 6f 75 70 31 15 30 13 06 03 55 04 03 13 0c 49 53 52 47 20 52 6f 6f 74 20 58 31 17 0d 32 34 31 32 31 31 30 30 30 30 30 30 5a 17 0d 32 35 31 31 31 30 32 33 35 39 35 39 5a a0 40 30 3e 30 1f 06 03 55 1d 23 04 18 30 16 80 14 79 b4 59 e6 7b b6 e5 e4 01 73 80 08 88 c8 1a 58 f6 e9 9b 6e 30 0a 06 03 55 1d 14 04 03 02 01 69 30 0f 06 03 55 1d 1c 01 01 ff 04 05 30 03 82 01 ff 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 03 82 02 01 00 25 d9 d5 af d1 d6 2f 91 05 35 50 65 d7 ad 13 d8 3b 73 d1 3f 5e 09 69 7f d7 82 29 12 c5 82 d0 96 fe 5f 07 a4 fe f5 92 dc e4 e2 8a 1a 2a 29 c5 eb 97 c8 85 a5 44 9b 9d ba 7b 05 2b 3f e3 3c 18 1c de 8d 37 f6 27 b5 e7 9b ef 45 e7 57 0e c1 f9 07 a5 95 44 fe e1 de 7f 9d e1 31 8c f8 1b 4f 18 5d f8 3d d7 5b e6 e2 03 a6 cb 71 0d ef 7a fe e0 8e f4 5d 1c c5 [TRUNCATED]
                                        Data Ascii: 000*H0O10UUS1)0'U Internet Security Research Group10UISRG Root X1241211000000Z251110235959Z@0>0U#0yY{sXn0Ui0U00*H%/5Pe;s?^i)_*)D{+?<7'EWD1O]=[qz]"2t@^+(zULdQpK?W)pqxW[6[V7?36_s$BwT+xw_]df_nu}yIqC`sVuP,@`|T+`/Pm w[!:O%'w9enSkbv}gGL")V 2kzr/xx}8i]oA,^i=pt>#6&7$_?k/( kAslBQDhXh~N T/BF?QCG*wsS:


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        0192.168.2.2449772150.171.27.10443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:14 UTC375OUTGET /th?id=OADD2.10239402414229_1P4RDVHBQE93FAZFW&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90 HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: tse1.mm.bing.net
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:14 UTC854INHTTP/1.1 200 OK
                                        Cache-Control: public, max-age=2592000
                                        Content-Length: 510198
                                        Content-Type: image/jpeg
                                        X-Cache: TCP_HIT
                                        Access-Control-Allow-Origin: *
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                        Timing-Allow-Origin: *
                                        Report-To: {"group":"network-errors","max_age":604800,"endpoints":[{"url":"https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE"}]}
                                        NEL: {"report_to":"network-errors","max_age":604800,"success_fraction":0.001,"failure_fraction":1.0}
                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                        X-MSEdge-Ref: Ref A: 0F43D8F912B84D4CA6955623C4DD26D4 Ref B: EWR30EDGE1020 Ref C: 2024-12-17T12:14:14Z
                                        Date: Tue, 17 Dec 2024 12:14:14 GMT
                                        Connection: close
                                        2024-12-17 12:14:14 UTC15530INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 48 00 48 00 00 ff e1 00 f4 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 07 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 62 01 1b 00 05 00 00 00 01 00 00 00 6a 01 28 00 03 00 00 00 01 00 02 00 00 01 31 00 02 00 00 00 3a 00 00 00 72 01 32 00 02 00 00 00 14 00 00 00 ac 87 69 00 04 00 00 00 01 00 00 00 c0 00 00 00 00 00 00 00 60 00 00 00 01 00 00 00 60 00 00 00 01 41 64 6f 62 65 20 50 68 6f 74 6f 73 68 6f 70 20 32 36 2e 31 20 28 32 30 32 34 31 31 30 33 2e 6d 2e 32 38 33 34 20 31 34 64 33 65 37 34 29 20 20 28 57 69 6e 64 6f 77 73 29 00 32 30 32 34 3a 31 31 3a 31 32 20 31 33 3a 32 36 3a 31 33 00 00 03 a0 01 00 03 00 00 00 01 ff ff 00 00 a0 02 00 03 00 00 00 01 07 80 00 00 a0 03 00 03 00 00 00
                                        Data Ascii: JFIFHHExifMM*bj(1:r2i``Adobe Photoshop 26.1 (20241103.m.2834 14d3e74) (Windows)2024:11:12 13:26:13
                                        2024-12-17 12:14:15 UTC16384INData Raw: cc 71 37 d0 65 cf fe 83 5e 25 6a 0d c5 bc 90 23 7c ca b9 6d df e7 af 15 e9 60 a0 94 5c 8f 2b 1d 36 e6 a2 48 9a 94 f7 d6 b0 3f cb 14 92 61 19 95 76 f0 7a 83 ef 45 fc 56 71 7e fc 4e d9 5f f9 66 bf e3 55 34 d9 de e2 e2 54 91 56 3f 35 88 6d df c3 cf f4 a9 2f ed e4 8a f1 23 f2 16 55 6f bc db be 56 f7 ed 5d f1 5a 9e 6c 9f 52 95 e5 ec 30 43 1b cd f3 2c 8c 42 fc a3 6e 3a d6 46 9f 24 b0 eb 90 4b 1f cc 24 8c 95 dc bb 9b 24 e5 78 1d 6b a3 d4 2c ad f5 0d 2d a0 10 49 fb b8 98 fd dd db 4f 6c 1a 83 c1 76 11 ad d3 4b 71 12 b4 b1 2f ca bf 79 79 c0 5f c6 b6 56 b3 39 dd f9 d7 63 3a fe 0b 97 b8 52 db 9a 58 db e6 f9 7e ef d6 b2 fc 49 1d c3 5b c4 b2 6e 62 ad fd da ed b5 0b 29 16 e1 a5 12 6d dc df 32 ee dd d2 b2 3c 43 26 fd 1e 42 91 36 dd d8 8f 72 ed 6c 8e bc 54 4a 3a 1b a9 ab
                                        Data Ascii: q7e^%j#|m`\+6H?avzEVq~N_fU4TV?5m/#UoV]ZlR0C,Bn:F$K$$xk,-IOlvKq/yy_V9c:RX~I[nb)m2<C&B6rlTJ:
                                        2024-12-17 12:14:15 UTC16384INData Raw: 26 da 31 ed 40 ac 47 b6 85 5a 93 1e d4 63 da 80 b1 1b 2d 26 da 97 1e d4 98 a0 2c 45 b6 91 96 a6 c6 29 31 ed 40 88 59 69 8c b5 3b 2d 46 c2 9a 02 26 5a 6b 2d 4a c2 9b 8f 6a 4c 08 99 6b c8 3f 6a bd 46 38 ad 74 8d 2c b7 dd 91 ae a5 55 6f 9b 00 6c 5f cf 2d 5e 9f e3 3d 72 d3 c3 9e 1f 9f 54 b9 5f 33 cb c0 8a 25 6d ad 34 87 a2 8f f3 c0 af 9d b5 e9 2e fc 4f e2 89 35 7d 56 7f 32 4d df 77 76 d5 53 d4 2a 83 fc 22 bd 0c 05 27 29 fb 47 b2 3c cc 7d 64 a0 e9 ad d9 e7 fe 34 16 d6 11 c6 77 34 72 5c 7d d8 9b ef 28 7e 73 9f a5 73 7a 80 9e d2 66 b4 76 db b7 e6 66 8a 4d df 5c e3 b5 3b e2 4d c3 c5 e2 a9 64 8e 4f 34 2b 91 fb c5 cb 73 c6 08 f6 ac 88 f5 30 fa 5c 76 ef f3 c9 13 1d bb 5b 69 c1 f5 c5 7d 24 1d 95 8f 96 a9 16 e5 74 4c d6 57 37 5f bb b5 55 65 56 25 59 be 56 6e 3d 2b 23
                                        Data Ascii: &1@GZc-&,E)1@Yi;-F&Zk-JjLk?jF8t,Uol_-^=rT_3%m4.O5}V2MwvS*"')G<}d4w4r\}(~sszfvfM\;MdO4+s0\v[i}$tLW7_UeV%YVn=+#
                                        2024-12-17 12:14:15 UTC16384INData Raw: 3d fe d9 26 68 4e d8 d9 73 c6 79 3e 94 ac d6 e4 5d 33 99 f1 65 dc 77 7a 5b 25 d4 f2 44 19 24 31 2c 8b b5 2e bf ba c0 8e e3 ad 70 cc 6e 2c be d2 25 f9 a2 b9 8f 64 72 ab 7c 8c 33 82 47 e3 5e ab e2 0b 0d 2f 52 8e 39 6e 25 b1 8e 68 f0 16 49 24 f9 63 40 73 b5 47 03 24 7b 57 2d a9 78 56 3b fb 85 92 0b 9f dd f0 f2 44 cb f2 aa 2f 65 c7 4c 9a 77 4d 04 24 93 2a f8 3e ca ca df 68 9e 28 e4 ba 9d b2 be 64 db 16 38 c7 b5 6b 43 07 f6 84 97 51 6d 8d ad 55 4c 6a d1 2e df 24 b7 45 27 1f 33 77 f6 a9 af b4 e8 b4 ed b7 f2 45 24 9e 54 78 89 5b 1b 63 03 d3 8c f3 ef 59 9a 3e a4 2d bc 40 df 2c 8d f6 e8 97 ee c6 7e 67 c9 27 eb c1 eb 42 09 6a ca b7 3a e8 87 4b 9e 28 3c d8 ef 20 61 0c bf 31 db 21 ce dd d8 ed 9a b3 e3 8b 51 17 85 ed a7 8a 59 18 ac 90 ed fe 2e ae 3f c6 a4 d4 34 08 24
                                        Data Ascii: =&hNsy>]3ewz[%D$1,.pn,%dr|3G^/R9n%hI$c@sG${W-xV;D/eLwM$*>h(d8kCQmULj.$E'3wE$Tx[cY>-@,~g'Bj:K(< a1!QY.?4$
                                        2024-12-17 12:14:15 UTC16384INData Raw: 24 3c 44 1e e7 45 75 77 a7 fd 86 28 93 50 8d 8c 7c 6d 5c f4 e0 1f ce a9 69 b0 95 f1 02 bf cd fb 86 8f 6a b3 6e dc 33 cf e9 58 d6 33 a3 db c6 e9 b5 4a b6 6b 47 49 96 43 a8 3c e2 2f 30 ac 7f 32 ed fc bf 3a e8 8c b4 67 15 4a 4a e9 9a 7e 32 31 4b 6b 1d b5 84 0c 92 49 39 76 fe f3 13 fa e2 96 e3 4a 78 64 80 48 ad 14 6b fe be 46 5d dc 91 d3 e8 3d 69 da 7d b8 95 9a e6 e1 59 84 18 db 1a ff 00 cb 47 ea 7e 8a 2a 7b 8f 10 9b bb 39 ec 42 b4 10 f4 dd e5 86 5c 77 3c fb 66 a7 50 6d 22 6f 87 ba 5c 0d 75 2c b1 45 e6 24 52 15 f3 24 6e e3 e6 cf 15 a9 7e f7 12 5c 47 6d 68 de 61 6c 1b 96 dc 36 46 99 ef 4c f0 78 16 1a 4b 24 1b 55 59 49 56 97 3f 30 3e a7 e9 cd 4c d1 ce f7 d1 0d 3f cb 92 49 14 c8 cb b4 28 67 c1 55 07 db 9a ce 49 f3 1a c6 49 41 23 3f 5e 57 fb 1d b0 b7 89 71 23 67
                                        Data Ascii: $<DEuw(P|m\ijn3X3JkGIC</02:gJJ~21KkI9vJxdHkF]=i}YG~*{9B\w<fPm"o\u,E$R$n~\Gmhal6FLxK$UYIV?0>L?I(gUIIA#?^Wq#g
                                        2024-12-17 12:14:15 UTC16384INData Raw: a7 bb bc 90 09 19 7e e2 81 c7 27 ae d1 5d 6d e4 51 d8 de 5b 5c 36 ef 29 72 91 45 1a fc aa e7 1c 80 3f 13 4e 6e ec 8a 70 b2 ba 20 d3 fc 3d a6 69 97 92 1f bd e7 c7 86 dd f3 32 91 d9 7f d9 f6 ad 4d 36 d2 38 2e 25 b9 95 96 45 6c ee 8d 97 e6 c6 3b 7a 56 66 a9 26 75 a8 52 49 db ca b9 fd dc 5f 28 6e 9c fe bd 2b 52 d9 ec ac ed e5 89 d6 45 2d c7 fb 4d ed 50 e3 a1 a7 37 72 dd e5 a0 58 e3 92 e1 55 a3 dd 95 6d bb bb 74 03 fb b4 29 02 16 21 57 2d 17 ee d7 f8 b3 ef 54 bc 45 ac 5c 88 60 b0 b1 b6 56 f3 63 3b 5b 76 df 24 0c 7e 78 15 4b 56 d6 9a ca 35 31 aa cb 2a af f0 b7 dd cf 73 f8 53 84 65 62 2a 4d 5c b5 a9 44 97 1a 4f 9e bf bb 2d 1e c6 db f7 97 8c 10 7d eb 8e d6 16 4b 2b 7f 2e e5 96 4b 69 54 06 66 fb cb c5 74 76 af 79 7b a7 b5 ec 77 2d 15 b5 cc ac 60 8d a3 da 58 74 2c
                                        Data Ascii: ~']mQ[\6)rE?Nnp =i2M68.%El;zVf&uRI_(n+RE-MP7rXUmt)!W-TE\`Vc;[v$~xKV51*sSeb*M\DO-}K+.KiTftvy{w-`Xt,
                                        2024-12-17 12:14:15 UTC16384INData Raw: ad 64 2e 6d 63 69 6d 9a 49 04 12 7f aa 93 ef 46 3b e3 da b5 e3 78 2f 6c 70 55 66 8a 75 f9 95 be 65 60 6a f9 12 31 f6 8d e8 c6 ea 46 08 ec 65 99 e2 69 0c 4a ce df 66 5f 9d 80 ed 8a cc d3 f5 1b 6b 8b 58 ee 6d ef 16 58 e4 5f 97 77 de fa 7e 1e 95 72 c2 c2 ca c6 cd ad ec e2 5b 68 d5 fc cd aa c5 b6 9e bb b9 a4 9a ce de 4b 89 64 68 20 69 3e ff 00 ee d4 6e 90 e3 a9 ff 00 6a 8b 02 9e a4 6b a8 41 1c 8b 1e e5 69 24 fb ab 1b 6e dd f9 73 8a d1 83 cc 95 78 5e 3f bd 54 2c 2d ac a3 93 ed 29 67 1c 72 37 de 6d a3 77 bf 35 b5 6e c0 56 53 b2 3a a9 cb 9b a8 eb 5b 60 bc 9e ad 56 b8 0b 8a af 34 e9 1c 6c ee ca aa bf 79 99 be 55 a7 f9 88 63 f3 47 cc 19 73 f2 fa 57 3b 4d 9d 2a 56 0b cb 88 2d ed 5a 5b 99 56 28 d5 49 66 6f e1 02 bc c7 50 d4 6d af b5 25 b6 8e 36 90 4f 21 3e 66 e0 8b
                                        Data Ascii: d.mcimIF;x/lpUfue`j1FeiJf_kXmX_w~r[hKdh i>njkAi$nsx^?T,-)gr7mw5nVS:[`V4lyUcGsW;M*V-Z[V(IfoPm%6O!>f
                                        2024-12-17 12:14:15 UTC16067INData Raw: a9 58 c4 37 41 9f 2c 19 23 db f3 29 3d 71 f8 d6 b2 91 84 29 a6 ee 73 ba df da 6c e4 6d 3e de 56 68 e3 da df 2b 7d d2 46 78 ae d7 e1 a6 ad ae 6a 7a 6c f0 6a 0c cb f6 6c 47 1d cb 7d ff 00 5c 60 f5 e3 bd 72 7e 27 36 63 50 8e 2d 3f 73 34 8b 89 19 9b ef 1c f7 fa 56 cf 85 75 2b cb 0b 59 ed 12 06 6b 98 f0 63 89 98 2b 73 f5 ea b9 15 cf 53 de 47 75 3d 15 ce b3 c4 36 31 df 68 f2 db ce cc de 7e 12 45 5f 97 77 3c 75 fc eb 9c 9b 49 8e eb c3 f3 bd bc f2 79 b6 d1 62 25 dd bb cc 78 f8 da 7e b8 fc eb 41 7c 41 67 23 47 a7 df 4f f6 6b c8 f1 e6 ee 5d cb f8 11 d7 e9 50 db 6a 5e 4e ad 2f db 65 8f ec 92 47 e6 47 2a ff 00 cb 32 4f 3d 70 47 dd 1f f7 d5 44 14 91 52 e5 93 29 db df 3d ef 87 6d ae ed 2e 7c b9 9a 31 1c f1 c9 d5 88 eb b8 63 39 15 cf f8 82 d4 c6 ca ee fe 6b 4a d8 da bf
                                        Data Ascii: X7A,#)=q)slm>Vh+}FxjzljlG}\`r~'6cP-?s4Vu+Ykc+sSGu=61h~E_w<uIyb%x~A|Ag#GOk]Pj^N/eGG*2O=pGDR)=m.|1c9kJ
                                        2024-12-17 12:14:15 UTC16384INData Raw: 00 d5 de a0 bb 8e 57 9a 39 43 33 08 ff 00 e5 97 1b 5b eb 9a 46 92 0b 2b e8 e5 f2 a3 8c cf c6 ef ba cc 4f f3 35 56 d0 84 f5 26 3b 66 56 8d f7 36 df bd b7 8d b9 a5 91 7e ee 59 97 6e 36 ed 6f 4a 6c d7 76 90 dc 2d be e9 1a 4b 96 23 6e ef bb c6 7f a5 4d 21 43 d3 ad 25 70 d3 b8 fb 3b 93 32 ec 75 da df ef 7c b4 f5 ca ab 6f ac c9 12 76 93 64 0c d1 5c 32 92 8c df 32 71 eb 57 16 59 7e cb 18 7d be 6e d1 e6 7f 12 a9 c7 34 e5 15 7d 02 32 76 d4 97 cc da d8 3d 29 33 b7 8f bd ba ab 35 c4 66 45 8c ca bb 99 72 ab ed eb 4f de bd 0b d3 e5 12 95 cb 51 83 b7 27 fe f9 aa d2 4a 7e d9 e5 fc df 77 2d ba 8d f2 26 d2 9f 32 37 de a9 64 08 eb b4 d4 da c3 6e fb 0d dd 89 17 0d b8 d4 eb 26 17 96 ac c6 93 ca dd 1a af dd e3 fd ea 9e 17 df 6f c3 73 fe d5 54 a0 38 55 e8 3a 69 33 b8 d3 61 7c
                                        Data Ascii: W9C3[F+O5V&;fV6~Yn6oJlv-K#nM!C%p;2u|ovd\22qWY~}n4}2v=)35fErOQ'J~w-&27dn&osT8U:i3a|
                                        2024-12-17 12:14:15 UTC16384INData Raw: b3 48 db be 71 c0 db c0 01 71 52 da 68 d1 49 dc d5 f0 8d 81 1a 1d b2 41 e5 c1 0c 6b 95 55 8f e6 6c 8e 7a f4 cd 49 a9 5a ce cd 1c 6e bb a4 93 85 6d bb 92 11 dc ff 00 f5 ab 52 dd 62 87 f7 68 db 63 db fe ad 57 f5 ac b8 e4 13 6b d2 79 52 ac 8b 1a e6 4f e2 55 39 c0 c7 e1 52 95 dd ca 93 b2 45 c7 d3 e2 95 58 dd b3 5c 8d a0 6d e7 0a 07 4e 3b d6 0e 97 6b 77 06 b5 7d 79 76 bb 4e d0 2d 95 5b e4 58 fe 9f de ae 9a d6 44 6d db 5b 76 ef f8 0d 53 6d 2e c9 ae 9a 73 b9 64 6c 7d e9 09 55 c7 a0 34 bd 47 7e c6 36 a6 c5 ed 56 31 2a b0 93 2e ae bf 75 48 f5 f6 ae 77 5b f1 95 a6 97 0d 8d bd bc bf 6a 93 94 bb 81 7e fa f5 c6 4f 4d de d5 a3 ae 48 f6 2b 25 b3 ac 7e 5a e4 6e fe ef 53 f3 7b 1e 2b 8f d5 2c 46 a5 a7 ae af e5 2c 7a a5 d4 fb fc ad bb 7f 76 38 24 0f e2 e7 bd 55 ac 82 32 52
                                        Data Ascii: HqqRhIAkUlzIZnmRbhcWkyROU9REX\mN;kw}yvN-[XDm[vSm.sdl}U4G~6V1*.uHw[j~OMH+%~ZnS{+,F,zv8$U2R


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        1192.168.2.2449774150.171.27.10443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:14 UTC375OUTGET /th?id=OADD2.10239402415504_17DDWI2WCHUD2N4TB&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90 HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: tse1.mm.bing.net
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:14 UTC856INHTTP/1.1 200 OK
                                        Cache-Control: public, max-age=2592000
                                        Content-Length: 380972
                                        Content-Type: image/jpeg
                                        X-Cache: TCP_HIT
                                        Access-Control-Allow-Origin: *
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                        Timing-Allow-Origin: *
                                        Report-To: {"group":"network-errors","max_age":604800,"endpoints":[{"url":"https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE"}]}
                                        NEL: {"report_to":"network-errors","max_age":604800,"success_fraction":0.001,"failure_fraction":1.0}
                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                        X-MSEdge-Ref: Ref A: A600C8F7279C4CE898F6A82F7F8FD13C Ref B: EWR311000107027 Ref C: 2024-12-17T12:14:14Z
                                        Date: Tue, 17 Dec 2024 12:14:14 GMT
                                        Connection: close
                                        2024-12-17 12:14:14 UTC15528INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 48 00 48 00 00 ff e1 00 da 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 07 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 62 01 1b 00 05 00 00 00 01 00 00 00 6a 01 28 00 03 00 00 00 01 00 02 00 00 01 31 00 02 00 00 00 20 00 00 00 72 01 32 00 02 00 00 00 14 00 00 00 92 87 69 00 04 00 00 00 01 00 00 00 a6 00 00 00 00 00 00 00 60 00 00 00 01 00 00 00 60 00 00 00 01 41 64 6f 62 65 20 50 68 6f 74 6f 73 68 6f 70 20 32 35 2e 31 32 20 28 57 69 6e 64 6f 77 73 29 00 32 30 32 34 3a 31 30 3a 32 34 20 31 31 3a 30 33 3a 30 35 00 00 03 a0 01 00 03 00 00 00 01 ff ff 00 00 a0 02 00 03 00 00 00 01 07 80 00 00 a0 03 00 03 00 00 00 01 04 38 00 00 00 00 00 00 00 00 ff db 00 43 00 04 02 03 03 03 02 04 03 03 03
                                        Data Ascii: JFIFHHExifMM*bj(1 r2i``Adobe Photoshop 25.12 (Windows)2024:10:24 11:03:058C
                                        2024-12-17 12:14:14 UTC16384INData Raw: a6 f9 3c c1 8e a3 a7 43 d3 d6 bd 1c 05 2a 75 6a 72 4d 1c b9 95 4a d4 28 fb 5a 4d 69 ba 6b 73 a9 b1 d4 62 97 e7 0d 56 e7 94 49 0d 78 dd ae b9 aa e9 77 8d 0c be 64 52 c7 f7 a2 99 7e 65 ad 68 fc 71 a8 85 c1 8a 06 fc eb d1 a9 93 d5 52 f7 0f 2a 97 11 d0 69 7b 54 d3 3d 1d 25 1d 0d 6b 59 e8 37 77 36 ad 7f 6e cb 2c 50 ae 5b 6f cd 5e 6b a5 f8 ca da 56 5f b4 ab 44 7f 8b f8 85 7a 2f c2 6f 1e 69 1a 65 e5 d4 52 af da a1 ba 51 e6 47 1b 0e df 5e d5 c9 53 07 56 9f c4 8e c9 66 b4 ea d3 e6 c3 c9 37 db bf de 75 1e 1f bb d1 bc 21 a7 cf 16 b7 12 c5 1e a0 a5 be d6 d1 96 49 03 26 70 0f b7 b5 79 7f 89 b4 e4 9f 47 d4 35 27 55 95 77 34 96 ca 8a 55 d4 7b f7 35 d2 fc 41 d6 07 89 3c ab 72 ab 1d a4 12 19 62 8d a4 dd b7 27 f2 1e 94 78 5e 44 9e df fd 1b 6c f3 7c c1 63 5c 32 e4 74 06 a6
                                        Data Ascii: <C*ujrMJ(ZMiksbVIxwdR~ehqR*i{T=%kY7w6n,P[o^kV_Dz/oieRQG^SVf7u!I&pyG5'Uw4U{5A<rb'x^Dl|c\2t
                                        2024-12-17 12:14:14 UTC16384INData Raw: db f9 72 6c 35 f7 59 76 29 56 a2 af ba 3f 1d cf b2 e7 84 c4 b7 1d 9e a7 49 a6 df 5a 6a b0 c7 6d aa ca d1 79 7b 45 b4 b6 d1 a2 a4 23 a3 19 06 32 dc 7b d4 77 56 90 db ea 0d 15 bd e4 77 51 2b 63 cf 6f 91 5b f3 ed 59 9e 1d bd 1a 75 e7 9e 60 5b 9d aa 47 97 23 1d 99 3c 64 e3 d2 b5 af e7 d2 e4 ba 69 6c ad a4 82 de 48 c7 97 1c b7 3e 63 c6 ff 00 c4 78 03 82 7b 1e 95 dd 24 ac 78 31 72 4f c8 4b 93 68 ca d2 48 ad 24 d2 37 cc b0 e1 11 7e 9c 54 77 16 fa 74 f6 72 ba 4b 3c 17 51 b0 f2 e0 92 3d eb 20 ee 77 f1 b4 fe 15 a9 a5 7f 65 dd aa c0 fa 54 f3 cd 24 65 15 6d a7 3b 9a 43 d1 b1 cf 4f 41 55 f5 49 f5 03 71 15 cc f2 34 13 5b 30 10 33 47 b5 b2 87 8c b6 3e 66 1e f5 3c a5 3a 9d 0c 89 b4 db 8b 66 d9 3c 13 c5 27 f0 ac 91 15 eb 51 a2 9d d8 35 d5 f8 93 c7 3a fe bd 66 91 f8 8e 2b
                                        Data Ascii: rl5Yv)V?IZjmy{E#2{wVwQ+co[Yu`[G#<dilH>cx{$x1rOKhH$7~TwtrK<Q= weT$em;COAUIq4[03G>f<:f<'Q5:f+
                                        2024-12-17 12:14:15 UTC16384INData Raw: c4 6d 3f ed 3e 13 f1 05 b5 d3 2f 12 da 3f ee e7 84 fa 34 6d 83 fd 2b f3 51 ac fc be 63 dc df ec d3 24 28 b3 2c b0 45 24 57 51 36 e8 e5 8a 42 ae a3 d9 86 08 fa e6 b3 9c 23 3d d6 a7 34 f0 3f c8 ec 7e af b2 e5 b9 eb 49 b7 da be 12 f8 23 fb 50 7c 40 f0 ad ac 5a 3e b3 6d ff 00 09 6d 9c 0a 15 12 ee 61 1d dc 60 7a 4d d1 ff 00 e0 43 3e f5 ef 9e 03 fd ab 3e 1a 6b 5a 94 5a 67 88 62 d5 3c 25 7d 2e 36 ff 00 6b c2 16 0c 9e de 72 92 bf 89 c5 73 cb 0f 35 aa d5 1c 92 84 e1 f1 23 dc 71 4b b6 a3 b1 ba b5 bd b3 4b ab 1b 98 6e 6d a5 5c c7 2c 12 07 46 1e c4 71 53 57 2c 9b 4e cc 9d c6 6d a3 6d 49 8a 31 4a f7 02 3d b4 6d a7 e3 da 95 56 8e 60 b0 cd b4 6d a7 e3 de 8c 51 71 d8 66 da 36 d3 b3 4b 8f 7a 2e 85 66 47 b6 97 6d 39 85 18 f6 a0 6d 58 6e d3 46 da 7e 28 c5 2b 88 63 2d 1b 69
                                        Data Ascii: m?>/?4m+Qc$(,E$WQ6B#=4?~I#P|@Z>mma`zMC>>kZZgb<%}.6krs5#qKKnm\,FqSW,NmmI1J=mV`mQqf6Kz.fGm9mXnF~(+c-i
                                        2024-12-17 12:14:15 UTC16384INData Raw: 64 e7 d7 91 53 3a 6f 6b 1a 53 c4 47 ab b2 38 19 a3 31 36 c7 ea bf dd a1 00 3c 96 ae 97 5c f0 bf 88 2c 26 8c ea 9a 53 5b c8 ca 04 70 49 84 79 87 41 b5 7a b7 bd 55 4d 32 da 69 23 cf ee 2e 37 61 a0 e5 99 8f b2 75 ac 1c 5a 3a e9 ce 12 5a 3b 98 6a ae 5b 0a dc d6 9e 9b a4 6a 17 11 ac 90 59 c9 2c 4d 26 cf 35 63 2e 99 f4 ca 8a e8 34 5f 09 cf 79 75 bf ec aa d1 b4 9b 62 dd 1b c7 1b 11 d3 39 c1 00 9f 5a f5 0f 0e f8 12 f7 40 f0 ed cb dd df 47 a6 c5 1e d9 27 59 6e cc 8c c4 ff 00 0a db c3 93 c6 78 2c 73 58 4a bd 18 7c 52 3b 63 85 c5 4d 7e ee 1b f7 d1 1e 55 a5 68 ba 74 52 2c 97 92 fd a6 48 db 12 d9 43 3f 97 33 67 a1 4f 94 f0 3d c5 6d e8 b6 96 ed 7c a5 34 e5 b6 54 63 b6 39 18 b3 7d 5d 9b a9 f7 c5 7a 1d c6 93 61 6b 66 d3 d9 c9 76 d6 d1 4a a6 36 6b 21 6f 73 24 84 60 ff 00
                                        Data Ascii: dS:okSG816<\,&S[pIyAzUM2i#.7auZ:Z;j[jY,M&5c.4_yub9Z@G'Ynx,sXJ|R;cM~UhtR,HC?3gO=m|4Tc9}]zakfvJ6k!os$`
                                        2024-12-17 12:14:15 UTC16384INData Raw: b6 ec 55 42 ab fc 3f 75 bf 3a b2 da 6a 4b 0e fb 4b 98 a7 ff 00 c7 76 8f 7a a7 25 bc 90 73 22 ed 0d fc 55 7a 93 1d 36 37 34 3f 13 dc 69 fe 63 ee 99 8b 60 2c 6b 8d 98 ef 9f fe b5 75 7a 67 89 f4 bb f5 54 92 29 e3 6d bf 7b 8f 99 ff 00 c2 bc cd c6 7a 75 a9 2d a7 96 09 15 d6 b8 b1 18 38 55 d6 da 9e c6 07 35 ad 86 69 37 78 f6 3d 26 49 11 9b 21 b7 0a 6c ed b9 70 5b cc 35 8d a0 df 79 d6 eb bf ef 2a fc d5 a0 a4 9a f1 27 4e 50 93 47 d9 d2 ad 4e b5 35 35 d4 8a e6 1c f4 aa cd 19 11 b2 0e 8d f7 be 5f bd 57 18 e7 8a 16 35 1f ed 56 91 a8 d2 39 ea d1 8c fa 19 73 58 fc ac 42 d5 2b 9b 00 63 f9 62 db fd ef 9a ba 16 40 7a ad 43 24 01 9b da ba 29 e2 1a 7b 9c 35 b0 10 9a d1 1c db 59 63 90 db 4d 57 b8 b6 90 f5 dc df ef 57 4b 2d ba f4 db 55 a6 b6 25 b1 b6 ba a1 8a ee cf 2e b6 5a
                                        Data Ascii: UB?u:jKKvz%s"Uz674?ic`,kuzgT)m{zu-8U5i7x=&I!lp[5y*'NPGN55_W5V9sXB+cb@zC$){5YcMWWK-U%.Z
                                        2024-12-17 12:14:15 UTC16384INData Raw: fb 41 8e ab a4 5b 5f 43 1f 2c ad bf e5 1e b8 56 19 ae be c7 5d d1 35 4d 72 4b b8 9a 08 a1 56 fd d2 32 94 5f f8 08 27 3f a9 ae 0c 46 12 b5 1a 7c d2 8e 87 b5 82 ce b0 98 ba ea 9d 39 d9 be e3 9a d1 e2 69 9f f8 63 6c 6e 6c 2e e3 ec 3a fe 95 13 9f 4a bf aa f9 57 13 2b c0 d1 e3 6f f0 fd ea a7 e4 b9 55 27 a5 79 0a 77 d5 9f 5c a1 ca ac b5 20 27 d6 9a c4 0a b5 f6 6f e1 dd ff 00 8e d3 3c 80 78 74 6a ae 64 4c a2 da 2a 70 7a d5 7b 84 51 d2 af 4d 6a 43 7d fa 88 c1 db b5 69 19 23 9e a4 5f 53 3d b1 f7 5a a2 99 50 2f 15 7a 48 9d 24 da 57 6d 23 59 a7 cb f3 6e 66 ff 00 66 b7 8b b1 c3 38 dd d8 c7 b8 0c 38 15 17 92 5b e7 dd b4 ff 00 0e da e8 a6 d3 01 87 f7 31 72 bc b3 33 7a fd 6b 3f ec 47 73 79 7f 37 fb b5 bc 2b 25 b1 c3 53 0f 7d d6 86 5c 96 c1 17 2e de 69 93 f8 b9 66 a8 1a
                                        Data Ascii: A[_C,V]5MrKV2_'?F|9iclnl.:JW+oU'yw\ 'o<xtjdL*pz{QMjC}i#_S=ZP/zH$Wm#Ynff88[1r3zk?Gsy7+%S}\.if
                                        2024-12-17 12:14:15 UTC16069INData Raw: 3f 34 8f 53 95 15 9a df e6 fb ab 9a 4f 20 9f e1 db 56 b9 3d 29 af bc 2b 63 ad 1c cc 5c a9 11 c7 94 f9 b6 ee a7 a3 87 6e 29 98 91 97 8a 96 d9 47 fc b4 5e 68 64 eb 72 68 c2 f5 dd c7 f7 76 d2 f2 ab c2 b3 7f 77 f8 69 18 a8 6f 91 59 b6 ff 00 76 9b 23 b2 fd f5 e2 b3 b5 cd 51 13 c2 26 ea cb 85 a7 5b 84 45 c0 5d c7 fb d4 bb dc 6d fd d5 4b 1c bb ba d5 5d d8 56 57 b8 d8 e6 d8 d9 29 26 3f ba d8 a9 d2 74 6e 4f ca 3f dd a4 52 0f 55 e6 9c d1 a6 dc 05 e3 fd ea 87 63 44 a4 85 59 62 2b c7 dd a6 6f 5d dc 2b 31 a8 a6 01 55 bf 84 7f bd 50 34 8a 3a 35 35 1b 8a 55 1a 26 92 e8 af fb 27 fd ed d5 5a 4b 89 37 73 f3 7f c0 69 ac 41 5c 96 5c d5 79 1d c2 ec 33 ad 6b 18 a3 39 56 d4 9a 4b 96 46 c9 6e 3f da aa 72 90 78 45 e2 91 c9 ee ca d5 52 69 11 59 81 6a da 30 b9 8c b1 0a da b1 f7 0e
                                        Data Ascii: ?4SO V=)+c\n)G^hdrhvwioYv#Q&[E]mK]VW)&?tnO?RUcDYb+o]+1UP4:55U&'ZK7siA\\y3k9VKFn?rxERiYj0
                                        2024-12-17 12:14:15 UTC16384INData Raw: 6d eb ff 00 8f 53 e5 8a 0f 6b 53 b8 47 79 7a ad f2 ca ac 3f ba d5 61 6f 67 7f be df f8 f5 52 45 b7 55 f9 3f a5 49 19 4d d8 1b b6 fe 14 38 c3 b0 2a f5 7f 98 b4 97 53 06 e7 a7 f0 d4 df da 97 01 b6 47 3a af fc 0a aa 66 22 b8 3f 29 a6 ac 69 f7 c4 aa c7 fb b5 3e ce 0f 74 52 c4 56 5b 48 92 f2 f6 e4 6e 7f b4 f3 fd ef bd 55 97 54 bd 66 c1 9f 77 fe cd 53 0d bf c6 ab 27 fb b9 a4 62 07 dd 89 7f ef 9a 6a 30 5d 06 f1 15 bf 9d 92 c7 a8 5d f4 32 d4 8b 77 74 39 13 b5 54 20 b7 25 78 ff 00 66 8f bc d9 fb b4 b9 21 d8 bf ac 56 fe 66 5d fb 75 c8 5c 79 ed 8a 6c b7 13 6d e6 76 ff 00 be aa bb 1d ab 83 ff 00 a1 52 7c ff 00 29 1b 73 47 24 7b 07 d6 2a b5 f1 32 78 66 b8 0c cf e6 f0 bf ec d2 b5 ec e7 8f 36 a2 65 1d 5e 55 ff 00 76 9d 1e c1 fc 34 72 c7 b0 bd bd 65 f6 87 ac f2 ed e6 76
                                        Data Ascii: mSkSGyz?aogREU?IM8*SG:f"?)i>tRV[HnUTfwS'bj0]]2wt9T %xf!Vf]u\ylmvR|)sG${*2xf6e^Uv4rev
                                        2024-12-17 12:14:15 UTC16384INData Raw: a0 ea b4 8d 1c 67 fe 59 6d aa f7 49 b6 a3 e3 bc 01 be f3 2f fe 83 52 2d d6 ee 37 b3 55 63 6e 0f 21 69 56 30 9c fd d6 a1 f2 db 41 ea 58 62 c7 76 1a a0 b9 c8 5c 89 55 a8 90 1d df 7a a3 78 83 b5 4a dc 2f 7e 85 5b 89 df 76 04 aa df ee d3 4b 12 bf 7a ac b4 00 7f 0d 2a db 81 cd 6d cd 14 88 57 b9 4f a7 de 65 a6 3b 7f 71 77 55 c9 2d 03 f1 b7 fe f9 a8 9b 4e ca ff 00 74 55 29 c5 8b 52 ac 2f b5 98 9e ad ce da 9f 74 2d d5 6a 44 d3 9c 74 dc c2 a7 5b 3d bc 6d 6c d2 94 e3 71 59 a4 53 56 da d8 4f 94 d4 d1 c9 20 a9 5a d9 ff 00 b9 4b 0d b1 fe ed 27 24 d0 72 bb 9c 87 f6 8e a0 7a 6e 56 a5 6b cd 43 fe 7a b2 d6 ab d9 c3 fc 57 34 e4 b3 b4 db fe bf fe fa ae ff 00 69 0f e5 38 b9 2a 5f 56 64 3d c5 e3 75 9e 4c d2 a3 5e 1f f9 6f 27 fd f5 5b 69 67 6d b7 fd 7a b7 fc 06 86 b4 b6 0d cc
                                        Data Ascii: gYmI/R-7Ucn!iV0AXbv\UzxJ/~[vKz*mWOe;qwU-NtU)R/t-jDt[=mlqYSVO ZK'$rznVkCzW4i8*_Vd=uL^o'[igmz


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        2192.168.2.2449775150.171.27.10443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:14 UTC346OUTGET /th?id=OADD2.10239402415503_1IET5OVL073FDA0RX&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90 HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: tse1.mm.bing.net
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:14 UTC854INHTTP/1.1 200 OK
                                        Cache-Control: public, max-age=2592000
                                        Content-Length: 352481
                                        Content-Type: image/jpeg
                                        X-Cache: TCP_HIT
                                        Access-Control-Allow-Origin: *
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                        Timing-Allow-Origin: *
                                        Report-To: {"group":"network-errors","max_age":604800,"endpoints":[{"url":"https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE"}]}
                                        NEL: {"report_to":"network-errors","max_age":604800,"success_fraction":0.001,"failure_fraction":1.0}
                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                        X-MSEdge-Ref: Ref A: 3868C40B92E84EA396807B8F7E1D4133 Ref B: EWR30EDGE0106 Ref C: 2024-12-17T12:14:14Z
                                        Date: Tue, 17 Dec 2024 12:14:13 GMT
                                        Connection: close
                                        2024-12-17 12:14:14 UTC15530INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 48 00 48 00 00 ff e1 00 da 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 07 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 62 01 1b 00 05 00 00 00 01 00 00 00 6a 01 28 00 03 00 00 00 01 00 02 00 00 01 31 00 02 00 00 00 20 00 00 00 72 01 32 00 02 00 00 00 14 00 00 00 92 87 69 00 04 00 00 00 01 00 00 00 a6 00 00 00 00 00 00 00 60 00 00 00 01 00 00 00 60 00 00 00 01 41 64 6f 62 65 20 50 68 6f 74 6f 73 68 6f 70 20 32 35 2e 31 32 20 28 57 69 6e 64 6f 77 73 29 00 32 30 32 34 3a 31 30 3a 32 34 20 31 31 3a 30 33 3a 32 39 00 00 03 a0 01 00 03 00 00 00 01 ff ff 00 00 a0 02 00 03 00 00 00 01 04 38 00 00 a0 03 00 03 00 00 00 01 07 80 00 00 00 00 00 00 00 00 ff db 00 43 00 04 02 03 03 03 02 04 03 03 03
                                        Data Ascii: JFIFHHExifMM*bj(1 r2i``Adobe Photoshop 25.12 (Windows)2024:10:24 11:03:298C
                                        2024-12-17 12:14:14 UTC16384INData Raw: fd 0d 7d 03 fb 3f 7e d3 ba ee 85 a8 41 a1 7c 4c 9f fb 42 c2 76 02 3d 59 97 69 87 fd ff 00 f1 af 07 7b 59 ed be 79 2c da 30 cb f2 b3 2f 7a 6b da f9 f0 b7 c8 ce 19 70 d5 bc 71 12 5b bb a3 cf af 95 e1 ea af 86 cf ba 3f 4d b4 ab cb 3d 53 4b 83 53 d3 2e 56 e6 d2 e5 43 c5 2c 6d b9 58 1a 9d 79 e0 d7 c1 7f 08 fe 31 78 c3 e1 96 83 67 65 a4 5e 2d d5 8c 52 6c 6d 3e e7 e6 55 4f 55 6a f7 3f 03 fe d6 de 0d d4 75 44 d3 fc 53 a7 cb a3 b4 d8 55 ba fb d1 b1 3e a7 b5 74 46 49 ec cf 9c ad 82 ad 49 bb c6 eb b9 f4 0e 07 fc 0a 86 fb d5 0e 97 7b 65 aa 69 b1 5f 69 b7 70 dd 5b 4a b9 59 22 6d cb 8a 9f f8 aa 8e 68 b4 d6 80 d4 7f 0d 2a f1 43 71 40 68 26 0d 2e 3b 9a 17 de 8c ff 00 df 34 98 98 01 9a 31 96 a3 18 a0 f1 f5 a4 82 20 46 ea 45 a7 2a 8a 31 45 d0 d8 94 ea 45 f4 a3 ff 00 42 a1
                                        Data Ascii: }?~A|LBv=Yi{Yy,0/zkpq[?M=SKS.VC,mXy1xge^-Rlm>UOUj?uDSU>tFII{ei_ip[JY"mh*Cq@h&.;41 FE*1EEB
                                        2024-12-17 12:14:14 UTC16384INData Raw: ed 6f a3 9e 58 17 cb 55 56 fe 32 71 80 7b d7 95 f8 6e 65 85 a6 bd bd 8a 39 24 95 f7 ff 00 ba 3d 2b 91 d7 3c 75 e1 47 bc 83 47 b1 d4 d6 5b 6b 11 b2 49 d7 ee cd 27 73 f4 cd 49 75 e3 5f 0c 43 0a c4 75 35 53 fd dd a7 75 72 d5 c2 62 1b fe 1b fb 8e ec b2 96 03 0d 42 51 55 97 bc f5 d5 2d 11 b1 af 3f da e6 92 45 f9 77 35 76 9e 0c b9 d4 fc 4f 66 9e 1e d3 1e db 4e d3 ad 50 7d aa 44 ea ff 00 e3 5e 46 3e 20 f8 4a 4b e8 ad 0d d5 cf 92 cd 89 67 58 3e 55 1f 4e f5 b5 f0 27 c5 d3 a6 bd a8 78 b1 2c 5a 3f 0e 5a f9 90 34 d2 c9 b7 ce 23 a1 fc 3b d7 46 13 2a c6 c9 fc 0e c2 cd f3 9c b6 38 66 95 44 e7 1f 87 ae bf 97 a1 ea 7a 2f c2 b3 17 8c 13 55 d4 2e 63 9e da cf f7 90 41 12 f3 21 f7 35 85 e3 cb bb fd 53 5a 9e e6 7b 6f 21 62 fd dc 63 ee ac 6a 2b cf fe 25 fe d3 1a f5 fc 92 e9 de
                                        Data Ascii: oXUV2q{ne9$=+<uGG[kI'sIu_Cu5SurbBQU-?Ew5vOfNP}D^F> JKgX>UN'x,Z?Z4#;F*8fDz/U.cA!5SZ{o!bcj+%
                                        2024-12-17 12:14:15 UTC16384INData Raw: bb 53 21 dd 1d 47 20 3b b0 7a d3 a3 f9 78 a2 e5 5b 42 4c 01 d4 d0 a9 d8 b5 39 47 7a 24 52 7f 8a 95 ee 03 55 80 ea d5 e8 bf 06 74 15 91 9b 58 91 9b f7 7f 24 6b fd 6b cf 14 0f 98 7c d9 af 66 f8 4a 8b 07 86 60 42 cd 86 e5 ab c7 ce ab 4a 18 66 a2 f7 3e ab 84 b0 90 ad 8f 4e 6a ea 3a 9d 4c 60 ba ed 0b c2 d3 94 ed e2 91 a4 10 af 0d b7 75 47 e7 46 5b 01 97 3b 6b e1 f5 3f 60 d1 0e 63 f2 e7 bd 37 96 fa 54 73 46 eb 27 de 56 1f ec d3 90 e5 79 a0 6b 52 55 38 e9 f3 54 b0 8d dd 5a a0 8f 1d 2a d3 32 24 7f bb dc c6 82 65 a1 24 d2 e2 d7 c8 4f 96 36 fb d5 59 82 46 df 22 ff 00 c0 69 a5 f1 1e 2a 38 48 dd cb 6d db 4a c4 28 a4 5a c1 5e 5d bf e0 35 0b 30 1b ce e6 5d b8 3b a9 48 2e d8 dd bb ff 00 65 a8 a6 60 19 96 6f bb 1f dd 6a 63 45 e8 64 22 15 95 1b 69 65 ab 4a c0 ab 49 3c 9b
                                        Data Ascii: S!G ;zx[BL9Gz$RUtX$kk|fJ`BJf>Nj:L`uGF[;k?`c7TsF'VykRU8TZ*2$e$O6YF"i*8HmJ(Z^]50];H.e`ojcEd"ieJI<
                                        2024-12-17 12:14:15 UTC16384INData Raw: 54 c6 bf 75 bf 8a b0 b4 b9 83 37 ce ac aa df de fe 2a ea b4 78 62 fb 2b 18 fe 63 fd da e7 c6 56 4a 92 8b 47 56 59 83 94 b1 1e d5 3f 91 9d af 69 fe 6c 8b 3a f9 6b e5 73 b5 b9 aa b1 b6 f5 de 56 35 2d fc 31 ae d5 fc ab a0 ba b5 b8 6b 76 12 40 d1 34 9f c2 cb f3 62 b1 2e ac dd 37 6c e8 bf 7a b9 28 d7 72 87 25 cf 43 15 84 51 ad ed 14 75 62 79 0f 70 df bd 89 64 89 7f e7 9d 5b 4d 2a dc c3 80 bc 56 95 85 c4 b1 69 30 5b 79 50 2f 96 a7 e6 58 fe 66 cf 76 3d e9 73 b9 79 ac eb 57 95 ed 16 74 61 b0 71 b5 e6 8c 6d 4a 01 06 9f e4 c9 f2 af 55 68 d7 6d 61 36 a1 a9 e9 f1 b1 8a 4f 32 26 fe f7 55 ae b2 f8 24 91 b4 52 2e f1 58 7a c5 b0 92 d7 01 7e 55 fb d5 d3 85 ac 9e 93 d4 f3 f3 0c 1c ad cd 47 4b 1e f9 fb 11 6a ad ad 78 3f 5c d0 f5 3d 32 46 d3 ee 1f cb 59 d5 b7 75 1c ae 3b 57
                                        Data Ascii: Tu7*xb+cVJGVY?il:ksV5-1kv@4b.7lz(r%CQubypd[M*Vi0[yP/Xfv=syWtaqmJUhma6O2&U$R.Xz~UGKjx?\=2FYu;W
                                        2024-12-17 12:14:15 UTC16384INData Raw: 51 64 97 7e dd ed ba 9c 9e 5b af 32 f9 7f 2d 43 70 83 6c 64 3f 3f c4 b4 8f 21 75 58 f6 fd d5 a9 48 d3 9d 5a c1 34 52 79 98 4f 98 7f 79 69 ca 82 36 c6 ed c5 7e f5 2a 89 3c 9c a2 b3 76 dc bf 76 96 d2 ce 5b 89 3c b4 97 6b 37 f7 ab 42 1c 6f ad cb 96 b7 37 d0 c3 93 75 23 47 bb 3e 5c 78 aa 5a 95 ed dd e4 98 b8 95 9a 56 6f bd 26 77 63 b0 ad 8b 8b 38 34 e6 8e da 2b e8 2f a4 93 06 49 22 ce d8 cf a7 35 3c d7 97 8d 1f d8 e4 89 54 ff 00 0a ac 61 77 51 4e ae b6 b1 8d 5a 71 e4 ba 3b df d8 c3 4c 97 fe 12 ad 63 51 b9 b1 59 56 de 05 4b 6b b6 8c fe ec 9f bc 14 f4 fa d7 a8 7c 66 f1 1e 95 a1 78 7d ed ef 96 e6 49 ee 93 10 46 9c 23 1e d9 f5 02 b0 7e 0a f8 53 c4 be 1f f0 b3 5c df 6a f0 da e9 f2 fe fe 5b 55 52 c7 9e ec dd b8 ec 2b 85 f8 c9 e2 5b 6f 13 78 bb 3a 77 99 f6 2b 34 f2
                                        Data Ascii: Qd~[2-Cpld??!uXHZ4RyOyi6~*<vv[<k7Bo7u#G>\xZVo&wc84+/I"5<TawQNZq;LcQYVKk|fx}IF#~S\j[UR+[ox:w+4
                                        2024-12-17 12:14:15 UTC16384INData Raw: c2 33 1c 9a df 89 1e 3b ad 6a e5 8b 6d 8f e6 4b 51 fd d1 9e a7 de ad 61 f9 2d 24 73 d7 cc 63 0a 7c 8d 68 65 fe cd bf 0b d7 c2 56 b7 3e 23 d4 ff 00 7b a8 6a 71 a7 91 1c 8b b4 da c6 3b 7b 31 ef 5e 91 a8 79 f2 dc 2c 71 f4 fe 2a bb 71 3e f5 c9 6d df dd a8 a1 65 da f9 6e 7f 86 bb 21 29 de ec f9 7a f2 55 1b 31 75 59 a2 b4 85 ad e3 fe 2f bc df 4a c7 10 f8 96 f2 e9 46 8f a6 c7 2d aa a9 2f 3d cc db 23 5c 7e a6 a5 f1 42 5c aa c9 f6 78 96 59 23 52 56 36 6d ab 21 ec 33 5c 26 b5 a7 fc 63 f8 8b 0a e9 5f 63 b4 d0 74 fb 35 c4 8b 6d 33 a4 77 07 dc 8e 5b f0 ae ca f8 88 d1 a4 ac f5 67 0e 0f 03 3c 4e 21 ca 6d 46 11 ea f6 38 8f 8a 3e 28 d6 35 5f 13 2d b4 f7 30 ca 2c 58 db 47 f6 26 2c b3 12 70 71 9e b5 eb 7f 03 7e 12 8d 12 e1 3c 51 ae df 47 fe ab 7f 91 bb 09 07 7c b1 ee 6a e7
                                        Data Ascii: 3;jmKQa-$sc|heV>#{jq;{1^y,q*q>men!)zU1uY/JF-/=#\~B\xY#RV6m!3\&c_ct5m3w[g<N!mF8>(5_-0,XG&,pq~<QG|j
                                        2024-12-17 12:14:15 UTC16067INData Raw: 3e 65 46 e9 39 af bc da 56 4d bb 87 cb b7 1f 2d 39 76 49 1b 18 ff 00 86 b2 e1 d4 ad dd 5b 7c aa ac bf 79 6a 75 9e 0d b9 8d 97 1d 37 6e fb d5 c6 e9 4a 3b a3 d6 8e 22 95 45 ee c9 7d e4 de 58 2d b1 db 68 6e 37 7f 76 ab be 9e 86 16 27 cb 62 df c3 53 ab fc bc ae e2 df c5 ba a4 b7 31 fd ab 12 ae e5 db f7 55 b6 d3 52 94 76 61 2a 74 e7 ba 31 a4 b0 0d 26 c0 bb 7b 55 77 b7 b8 86 6c ee 6c c7 fc 2d f3 6e ae 8a eb ec ce df b9 83 cb 0b fe d6 ea af 20 49 37 07 fd db 2f dd dc b5 d3 47 11 3b 9e 56 2b 2f a7 2d 63 a1 1c 7e 24 bb 93 49 5d 3e 6b 6f 2a d5 5b 3b 96 3d cd bf d7 3d 6a 38 26 82 49 98 c1 78 b2 05 fb ab b4 ab 66 ae 5a c3 72 ec b1 46 b0 37 9a db 77 34 1c fe 02 b5 f5 4f 0f 26 9b e1 b8 cd e7 88 d6 4b e9 5c 18 34 98 2d a3 66 58 fb b4 92 0e 41 f6 ae a7 4a 94 a3 cd b3 3c
                                        Data Ascii: >eF9VM-9vI[|yju7nJ;"E}X-hn7v'bS1URva*t1&{Uwll-n I7/G;V+/-c~$I]>ko*[;==j8&IxfZrF7w4O&K\4-fXAJ<
                                        2024-12-17 12:14:15 UTC16384INData Raw: 18 e3 ff 00 1a b0 8a 56 1d bf 74 af de a8 a4 b4 8e 56 57 95 9b 72 af ca b5 9f 36 a6 de ca 56 29 2c 77 08 ac 53 e6 fe ee ef e2 a2 4b 7d 46 4f be 9b bf e0 55 7e 4c c7 1a e3 ee 7d d5 a7 33 16 5c 9f 94 ee a7 ed 19 3f 57 4d 6a cc 68 ed ef 44 d8 75 da 37 7c db 9a af 47 6f e7 2e 0b 6d 1f ec fc b5 6d 62 cb 72 fb 85 4c b0 c4 ac a0 7c bf f0 1a 52 ac d9 70 c2 a5 b1 59 22 b7 81 73 e5 b4 8d b7 ee ab 7c b5 2d bf 9e d2 2b 3e d8 e3 da 7f 75 1f cb f9 9a 7c 9b 37 30 0b ba 9d 0c 27 a8 ac 5c ae 74 46 1a 86 dd b1 fd d5 51 fa d3 15 07 6d cc 37 7c db aa 6f dd 96 c4 8c ab fe f5 34 3c 66 4c 24 bb bf bd f2 d2 b9 af 50 f2 a3 91 98 05 e7 f4 a9 23 de 8d e5 f9 4b b7 ff 00 41 a7 a3 aa 6e 03 e6 2d fc 54 e0 fb e4 c5 4b 6c d2 28 45 60 17 ef 7c df dd a1 98 0e b5 3a ed e8 76 d4 53 18 fe 62
                                        Data Ascii: VtVWr6V),wSK}FOU~L}3\?WMjhDu7|Go.mmbrL|RpY"s|-+>u|70'\tFQm7|o4<fL$P#KAn-TKl(E`|:vSb
                                        2024-12-17 12:14:15 UTC16384INData Raw: f2 6a 39 75 2b 7e 9b 5b fe fa ae 32 e3 5e 07 a4 fc 55 66 d7 23 1c ee a8 59 7c db d8 a9 71 0d 18 ad 19 da cd aa 44 8c c6 3e bd 36 d5 6b 9b 93 22 e7 e6 c7 5a e3 ff 00 b6 c7 65 56 2d fe d5 4d 0e b9 27 cc 0f 96 a7 fd ea d1 60 26 b6 46 4f 3e a5 2d e4 75 b6 d7 8a ab 9f 29 bf da 6d d4 f9 26 81 b9 76 dd b7 fb d5 c7 4b ab 07 e5 db 9a 86 4d 5f 6f 1b b8 a3 ea 33 64 bc fa 9c 15 af 73 af 92 ea 38 d9 9b 72 d4 2d aa ca 24 e2 26 51 fe f0 ae 56 4d 62 0e 9b b9 ff 00 66 93 fb 6a 2d b8 dc d5 a7 d4 65 d5 18 3c fa 0f ed 1d 84 7a 8e d8 d8 9f de 16 fe f3 7d da 81 af 9a 4e 8a ab 5c 9f f6 9c 7b 72 25 a3 fb 48 bf fc b7 e3 fe f9 aa 58 19 76 33 96 7d 4e df 11 d8 25 c0 5d a7 cd 55 2b 53 43 a8 85 dc 59 95 8f f7 ab 85 5d 47 2d fe bf 8e 9b 6a 44 d5 11 3a b5 0f 2f 93 22 39 f4 56 c7 68 da
                                        Data Ascii: j9u+~[2^Uf#Y|qD>6k"ZeV-M'`&FO>-u)m&vKM_o3ds8r-$&QVMbfj-e<z}N\{r%HXv3}N%]U+SCY]G-jD:/"9Vh


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        3192.168.2.2449771150.171.27.10443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:14 UTC346OUTGET /th?id=OADD2.10239402414228_1EUMX2S6TUEXTBXLL&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90 HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: tse1.mm.bing.net
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:14 UTC861INHTTP/1.1 200 OK
                                        Cache-Control: public, max-age=2592000
                                        Content-Length: 508979
                                        Content-Type: image/jpeg
                                        Access-Control-Allow-Origin: *
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                        Timing-Allow-Origin: *
                                        Report-To: {"group":"network-errors","max_age":604800,"endpoints":[{"url":"https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE"}]}
                                        NEL: {"report_to":"network-errors","max_age":604800,"success_fraction":0.001,"failure_fraction":1.0}
                                        X-Cache: CONFIG_NOCACHE
                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                        X-MSEdge-Ref: Ref A: 4A762B62E4864E7E9CF7AEF59278152E Ref B: EWR30EDGE0312 Ref C: 2024-12-17T12:14:14Z
                                        Date: Tue, 17 Dec 2024 12:14:14 GMT
                                        Connection: close
                                        2024-12-17 12:14:14 UTC3675INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 48 00 48 00 00 ff e1 00 f4 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 07 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 62 01 1b 00 05 00 00 00 01 00 00 00 6a 01 28 00 03 00 00 00 01 00 02 00 00 01 31 00 02 00 00 00 3a 00 00 00 72 01 32 00 02 00 00 00 14 00 00 00 ac 87 69 00 04 00 00 00 01 00 00 00 c0 00 00 00 00 00 00 00 60 00 00 00 01 00 00 00 60 00 00 00 01 41 64 6f 62 65 20 50 68 6f 74 6f 73 68 6f 70 20 32 36 2e 31 20 28 32 30 32 34 31 31 30 33 2e 6d 2e 32 38 33 34 20 31 34 64 33 65 37 34 29 20 20 28 57 69 6e 64 6f 77 73 29 00 32 30 32 34 3a 31 31 3a 31 32 20 31 33 3a 32 36 3a 35 38 00 00 03 a0 01 00 03 00 00 00 01 ff ff 00 00 a0 02 00 03 00 00 00 01 04 38 00 00 a0 03 00 03 00 00 00
                                        Data Ascii: JFIFHHExifMM*bj(1:r2i``Adobe Photoshop 26.1 (20241103.m.2834 14d3e74) (Windows)2024:11:12 13:26:588
                                        2024-12-17 12:14:14 UTC8192INData Raw: 8c d1 fc cd 14 11 d3 14 00 0c 52 fb 51 8a 5e b4 00 9d 29 7d a8 eb 46 0d 00 03 d2 8c 9e 86 95 69 68 01 be d4 64 d3 8f 2d 9a 42 28 01 41 cd 27 d6 95 7a 51 d6 80 11 69 71 f3 51 42 f5 a0 61 8c d1 fc 59 a5 c7 71 4b d7 ad 02 1b 45 18 34 ab 40 06 28 c5 2e 05 14 00 98 a5 03 14 63 3c 8a 55 18 a4 ca 13 1f 35 07 da 8f 7a 75 20 1a bd 68 e8 29 d4 50 02 74 a3 93 4b 45 00 27 4a 00 a5 a3 f8 73 40 06 45 18 14 ac 31 48 05 00 18 ef 40 f7 a2 95 68 01 28 1e d4 63 d6 97 14 00 94 a0 7c d4 b4 75 e9 40 08 00 a4 a7 1f 6a 28 01 b4 ef ad 14 0e 68 00 1c f4 a3 1d e9 d4 da 00 28 a2 97 19 e6 80 10 66 8f 7a 30 69 71 f2 e6 80 12 97 1d a8 c6 7a 52 ff 00 17 14 14 34 fa 53 bf 86 8c 0a 1b a5 02 11 69 79 a0 71 d2 8a 57 18 63 34 50 7d a9 40 cd 0c 16 e2 50 bd 69 7d a9 40 c5 2b 94 27 4a 4a 77 34
                                        Data Ascii: RQ^)}Fihd-B(A'zQiqQBaYqKE4@(.c<U5zu h)PtKE'Js@E1H@h(c|u@j(h(fz0iqzR4SiyqWc4P}@Pi}@+'JJw4
                                        2024-12-17 12:14:14 UTC3986INData Raw: 33 d5 e5 82 ed 6d ae a5 b6 68 6d 49 6c 33 3b 60 61 7b 92 01 27 8e 95 b3 79 ab 69 d6 de 1e b8 d6 fe d0 b2 d9 5b 46 f2 3b c4 73 90 bd 40 f7 cf 18 af 9e 3c 61 e2 bd 47 c5 ba e4 ba 94 a0 2c 69 98 ac ec cf 48 c6 7a 67 b9 3d cf 7a f2 b0 b4 1d 49 dd ec 8f 63 19 88 54 e1 65 bb 30 6d c1 d3 b4 f8 24 61 b2 12 e1 4c c8 bb b9 f4 6f a9 f5 c5 47 36 a0 d2 b7 97 04 ab 0e 1c ed 28 4a e4 ff 00 74 82 4f 24 7b 55 ed 42 e2 49 34 d9 ac e6 05 62 9b 2c df 2e 0a 9e a0 74 ec 47 e9 5c 65 c5 d8 8c 80 fc c8 c4 ee 64 e9 90 38 23 d2 bd cd cf 0a 31 3d af f6 7c f1 5f d8 bc 53 fd 95 7d 24 89 16 a6 04 71 af f0 09 87 2a de c4 80 47 e5 5e ea a7 35 f2 27 84 6f 84 37 f6 17 d1 93 ba de 64 91 5c 74 dc ac 0f 23 8a fa eb 39 62 47 43 c8 af 1b 1f 04 a6 a4 ba 9e de 5f 26 e0 e2 fa 0f 5a 7a 9c f5 a8 96
                                        Data Ascii: 3mhmIl3;`a{'yi[F;s@<aG,iHzg=zIcTe0m$aLoG6(JtO${UBI4b,.tG\ed8#1=|_S}$q*G^5'o7d\t#9bGC_&Zz
                                        2024-12-17 12:14:15 UTC8192INData Raw: d0 03 81 14 1f bb f2 d2 7f 0d 28 1f 2f b5 48 07 f2 a2 81 ea 68 a0 02 81 c5 1d 28 fe 2a 00 28 a2 8a 00 28 a2 8a 00 33 da 8a 17 a5 27 f1 71 40 0b d3 a5 19 14 80 d2 1e 68 01 49 a2 92 8a 00 c9 ce 69 ad d6 9d 4d 26 ba 0e 71 33 8e 29 38 ed 47 14 da 60 12 32 a2 33 b9 da a8 a5 99 8f 60 06 49 fc 2b e6 5f 88 de 23 6f 12 78 da ea f1 01 68 ae 76 c1 6c a7 39 48 d7 a7 b7 3d 73 5e f9 f1 43 52 5d 2b e1 e6 b1 7a 4e 19 6d 1a 34 f7 67 f9 00 fc da be 5b b4 92 45 b9 03 ef 6d 72 33 eb 81 fa 72 6b d2 c0 41 6b 3f 91 e4 66 55 1d e3 05 ea 56 f1 25 cd e6 9f af 43 70 92 b4 22 70 11 98 1d c0 29 39 0d 81 8c 11 8e d5 7f 55 bc 9e fd 56 29 64 97 7b 10 37 06 3b 4a e3 00 67 de ab df 3c 0b 34 8f 3c 63 62 40 f8 04 ee 01 b1 80 07 4e 46 7b f4 f7 a6 e9 f2 db cb 65 24 05 83 0d 81 a2 27 23 6e 79
                                        Data Ascii: (/Hh(*((3'q@hIiM&q3)8G`23`I+_#oxhvl9H=s^CR]+zNm4g[Emr3rkAk?fUV%Cp"p)9UV)d{7;Jg<4<cb@NF{e$'#ny
                                        2024-12-17 12:14:15 UTC8192INData Raw: 32 91 9f ba 47 04 53 72 b1 2a 3c d6 38 a6 79 67 85 6d 63 cb 49 26 00 c7 7c 8e 45 7a 45 ac 31 d8 58 d9 e9 f1 ff 00 cb ba 05 64 19 19 6c 67 24 f1 df 3c f4 a8 74 9d 0f 41 b2 d1 52 f7 4f 96 49 ae a5 60 aa 66 3c 83 8f bb 80 00 18 f5 a5 7b 9b 47 fb 32 4f 70 cd 70 f2 ba a9 7c 86 dc 01 24 71 c6 0e 7a fd 2a 65 2b d8 ba 71 4a e7 2f f1 15 a6 8b 5e 5b 8c b1 0e 80 a9 ea 78 e3 af b1 ab 1e 15 9e 5f ec f8 c2 47 e6 64 15 20 f4 c7 bf b5 4d f1 02 cb ed 56 c9 3a 38 c4 59 1d 71 9e 9c 01 eb 51 78 1e 78 d7 4f 8e 2c 65 91 98 b1 1d c6 7f a5 52 d5 02 f7 64 74 f6 13 40 21 4d e9 1e 4a e1 43 47 c8 23 d3 ff 00 ad 45 a5 bc 6f 75 70 43 ca 87 e5 63 d3 03 23 1d 0f 6a 22 9d 4b 84 64 38 24 32 63 1c 63 b9 a2 d5 e2 5b 89 d1 4b 30 01 70 5b 92 3a 92 0f b0 ac a4 8d a3 22 d1 8e e2 2b 34 33 4b 1b
                                        Data Ascii: 2GSr*<8ygmcI&|EzE1Xdlg$<tAROI`f<{G2Opp|$qz*e+qJ/^[x_Gd MV:8YqQxxO,eRdt@!MJCG#EoupCc#j"Kd8$2cc[K0p[:"+43K
                                        2024-12-17 12:14:15 UTC8192INData Raw: ca 13 d4 0f f3 e9 54 6d ee a4 89 db 6e ed cb e8 71 fa 8f 4a d0 d1 21 5b 9d 1d 66 23 6b c6 70 e4 e0 70 7b f1 e9 81 55 2f 60 30 17 63 82 ac 38 61 5c f2 dd 9e 95 1b 38 23 7f 4b bd b6 bf 90 ba 02 0b ec f3 79 03 0b d0 e0 fa 93 cd 4f ad e9 ba 56 f9 8a 6e 43 f7 49 c8 24 12 71 9c 0c 66 b1 3c 37 20 b7 b4 59 a4 da aa 32 37 8f af 19 1d ce 7d 6b 73 55 4f ed 1d 1e 2b b6 70 a6 20 59 58 e7 05 7b 86 03 a6 0f f5 ad 22 ae 8e 5a b2 71 9e 83 ad f4 c3 6b a6 20 2d b4 3b 84 88 01 83 29 1d 58 93 d0 0f d4 d4 73 dc 47 34 8f 6e e2 25 c6 15 30 0e 41 c7 a1 ec 6b 3e 3b db 8d 2e 68 e7 9d 18 c6 c9 b7 cb 91 cb ee 1d 0b 46 4f 03 07 9a a1 24 57 37 37 4f 7b 14 72 44 b2 37 ee fd bd b2 2b 39 a4 8e 9a 32 72 25 82 7d b7 9e 4c a0 83 1f 3d 3a 81 df eb 57 7c 41 7b aa dd db db 79 b2 87 b7 82 70 d6
                                        Data Ascii: TmnqJ![f#kpp{U/`0c8a\8#KyOVnCI$qf<7 Y27}ksUO+p YX{"Zqk -;)XsG4n%0Ak>;.hFO$W77O{rD7+92r%}L=:W|A{yp
                                        2024-12-17 12:14:15 UTC8192INData Raw: bd 6b 4e b3 6e dd 0e 6a f8 6b 46 fd 4d d6 b7 0f 20 61 90 08 1d ce 7f 2e d5 62 00 b1 cc 66 53 90 a4 6e 27 07 8a a9 67 72 f2 2e c0 9e 60 e0 96 3d bb 7a f3 c5 5b b6 f2 dd 48 91 0e d3 c8 3d b8 fe 78 ae c8 da c7 98 ee 99 35 c4 6b 3d e5 b5 ba 46 cf e7 ca 00 51 e9 9e c3 f1 ab 1e 25 48 63 d4 bc 84 4f 28 bc 60 3a 8c ed 04 74 c8 f5 c0 ed 59 a6 7b 88 7c 4b 08 b7 7c b0 50 c9 dc 0e 3b 7e 15 20 9c cd a8 49 2c ae 58 ee c6 e3 cb 70 6b c7 c5 4b df 67 d5 60 29 fe ee 2f c8 ab 2a 2a 39 03 71 42 39 03 a6 47 4e 3b 53 a1 38 b8 24 93 b4 e3 78 eb 81 fd 40 ad 32 b6 6f 08 92 57 90 37 20 30 e4 fe 40 1a a1 7b 0c 0a c2 6f 37 69 0d b7 1d f9 1d 6b 28 1d 35 22 6a 2c 56 fb 66 7b 64 62 db c2 b4 2c 41 39 3c 71 ed 9f d2 b6 ae ec 2d 6e 6d 62 49 e3 65 da db 55 7e ee d3 eb 8f 73 59 7e 0b 31 4f
                                        Data Ascii: kNnjkFM a.bfSn'gr.`=z[H=x5k=FQ%HcO(`:tY{|K|P;~ I,XpkKg`)/**9qB9GN;S8$x@2oW7 0@{o7ik(5"j,Vf{db,A9<q-nmbIeU~sY~1O
                                        2024-12-17 12:14:15 UTC8192INData Raw: 9b f4 97 cc 44 09 85 8c 85 8d 7d 49 3c e7 e9 8a ec 56 38 67 b9 33 db 4b 1e d3 19 62 83 00 96 e0 8c 28 e8 31 59 1a b6 8d 71 33 c7 27 cd 1a bb 79 8c d8 1c 29 e4 e0 0e 6b 48 c8 c6 45 40 24 48 c2 31 50 aa a3 19 ee 71 c7 eb 51 5b 6c 92 e4 39 51 b8 12 1b d5 8f f8 d5 ad 69 1a 2b 88 fc b0 1a 09 a3 1b 4f 18 c8 39 eb d3 3c e2 b3 4d f2 59 de 2c bd 14 31 2d ef 9e a2 aa e0 96 a5 8d 75 95 e4 8c 11 f3 29 2a 6a 8c 16 2f 25 ea c8 48 c2 64 90 49 e4 f4 e2 ad 42 3e d7 31 74 0a db c8 61 c8 c0 ed 53 ca 9b 19 63 8e 26 38 3f bc 62 0a 8c 0e 48 e7 b9 ae 67 b9 db 09 24 8b 7a 74 10 89 04 53 f2 b2 2e 41 1e de fd 85 65 de 29 01 86 70 73 8f c3 3c 54 cf 74 ea ea e8 e1 b0 c4 6d ff 00 64 f6 a9 35 08 a0 68 d6 74 7d e0 b0 1b 47 7e fd 7b 52 e5 b1 7c f7 25 30 3d ce 9f 1c e0 06 30 b6 de 3e f0
                                        Data Ascii: D}I<V8g3Kb(1Yq3'y)kHE@$H1PqQ[l9Qi+O9<MY,1-u)*j/%HdIB>1taSc&8?bHg$ztS.Ae)ps<Ttmd5ht}G~{R|%0=0>
                                        2024-12-17 12:14:15 UTC8192INData Raw: 95 6e 9e c9 59 f8 05 91 83 6d 0a c3 1c 02 a3 39 3e 86 a1 bb b9 23 c3 e8 b7 82 27 99 79 e2 3c a8 c1 e0 29 39 24 81 58 7a 5b d8 dd 59 a6 ae 13 cb 97 63 42 e8 83 8c 86 6c 64 76 e1 be 86 b2 94 79 ad 73 a2 9d 4e 44 5e 84 d9 89 a7 9a 3c 5d 19 0f cb 19 93 05 5c 1c ee fa 13 da ba bb 1f 22 fa d6 0d 46 06 91 19 d4 a9 0e a1 72 e3 19 53 9e 4e 09 cf 07 a1 15 e7 16 16 8a 97 8d 6d 01 92 e2 59 1b f7 51 a8 00 0e e7 27 a0 03 d4 d7 5d a2 59 1b 1d 0e 5b 5b 9b 8f 3e 26 90 31 85 18 b2 c4 c4 10 70 7a 90 40 1c 8e 41 5a 52 8d 86 aa 73 5f 43 7a 4b 81 11 da f6 ff 00 28 cf ce 84 63 18 ef dc 57 0d a9 df c7 73 7d 2f 93 f2 3a 9f dd c8 64 0c 5b 3d 98 77 19 e3 1d ab 76 0d 46 44 d2 26 86 fa 58 d7 60 2a 93 0c ee 94 12 40 07 1f c5 d8 d6 09 d2 ed a4 40 81 cf 9d 92 ac 7c b1 b4 9c e0 f4 e7 3c
                                        Data Ascii: nYm9>#'y<)9$Xz[YcBldvysND^<]\"FrSNmYQ']Y[[>&1pz@AZRs_CzK(cWs}/:d[=wvFD&X`*@@|<
                                        2024-12-17 12:14:15 UTC8192INData Raw: db d7 d3 f0 a3 56 99 6f 75 c4 82 42 55 22 04 12 c3 04 01 d3 9f 7e b5 4e 3b d7 8a cc c8 a0 00 d2 00 01 1d b3 8e 73 c8 15 0f 85 a0 bb d6 bc 67 b2 16 66 8d 58 35 c3 73 85 19 e9 9f c3 f2 ac 5e ed b3 68 ec 91 b9 24 89 65 a5 c9 e6 c5 05 cd c5 d9 10 db 92 72 db 14 72 c0 fa 93 f9 d7 2f a8 3a 8b e5 81 f0 84 95 53 c7 0a 7f ae 3d 2b 4b e2 45 b4 56 de 27 96 da 32 df b9 8d 4a 02 79 e4 67 a8 c7 15 cc 6f 74 d4 21 64 38 21 c3 7c dc f4 f6 f7 35 8b 5d 4e a8 ca ca c7 a3 78 4a ec ea d7 13 cb 25 a8 4b 5b 42 23 dc b9 0c 70 09 c9 1d b3 c9 e2 b4 6e 62 79 f4 a2 f0 0c 92 09 00 93 82 73 c6 38 fc 2a 87 82 ec ae ed 3c 3f 73 09 31 41 75 7b 99 95 a4 6d db 47 18 04 0e f8 27 8e bf 4a 70 6d 5e 1b c5 8e 59 25 65 67 11 79 84 8d a4 13 93 f2 f6 ff 00 0a 22 67 3d cd f5 b8 1a 46 83 1d d4 d3 cb
                                        Data Ascii: VouBU"~N;sgfX5s^h$err/:S=+KEV'2Jygot!d8!|5]NxJ%K[B#pnbys8*<?s1Au{mG'Jpm^Y%egy"g=F


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        4192.168.2.2449773150.171.27.10443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:14 UTC375OUTGET /th?id=OADD2.10239359955652_1UH15L5Z2LXM3P8PA&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90 HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: tse1.mm.bing.net
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:14 UTC854INHTTP/1.1 200 OK
                                        Cache-Control: public, max-age=2592000
                                        Content-Length: 591970
                                        Content-Type: image/jpeg
                                        X-Cache: TCP_HIT
                                        Access-Control-Allow-Origin: *
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                        Timing-Allow-Origin: *
                                        Report-To: {"group":"network-errors","max_age":604800,"endpoints":[{"url":"https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE"}]}
                                        NEL: {"report_to":"network-errors","max_age":604800,"success_fraction":0.001,"failure_fraction":1.0}
                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                        X-MSEdge-Ref: Ref A: 1A496F6D2CE34BE1B6076F7C82CB5558 Ref B: EWR30EDGE1610 Ref C: 2024-12-17T12:14:14Z
                                        Date: Tue, 17 Dec 2024 12:14:14 GMT
                                        Connection: close
                                        2024-12-17 12:14:14 UTC15530INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff e1 18 6c 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 07 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 62 01 1b 00 05 00 00 00 01 00 00 00 6a 01 28 00 03 00 00 00 01 00 02 00 00 01 31 00 02 00 00 00 1f 00 00 00 72 01 32 00 02 00 00 00 14 00 00 00 92 87 69 00 04 00 00 00 01 00 00 00 a6 00 00 00 d2 00 60 00 00 00 01 00 00 00 60 00 00 00 01 00 00 41 64 6f 62 65 20 50 68 6f 74 6f 73 68 6f 70 20 32 34 2e 34 20 28 57 69 6e 64 6f 77 73 29 00 00 32 30 32 33 3a 30 35 3a 31 33 20 31 38 3a 33 37 3a 31 31 00 00 03 a0 01 00 03 00 00 00 01 ff ff 00 00 a0 02 00 04 00 00 00 01 00 00 07 80 a0 03 00 04 00 00 00 01 00 00 04 38 00 00 00 00 00 00 00 06 01 03 00 03 00 00 00 01 00 06 00 00 01
                                        Data Ascii: JFIF``lExifMM*bj(1r2i``Adobe Photoshop 24.4 (Windows)2023:05:13 18:37:118
                                        2024-12-17 12:14:14 UTC16384INData Raw: 51 4d 67 6d 70 ff 00 e9 96 db 52 3f f5 6d bb 1b fd 33 5e ac 60 31 5c 69 f6 1a 66 b3 f6 55 8b 73 3d bf 91 e6 79 ca 17 18 19 fb b8 35 f1 e4 7f 1e 25 f1 5a f8 6c df c2 be 16 d6 3c 2b 79 12 dc 1d 8b 24 0f bf e4 92 4d 87 9c 77 28 7f 03 5f 4f d8 eb b7 3e 20 bc d1 e3 fe ca 37 b6 91 ee 97 fb 7a 2d d1 5a 3b 6d 2a 36 a6 77 7c df f7 cf bd 7a f8 1c 65 09 b9 a8 6f a6 9f 24 bf ae 87 35 58 ca c9 f4 ff 00 82 74 1a ca 34 1a 7c 5a cb dd a4 57 16 cd f3 cb 6f 1b 32 cc a7 e5 da c9 fc 5f d2 b9 5f 8a 50 5d eb 1e 17 93 55 b9 b0 99 de ce e1 61 b5 d3 1e 1d cf 36 e9 10 37 cc bc e5 ba 7c bd 05 74 3e 2c b7 d4 e5 d1 15 05 f4 16 16 50 b2 49 2c b6 90 ee 64 8d 3e 66 f9 5b f8 7f dd ed 59 7f 13 e4 4d 5b c4 9e 14 d0 9b 51 fb 3e 9d aa 5d f9 b3 6c 91 57 cf f2 57 cd 58 f3 90 ff 00 37 fb 35 e8
                                        Data Ascii: QMgmpR?m3^`1\ifUs=y5%Zl<+y$Mw(_O> 7z-Z;m*6w|zeo$5Xt4|ZWo2__P]Ua67|t>,PI,d>f[YM[Q>]lWWX75
                                        2024-12-17 12:14:14 UTC16384INData Raw: 1a 66 a5 a8 dc 69 71 4d e6 c3 69 34 fe 6c 0f 1a af ce 8c bf c2 d8 3c 57 b8 7e d3 da 64 ba 8f 8f 3c 13 79 a0 e9 fa 75 b4 3a 86 a3 1d a4 37 51 40 aa ad 20 90 3e 1f 8d 8e 57 66 ce 98 f5 ae eb 53 d3 bc 05 f1 5b 4d d6 fc 2f af e9 b0 da ea da 4b 4f 15 a6 a0 9a 73 40 ce a8 a3 73 a8 1f 7b 6b 7c af 1f f4 35 c0 f0 52 9d 59 3a 6d 45 a7 a6 eb ee 65 fb 58 fb 35 cc ae 73 7e 1f fd a5 74 7b ff 00 0b c5 6d a2 78 79 d7 54 b8 f9 53 4b b9 ba 55 df bf fb bb bd 47 f7 4e 3d ab a3 d7 fc 4b a4 78 df 5c b1 89 fc 37 7d e4 f8 42 d3 fb 4d 52 6b a4 85 ad ae 36 85 8d f9 3f bc da bb ff 00 1a f9 17 e3 07 c3 cd 6b e1 c7 8c 2e 2c 35 0b e8 44 d6 0f 1f 95 2a c1 26 d7 84 af ee e4 8a 4e 9f 55 3c 83 52 7c 35 f8 f5 a6 6a 9e 3c d3 6d 7e 2a e9 a8 eb 04 4d a5 25 f2 7f a3 23 ae ef 93 ed 05 54 ef c3
                                        Data Ascii: fiqMi4l<W~d<yu:7Q@ >WfS[M/KOs@s{k|5RY:mEeX5s~t{mxyTSKUGN=Kx\7}BMRk6?k.,5D*&NU<R|5j<m~*M%#T
                                        2024-12-17 12:14:15 UTC16384INData Raw: da a6 e9 fc 9f e2 9b 0b b7 0b 8f bb 9a e1 24 9d af 3c 3e 9a c4 da 4d d5 ac cb 32 c6 fb f7 34 1b 57 b9 66 e7 75 75 fa 4e a3 24 17 5a 84 70 c1 03 49 14 cb 73 a7 24 db 9b fe 5a 63 62 c6 dc ff 00 7b 35 7b cb 8b fb 62 66 d3 7c bb d9 a2 7b 49 13 f8 55 24 dd bf 88 9b 28 cb bb ad 79 f5 2a 37 25 ae 8f fa 67 4f 2f bb 7e a7 49 f0 7f 42 d5 7c 61 e0 eb 4b ab 1f 1b df 58 69 6b 71 f6 19 b7 be e8 3e d0 7e ed bc 96 f9 2c ea 55 9f 04 0e b5 ea 9e 07 f8 6f a9 58 f8 c2 d2 1d 23 c7 52 7d b1 ac 83 5b b5 f7 99 e7 fd 96 1f dd 32 3a f1 fb a6 e8 bd 18 0a d2 b3 b8 b9 fe d2 87 c5 96 7e 04 4b cd 3f c5 16 31 b5 dd f4 33 c3 14 b6 d7 10 7e f3 6f 96 ea bf dc 6d bd fd 0f 35 db ea de 20 b4 bc fe cf f1 65 b5 ad ae 9d 1c 17 11 7f a6 6b 36 2f 04 ad 6f 23 7e f1 90 b0 f9 43 fc 83 e9 cd 7d 25 3c
                                        Data Ascii: $<>M24WfuuN$ZpIs$Zcb{5{bf|{IU$(y*7%gO/~IB|aKXikq>~,UoX#R}[2:~K?13~om5 ek6/o#~C}%<
                                        2024-12-17 12:14:15 UTC16384INData Raw: 76 6d a7 47 71 6b 6b 3d af d9 65 d4 63 96 19 bc f5 97 fd 1c e0 b8 3f dc 6d dd bd 6b 37 c1 bf 0e e0 b7 d0 53 5c f1 27 8a 2d 75 2d 6a 29 96 54 8a de 06 69 7c c3 95 73 e6 f4 da 3d 2b 8e d7 ee 7c 43 e0 4d 4a d3 c3 f6 bb f5 6d 3f 4b b4 fb 4d da 3f cb 14 cb bb cd 7d ac bc e4 7c a3 03 e9 4b 1d 98 55 c5 4d 42 ab 4e c9 35 b2 f5 b7 dd b3 23 0f 4e 8d 3b fb 3d fa 9b be 19 d2 af ac af ad e6 bc d3 63 b8 b8 d5 2e 2e 6c ee 21 df f3 43 f7 db ef 75 fb be 86 b4 b4 ff 00 0b b3 f8 71 35 88 75 28 ef 37 5f 47 05 c7 d9 a4 f9 61 63 c2 1d df dd f5 a8 fe 1b dc d8 fc 4c f0 ad f7 88 2d 6c 6e a0 6b 7b 89 ae 52 1b ef 95 a1 fd d8 fe 1f f7 ba 11 5d 0f 85 fc 43 07 c3 8f 0c ae 9b e3 3f 0b ea 2d a3 eb 32 c6 a9 77 63 f3 7e f0 b7 de 95 7f 83 0d d0 fa d7 93 57 30 a9 09 3a 71 5f bd 8b d6 3a 6a
                                        Data Ascii: vmGqkk=ec?mk7S\'-u-j)Ti|s=+|CMJm?KM?}|KUMBN5#N;=c..l!Cuq5u(7_GacL-lnk{R]C?-2wc~W0:q_:j
                                        2024-12-17 12:14:15 UTC16384INData Raw: 17 fa 3e ef dd b0 df fc 0a 8d b7 77 fb 14 ed 72 f2 2b 8f 84 be 19 87 58 4b 1f ec 8b c9 63 57 6b b8 7f 74 90 06 c7 cd 23 70 b9 4f c6 bc 8b c1 29 a9 4b e0 eb 8f 1d 78 a3 c5 12 6b 6d 75 6f 1c 57 10 a6 e5 b6 d3 e1 4f f9 60 8b ed bb 2d fe f5 69 eb 1a ba 6a 7a 7c 5a 36 a6 f3 cf 65 67 2f 95 69 65 f7 63 85 8f 39 d9 d1 bd b3 45 7e 2b a3 56 ad 5a 53 a6 ee a3 c9 7f b2 f6 76 77 d7 6d 3f 1e a6 f4 e2 9c 62 93 d2 f7 37 3c 5d a7 7c 1c 6d 51 ad 7c 0f 3c 10 b5 9c b0 db 5c 25 8f 98 b0 43 0e e3 e6 26 ef ba c4 8e 45 72 1a 6d d7 82 ad fe 1d 5f 78 6e c6 04 bf bc d5 ae 3c cb 44 fb db e6 8e 67 28 d0 7f 71 76 75 42 69 6e 9e 2b 7d 62 d2 d7 4f 7f f4 59 fe 66 7f b2 f9 4b c2 fd d6 5f d2 bc fb 48 bd d1 ad 2f a1 fb 3e cb 0b 8b 54 93 fb 3a 18 64 f2 b6 62 4f e0 ff 00 3c d7 9e f3 7a b8 a9
                                        Data Ascii: >wr+XKcWkt#pO)KxkmuoWO`-ijz|Z6eg/iec9E~+VZSvwm?b7<]|mQ|<\%C&Erm_xn<Dg(qvuBin+}bOYfK_H/>T:dbO<z
                                        2024-12-17 12:14:15 UTC16384INData Raw: 19 27 bd 8e d3 e1 f6 85 67 e2 bf 1a 4b 0f 99 04 ba 5d 8d f2 ac 57 69 f2 c1 32 8f f9 69 fe d6 6b ea e8 fc 79 e1 0f 0e 68 ef 6b 67 3f da a4 b3 85 7f 73 12 7c bf f7 d5 79 5d c6 97 a3 78 5b e2 32 f8 7e de 7f b1 e9 ad 62 bf 64 b7 96 35 58 b7 05 fb db bf be 7d 6a bf f6 c6 fb a7 b5 d1 ef 92 05 f9 a2 9a e2 db 6b 2f b8 ff 00 6a bc 98 71 37 f6 66 25 e1 a9 53 bd 34 97 34 ba ff 00 96 e7 1d 7a 95 1d 4e 77 f0 87 8d 3e 2c f8 8f c4 52 4d 6b ac 49 05 86 9b 2f cb 6e 90 a6 e5 da 3f bd bb 8c d4 7f 0e 7c 6b a9 de cf fd 83 6f a9 58 dd 6c f3 3e ce 89 f2 cb 36 17 e5 4d cf c2 93 5e 5b f1 22 d6 ef 50 f1 55 a7 87 7c 3d af 25 ba de 4d b9 d1 5f 74 5e 67 7f 99 be 99 1e 95 cb d9 24 7a 04 fa b6 b5 67 3d d4 5a 85 ac d0 ca ff 00 68 f9 7f 78 8d f2 b0 51 d8 fe b5 ac b1 54 f1 b2 8d 5a 8d bb
                                        Data Ascii: 'gK]Wi2ikyhkg?s|y]x[2~bd5X}jk/jq7f%S44zNw>,RMkI/n?|koXl>6M^["PU|=%M_t^g$zg=ZhxQTZ
                                        2024-12-17 12:14:15 UTC16067INData Raw: f7 da 5e c9 3c 4f df e5 66 e5 b3 de a9 eb 97 96 da d6 b9 a4 dd 59 e9 b1 de 4f 14 5f f1 ef 70 ff 00 bb fc 71 fe d5 72 c2 a5 49 56 5c d1 bd 3d 6d aa 7d fa bf eb 41 f2 5b dd be ba 1d df 82 34 bb 6f 10 78 16 de fa fe c7 c3 2d 66 c5 16 1b 2b 8b 56 8a f9 d8 b6 31 f2 fc 8d 91 d0 b5 70 f7 56 da 7d 9f 8c 5b c2 93 7f 6a c5 6f 04 db 75 18 bc 85 59 d1 4b 72 98 3c 7e 06 ba 2b 8b cb 9b 89 f5 1f 0f df 41 0b 5c 5a c5 34 57 16 89 f2 c4 98 c3 2a 83 fe cb 74 35 db 7c 2d 8d bf e1 2d 87 4d f1 35 dd ad d4 76 7a 73 35 be a1 70 8a d7 90 a8 6e 23 dd d6 48 d7 fd ae 47 6a f1 15 49 e1 5d 49 4b ad da 8f 6e cd 77 b7 de fc f6 36 8c 34 51 b6 bd ff 00 43 ce e1 fe c3 d3 bc 46 8d a7 df 3a e9 eb 34 cb 2a 79 1e 42 ee db bb 0b fe ef 6a 9b c7 1e 2e bb f1 06 a3 71 0b 4e 8f a6 e8 d6 9f 6c 69 91
                                        Data Ascii: ^<OfYO_pqrIV\=m}A[4ox-f+V1pV}[jouYKr<~+A\Z4W*t5|--M5vzs5pn#HGjI]IKnw64QCF:4*yBj.qNli
                                        2024-12-17 12:14:15 UTC16384INData Raw: 47 44 fe e7 f5 aa bf da 73 f8 8f c0 f7 7f 67 f9 6e 22 8b ee 3f de e7 d2 a6 87 55 9f fb 1e c6 ea 39 3f 7d 6b 36 d7 ff 00 ae 65 7f a5 72 52 a7 cb 56 cd d9 de df 91 cd 88 97 bb a6 c7 9d fc 6b d4 e1 b8 f1 57 87 35 fb 84 dd f2 2c 13 4a 9f 79 59 7e 5c fd 2b 5b 4d bc b6 8f 52 49 a1 b4 f9 60 dd bf 67 bb 63 9a f3 5f 89 97 eb 7b a7 f9 76 f2 7e ee 2b 89 19 13 fe 05 9a f4 8f 05 dc c1 35 ad dc 97 4f fb e4 d3 20 64 74 f7 6a fa 3a 94 25 4f 09 0d 35 57 5f 8e 9f 99 e7 c2 a2 9a 71 f9 9d 26 a5 24 ba 7e 9b 71 75 36 ff 00 b3 ad a3 37 c9 fd de b5 89 f0 9f 5f 5f 10 58 b4 97 1f f1 f9 67 e6 6c 7f bb be 33 f7 53 3e a3 b5 6f f8 9b 53 59 7e 14 6e ba 8d 16 6b f4 fb 32 7f bb da b8 1f 87 3a 16 a3 2e 9b 35 8d 8b c7 15 d6 f9 2e dd dd f6 aa 47 0d 79 98 4a 30 96 1e a7 3e f7 b2 f4 ea 2a 71
                                        Data Ascii: GDsgn"?U9?}k6erRVkW5,JyY~\+[MRI`gc_{v~+5O dtj:%O5W_q&$~qu67__Xgl3S>oSY~nk2:.5.GyJ0>*q
                                        2024-12-17 12:14:15 UTC16384INData Raw: d6 cf 2e f6 6f 27 7a 90 a1 47 f0 ae ea ee 3c 0d 68 da a5 c6 99 1c de 64 53 5a a4 36 72 ef f6 85 6b 8d f1 96 8b 1d 9f 8a ae db cc 8e 5b 76 b8 87 ec 3f de dc 1b e6 cd 7a 5f 83 6d a7 5d 7e e1 a1 f9 bf d3 a4 fb 9f c7 88 ca ff 00 e8 55 f5 f9 93 a5 cd 4e 71 d3 9a cf ef b7 e8 ff 00 01 62 29 c6 51 d3 73 d9 fe 00 f8 6e d9 3e 21 ff 00 6d 2c 1f 2d ad 8a b2 3f fb 5f 70 57 a0 6a 97 b2 6a 3a 95 db 2c 9f 2e fd bf 95 60 7c 2d 2d a6 f8 3a 6b a9 3e f3 22 aa 7e 0b 4b a7 df c4 9a 3c d2 37 de 97 73 57 d8 61 64 a8 e1 d4 bb 9c bc dc 91 f3 3c 97 e2 46 99 6d aa 78 83 c4 9a d4 93 c8 cd 6f 68 d0 79 3f 4e 98 af 9f 75 0b 1d 55 fc 41 12 d8 ff 00 ab 5b 78 bc ed ff 00 2f ef 37 7a 7f 17 15 ef 91 de 5e 45 e2 0d 41 96 4d b6 f2 c3 23 24 df df 63 cf 35 e7 bf 0a 52 db c4 7f 11 b7 34 7f b9 5b
                                        Data Ascii: .o'zG<hdSZ6rk[v?z_m]~UNqb)Qsn>!m,-?_pWjj:,.`|--:k>"~K<7sWad<Fmxohy?NuUA[x/7z^EAM#$c5R4[


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        5192.168.2.2449777150.171.27.10443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:19 UTC346OUTGET /th?id=OADD2.10239359955653_16Q8BS61PKT108CUW&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90 HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: tse1.mm.bing.net
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:20 UTC854INHTTP/1.1 200 OK
                                        Cache-Control: public, max-age=2592000
                                        Content-Length: 498769
                                        Content-Type: image/jpeg
                                        X-Cache: TCP_HIT
                                        Access-Control-Allow-Origin: *
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                        Timing-Allow-Origin: *
                                        Report-To: {"group":"network-errors","max_age":604800,"endpoints":[{"url":"https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE"}]}
                                        NEL: {"report_to":"network-errors","max_age":604800,"success_fraction":0.001,"failure_fraction":1.0}
                                        Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                        X-MSEdge-Ref: Ref A: AE5401A471954D0E9918964AE77DF7E5 Ref B: EWR30EDGE1010 Ref C: 2024-12-17T12:14:20Z
                                        Date: Tue, 17 Dec 2024 12:14:19 GMT
                                        Connection: close
                                        2024-12-17 12:14:20 UTC15530INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 48 00 48 00 00 ff e1 00 da 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 07 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 62 01 1b 00 05 00 00 00 01 00 00 00 6a 01 28 00 03 00 00 00 01 00 02 00 00 01 31 00 02 00 00 00 1f 00 00 00 72 01 32 00 02 00 00 00 14 00 00 00 92 87 69 00 04 00 00 00 01 00 00 00 a6 00 00 00 00 00 00 00 60 00 00 00 01 00 00 00 60 00 00 00 01 41 64 6f 62 65 20 50 68 6f 74 6f 73 68 6f 70 20 32 34 2e 34 20 28 57 69 6e 64 6f 77 73 29 00 00 32 30 32 33 3a 30 35 3a 31 33 20 31 38 3a 33 37 3a 33 38 00 00 03 a0 01 00 03 00 00 00 01 ff ff 00 00 a0 02 00 03 00 00 00 01 04 38 00 00 a0 03 00 03 00 00 00 01 07 80 00 00 00 00 00 00 00 00 ff db 00 43 00 04 02 03 03 03 02 04 03 03 03
                                        Data Ascii: JFIFHHExifMM*bj(1r2i``Adobe Photoshop 24.4 (Windows)2023:05:13 18:37:388C
                                        2024-12-17 12:14:20 UTC16384INData Raw: 3a 2f fc 23 d6 b6 f1 e8 b1 ce f6 36 e9 f3 da 6f dc df 77 aa 6e ef f8 d7 c7 9e 13 69 2c f6 5e 79 1f 68 6f 3b 72 7f bc 1a be c5 d1 ee 7c 4b a9 78 72 1b 8f b3 d8 db b4 b0 ae c4 47 65 6e 7f de 1f 2d 3c 14 92 72 d3 51 62 23 aa 2f 68 77 2b 7f a5 25 e2 dc 46 cb 71 f3 26 cf e5 fe f0 ef 56 fc bd d1 fc d5 cb 7c 31 f0 f5 9f 86 74 79 ad d6 c2 4b 5d 4a 59 a4 96 ef 66 e9 55 d8 b1 23 db a5 74 1a 5e a8 d7 4e 90 c9 a6 df 5b cd f3 6f df 06 d5 e3 fd aa f4 a1 3b a5 7d ce 63 c2 7f 6c 8d 2f fb 27 5c d0 7c 55 a6 c9 f6 5b a6 76 89 dd 3e 56 f3 13 e7 47 fc 2b c6 a4 8f 5a bc d5 66 d5 af 35 6b a4 bc b8 4f b4 bd c3 c9 b5 a6 fa 9f e9 5f 46 7e da d7 30 59 fc 19 fb 54 d6 11 b5 c2 df 42 b6 93 3e dd d0 b1 6e a0 7f bb 5f 35 cd a9 cf 3e 8f fd a9 7d 7f 1b 6d 9b ca 78 53 fd 6a 7f b5 8a f0 f3
                                        Data Ascii: :/#6owni,^yho;r|KxrGen-<rQb#/hw+%Fq&V|1tyK]JYfU#t^N[o;}cl/'\|U[v>VG+Zf5kO_F~0YTB>n_5>}mxSj
                                        2024-12-17 12:14:20 UTC16384INData Raw: 75 9b 44 fb 57 d9 65 8f fd 5c 49 68 9b 7e bb 54 f1 f8 d7 7c 52 c1 c2 13 c4 54 4d 5a d7 6a cd c8 99 49 4a fc ab 43 d2 ff 00 67 9f 0c 6a 7a f6 9b a8 2e 97 ae ea 3a 5d 8a ba ab bc 4e bf be f9 7f 8f 1f ca bd 77 58 4f 0b f8 5f c3 2e ba b5 86 9b e4 c4 8a be 4c 30 2e e9 9b f1 af 1e f8 03 e2 0d 4b c2 a9 71 a0 ac f1 d9 da cb 32 b4 29 71 02 f9 ae c7 fb a6 bb 0f 14 68 9f f0 95 ea 5f d9 fa b6 8b ac 5f dc 32 6e 49 9e 36 8a 2d be d2 74 c5 6f 1c ee 2e bc 70 78 7a 0e 75 2d ac ad ee 45 3e b7 eb e8 8e 3a 98 5d ea 4e 69 2e dd 59 c4 6b 91 78 f7 e3 0d bb db e9 fa 6c 96 fe 17 6b b5 58 7e d0 fb 60 45 1f 2e 40 fb d2 62 b9 df 8e 1f 03 b4 8b 2d 57 c2 de 05 f0 af da ee 35 cd 52 56 92 ee e3 e5 58 92 14 fb ef b4 7d da f7 8d 1f c4 11 e8 7a 6d 8d 9e a5 3d ae 9a b6 08 d6 df 61 4f f5 bc
                                        Data Ascii: uDWe\Ih~T|RTMZjIJCgjz.:]NwXO_.L0.Kq2)qh__2nI6-to.pxzu-E>:]Ni.YkxlkX~`E.@b-W5RVX}zm=aO
                                        2024-12-17 12:14:20 UTC16384INData Raw: ba 69 cd 3b fc be ed c5 52 8d a7 6b fe 67 73 e0 7f 07 78 56 ce eb fb 73 4b b4 f9 9b 72 a2 3f cc a9 f3 7f 06 6b 75 53 fe 2a 69 a4 fd da aa 5a 2a bf fd f5 5e 4f 63 aa f8 f6 df c3 f6 f6 ba 3e bb 25 fb 7f cb ba 26 81 22 ef 53 ff 00 4d 1b 8a cd d7 bc 4b f1 2e e3 c4 09 a6 e9 fa 4d f6 a5 34 49 1a eb 36 89 63 e5 6f 8f 6f 03 cd 3c 26 7d a9 d3 af 4d 24 94 6d 7e dd fe f2 67 4d c9 fc 5b 1e ad e0 1d 4b 47 f1 1d f6 a7 af 69 bf bd 91 6e 1a c7 ce ff 00 66 3f ee ff 00 b2 6b 4b fb 3b 4f 83 55 76 5b 08 fc e9 fe 69 a6 d9 f7 ff 00 de af 25 f0 2f c4 bb cf 0e 6a ba b4 3e 30 f0 9e a5 a5 c9 74 f1 b7 d9 ed 20 5f 22 16 0b b7 19 cf 75 db 5b de 2a f1 e7 89 b5 28 62 9b c0 7e 1e 79 66 8b fe 3e 1f 54 9e 35 89 14 fd d7 c2 b6 e6 fe 55 b4 6b 43 97 5d 59 9f 23 5d 0f 29 f8 d1 05 8c 1f 19 af
                                        Data Ascii: i;RkgsxVsKr?kuS*iZ*^Oc>%&"SMK.M4I6coo<&}M$m~gM[KGinf?kK;OUv[i%/j>0t _"u[*(b~yf>T5UkC]Y#])
                                        2024-12-17 12:14:20 UTC16384INData Raw: 23 d9 6b 23 5e bd f0 fd ff 00 83 ef bc 31 27 85 ed 6d 7c 4f 61 a9 ac f6 37 b6 f1 ee df 6a fd 63 cf de fe f0 ae 83 f6 9a d4 7c 27 af f8 ab c3 7e 38 f0 ef 92 ba 87 9d b7 54 45 8d 97 7a 8f bb bb fd a1 58 da 5d ce 91 aa 7c 7a d2 6c e6 bf 82 c2 fa e1 e1 96 df 7a 6d 54 60 db 93 9e 8c b5 e4 56 a9 25 8b 74 e9 59 f3 7d d6 ff 00 33 ae 14 ef 45 39 2b 58 fa 16 6f 08 78 a3 49 d0 34 9d 5b c0 da cc 2d 77 65 69 1c 0f 6f 71 06 ef b4 c2 7b 37 fb 4b da bc fb c7 1a 66 a7 a6 fc 7a f0 b7 8f bc 55 a4 da b5 bd ba 35 9e a3 aa 5a 7e f6 07 62 b8 c3 a1 1f 26 0d 7d 15 25 ee 9b 6f 1f da 2e 2e 20 56 f9 77 ba 3d 79 7f c4 bb df 0e e8 be 3e d0 66 88 ea 5f 63 d4 2e e4 5d 46 d2 da 06 96 da e6 46 5d d1 97 43 fc 5e eb 5f 41 5a 8a 82 e6 4f 4d 3d 0f 3a 13 bb d5 15 7e 26 78 9f c3 af a5 ff 00 62
                                        Data Ascii: #k#^1'm|Oa7jc|'~8TEzX]|zlzmT`V%tY}3E9+XoxI4[-weioq{7KfzU5Z~b&}%o.. Vw=y>f_c.]FF]C^_AZOM=:~&xb
                                        2024-12-17 12:14:20 UTC16384INData Raw: de 1e d1 ee f5 0f 0d 5e ff 00 c2 59 a4 df b7 ef ac ae 2d 55 6e dd 7f bc 1c 70 f5 f3 ff 00 8a 3c 0d 3e 8d f6 8b 8d 2f c4 2f 6e b2 dc 6d b8 d3 ae d1 a2 96 d9 bf ba d5 f5 5f 82 3e 35 26 87 73 63 e1 7d 13 46 be f1 2e 99 15 be d5 8a df e6 be b6 db fc 3f dd 90 0f f8 0d 79 97 ed 3d e2 2d 37 c7 b7 5f 6e 4d 0e 4f 0d 6a d6 7e 64 77 29 71 1b 24 ee bf c1 e7 0c 0f c2 b8 b1 54 70 ae 9f 35 37 af 6d 7f 31 d3 75 39 f9 66 8f 34 f8 43 f1 53 c7 ff 00 0b b5 e8 63 58 37 d9 dc 3a ec b6 9b 6b 2b b7 fb 0d fc 39 af ae 3e 17 fc 63 d3 fc 67 71 a8 69 7a ad 8c da 5e af b2 36 b7 d9 07 ef 51 76 fd e3 ea 15 b9 f4 c5 7c 99 a7 fc 38 f1 55 ff 00 87 ed ee ae bc 3d e2 06 b3 5d b3 c3 7d 6f 6a d2 ae d1 fc 40 ff 00 76 b8 fd 7a 6d 73 43 92 2b cb 5b b9 22 6b 5b ef 2a 1b 88 5d b7 79 6f f7 79 ae 6c
                                        Data Ascii: ^Y-Unp<>//nm_>5&sc}F.?y=-7_nMOj~dw)q$Tp57m1u9f4CScX7:k+9>cgqiz^6Qv|8U=]}oj@vzmsC+["k[*]yoyl
                                        2024-12-17 12:14:20 UTC16384INData Raw: eb da 7f 84 61 d2 fe d5 6b ab 59 df 2c ac f6 ce be 57 98 8b 82 c8 b5 96 0e bc 29 42 a3 be e9 69 f3 36 c4 52 9d 57 1b 2d 11 db 7e d3 be 37 d0 4f 87 74 8b 1f b2 24 fa e2 db f9 e9 13 c2 bf e8 7b e3 db 9d df c2 de 95 e5 9f 0a 7c 6b ae f8 57 c2 ed ae 78 5b 49 9e e3 50 d7 26 6b 4b 8b 89 91 a5 5d c1 b8 93 db 15 6f e2 12 58 c1 a6 da 78 9a f3 cc 96 45 bb 87 ed d0 ef 5d d7 b1 ee dc 73 ee 6b dd fc 3b 37 8c f5 ef 07 7f c4 8f c2 16 3e 1a 59 37 7d 93 fb 47 ef 43 19 fb ac a8 9f 74 d6 be d2 78 ba ca a4 64 e3 6b 6c 9b 76 fd 3d 49 70 85 1a 7e cd ab df cf a9 f3 df c5 c3 7d a2 da 5c 5b ea 9a 95 8d d5 d5 c2 79 b7 6f 69 3f 9f 03 c8 ff 00 5f e2 fa 57 98 ea 57 16 31 6b 96 97 4b 6f 25 bd bd bc 2c d2 ef f9 95 e4 fe 1c 57 ad 7c 60 f8 5b e2 9d 24 34 fe 31 b8 b5 bd 86 e9 da 5f 3b 4e
                                        Data Ascii: akY,W)Bi6RW-~7Ot${|kWx[IP&kK]oXxE]sk;7>Y7}GCtxdklv=Ip~}\[yoi?_WW1kKo%,W|`[$41_;N
                                        2024-12-17 12:14:20 UTC16067INData Raw: 4a ad 5c 47 b9 2a 9b 6d a5 87 e8 71 cb 6f 6a da 7c d2 47 aa 6f 9b ca d3 b7 ff 00 1c 27 ee ef fa 74 ab 3a a6 a7 07 87 35 cf ec db 7b 08 16 4b 84 fd f5 c7 f7 3e 5f ba 2a 4f 18 41 a7 78 53 e1 ce b1 aa 35 8c 76 ea b6 fe 7f df 66 f3 a4 fe 15 5a e4 f4 fb dd 67 56 f0 fc 3a e5 9d dc 6d 63 79 6e b2 6f bb 83 cd 5d df d0 57 a5 43 88 b0 f5 70 f1 ab 6d 1e 8d f6 7d be 7e a5 ce 32 8e 89 5e e5 af 11 68 7e 29 bc f0 cd bf 8a b4 3b b9 ed f4 d9 6e 3c b9 ae 12 76 5d 92 2f 4e 41 cd 69 78 0f e3 7f 89 b4 3d 06 3d 32 da 7b 59 e4 bc dd 0c bb fe f6 ef bb e6 2f bd 5a d6 35 eb 6f f8 45 6d f4 1d 4b 52 8e df ed fb 7f d1 ed dd 55 52 4f ef 2a 57 97 69 3a 04 09 af f9 90 c7 f6 c6 b5 bb 91 53 7b ed 91 19 5b ef 1e d5 c7 84 cc 5c 65 ed 68 ce 71 4b af ad ef ae d6 d8 e7 ad 45 d4 f7 a4 8f 6b f8
                                        Data Ascii: J\G*mqoj|Go't:5{K>_*OAxS5vfZgV:mcyno]WCpm}~2^h~);n<v]/NAix==2{Y/Z5oEmKRURO*Wi:S{[\ehqKEk
                                        2024-12-17 12:14:20 UTC16384INData Raw: d6 de 57 f7 d8 56 67 c5 2d 52 da e1 34 fd 0f 4f 47 ba 8e df 50 5f dc ef da b7 33 05 cf cc 7f ba 95 c0 7c 5a f1 35 f7 86 74 9b 7b 1d 3f 5d 7b 7d 7b 52 b8 fd ec 4f f3 2d b4 67 8f 9f fb ac 7f 95 62 7c 21 d6 ac a1 d7 21 99 6f 9e f6 fa c1 da 0b eb 8b bd de 54 2c ff 00 5e de f5 df 82 ca 2b 4f fd b6 55 2d 15 a2 5a db 4d 2f e9 7f bc d9 6d c9 63 dd 3c 23 73 37 85 7c 45 a3 e9 77 50 47 71 7d e2 a9 be 4f 2b ef 5c c8 fd 53 d9 51 79 15 83 fb 45 69 d6 d6 7f 11 ad fc 33 6b 3e 9d 79 71 aa 4d f3 dd ef db 14 2a 9f 36 dd a3 3d 2b ce 3e 27 78 d3 4d f1 07 c4 2d 06 38 ef ff 00 b2 61 b2 76 54 74 dc df 66 f9 7e ff 00 af 3e dd 05 61 6a da cd ce 97 e3 8d 2e e2 e2 48 25 68 a6 65 b7 bb 5f de c5 36 7f 89 b7 75 35 ed 51 c1 38 d0 8d 3a 8b 9a 6f de bd fd 6c 92 fb 9e e2 54 53 bc 9c ac b6
                                        Data Ascii: WVg-R4OGP_3|Z5t{?]{}{RO-gb|!!oT,^+OU-ZM/mc<#s7|EwPGq}O+\SQyEi3k>yqM*6=+>'xM-8avTtf~>aj.H%he_6u5Q8:olTS
                                        2024-12-17 12:14:20 UTC16384INData Raw: 07 96 ce bf ed 56 18 89 d5 4e 9e 13 97 d5 df f2 f5 25 c9 73 3a 8b 63 9d f1 05 86 8d 75 3c 53 47 04 8c d2 ee f2 91 13 e5 4f 9a ab cd a3 cf 17 89 fc c9 a4 ff 00 45 95 17 ed 1b 13 f8 47 52 bf 4a d1 f0 8e a1 14 5a b4 4d 75 1c 72 d9 dd 6e 64 df ec b5 7b 43 d6 60 8e 77 b7 b8 79 25 9a 2f 9b e7 f9 b7 a9 e8 d5 b4 65 52 9b 4b 75 6e a5 af 7d 21 f3 4a ba a4 fa b2 e8 bb 16 18 13 f7 56 ff 00 c4 f0 8e 37 fe 3d 6b 4f c3 7e 11 d7 6e 34 0b bb 89 ad 27 8a d6 58 95 93 66 df 2b fd e3 5c ee bd 6d 63 14 8f f6 59 3c 8b 85 7d d1 3f f1 6d fe ef fb b5 d2 6a 9f 19 35 a9 3c 1d 16 87 6b a6 d8 fd a9 51 7e d7 73 0f cd fb b4 fb a3 1f ce bc dc 4f d7 25 08 47 09 14 d3 7a df a2 ee 6a 9b 8a f7 8d 2f 87 51 5f 68 7a 5d a5 9c 73 da b5 f3 6a ca df be 83 cd 8b 68 5e df ec d7 56 f6 5e 3a f3 35 6d
                                        Data Ascii: VN%s:cu<SGOEGRJZMurnd{C`wy%/eRKun}!JV7=kO~n4'Xf+\mcY<}?mj5<kQ~sO%Gzj/Q_hz]sjh^V^:5m


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        6192.168.2.2449844104.117.182.75443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:38 UTC436OUTOPTIONS /api/report?cat=bingth&ndcParam=QUZE HTTP/1.1
                                        Host: aefd.nelreports.net
                                        Connection: keep-alive
                                        Origin: https://th.bing.com
                                        Access-Control-Request-Method: POST
                                        Access-Control-Request-Headers: content-type
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36 Edg/100.0.1185.36
                                        Accept-Encoding: gzip, deflate, br
                                        Accept-Language: en-US,en;q=0.9
                                        2024-12-17 12:14:39 UTC444INHTTP/1.1 200 OK
                                        Content-Length: 0
                                        Server: Kestrel
                                        Date: Tue, 17 Dec 2024 12:14:39 GMT
                                        Alt-Svc: h3=":443"; ma=93600,h3-29=":443"; ma=93600,h3-Q050=":443"; ma=93600,quic=":443"; ma=93600; v="46,43"
                                        Connection: close
                                        PMUSER_FORMAT_QS:
                                        X-CDN-TraceId: 0.47b67568.1734437678.59e8376
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Credentials: false
                                        Access-Control-Allow-Methods: GET, OPTIONS, POST
                                        Access-Control-Allow-Origin: *


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        7192.168.2.244984913.107.246.63443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:14:51 UTC399OUTGET /creativeservice/2d863f0f-0fd5-72db-6971-f905df03ef53_3255140379518978990_128000000004796009_assets__image_1709055739600.jpg HTTP/1.1
                                        Accept: */*
                                        Accept-Encoding: gzip, deflate, br
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
                                        Host: res.public.onecdn.static.microsoft
                                        Connection: Keep-Alive
                                        2024-12-17 12:14:51 UTC1038INHTTP/1.1 200 OK
                                        Date: Tue, 17 Dec 2024 12:14:51 GMT
                                        Content-Type: text/plain
                                        Content-Length: 2495
                                        Connection: close
                                        Vary: Accept-Encoding
                                        Last-Modified: Thu, 12 Dec 2024 01:09:08 GMT
                                        x-ms-request-id: 2aad639d-001e-0026-237d-502018000000
                                        Access-Control-Expose-Headers: date,X-Cdn-Provider,X-Ms-Request-Id
                                        Access-Control-Allow-Origin: *
                                        x-azure-ref: 20241217T121451Z-156796c549bm4sgmhC1EWRutb40000000btg0000000048f8
                                        Cache-Control: public, max-age=31536000
                                        x-fd-int-roxy-purgeid: 0
                                        X-Cache: TCP_MISS
                                        Strict-Transport-Security: max-age=31536000; includeSubDomains
                                        Timing-Allow-Origin: *
                                        X-CDN-Provider: AFDX
                                        Access-Control-Allow-Headers: *
                                        Access-Control-Allow-Methods: GET,HEAD,OPTIONS
                                        NEL: {"report_to":"NelM365CDNUpload1","max_age":604800,"include_subdomains":true,"failure_fraction":1.0,"success_fraction":0.01}
                                        Report-To: {"group":"NelM365CDNUpload1","max_age":604800,"endpoints":[{"url":"https://M365CDN.nel.measure.office.net/api/report?FrontEnd=AFDXWorldwide"}],"include_subdomains":true}
                                        Accept-Ranges: bytes
                                        2024-12-17 12:14:51 UTC2495INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 02 01 00 48 00 48 00 00 ff db 00 43 00 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff db 00 43 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ff c0 00 11 08 00 40 00 40 03 01 11 00 02 11 01 03 11 01 ff c4 00 1f 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b ff c4 00 b5 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51 61 07 22 71 14 32 81 91 a1 08
                                        Data Ascii: JFIFHHCC@@}!1AQa"q2


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        8192.168.2.244985734.117.42.1604438932C:\Program Files\Google\Chrome\Application\chrome.exe
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:15:01 UTC858OUTGET /api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ== HTTP/1.1
                                        Host: nhlnkc.com
                                        Connection: keep-alive
                                        sec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"
                                        sec-ch-ua-mobile: ?0
                                        sec-ch-ua-platform: "Windows"
                                        Upgrade-Insecure-Requests: 1
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
                                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                        Sec-Fetch-Site: none
                                        Sec-Fetch-Mode: navigate
                                        Sec-Fetch-User: ?1
                                        Sec-Fetch-Dest: document
                                        Accept-Encoding: gzip, deflate, br, zstd
                                        Accept-Language: en-US,en;q=0.9
                                        2024-12-17 12:15:02 UTC369INHTTP/1.1 400 Bad Request
                                        X-Robots-Tag: noindex
                                        Content-Type: text/plain;charset=UTF-8
                                        Content-Length: 8
                                        Date: Tue, 17 Dec 2024 12:15:01 GMT
                                        Via: 1.1 google
                                        Strict-Transport-Security: max-age=3104000
                                        Cache-Control: no-cache, no-store, must-revalidate
                                        X-Content-Type-Options: nosniff
                                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                        Connection: close
                                        2024-12-17 12:15:02 UTC8INData Raw: 42 6c 6f 63 6b 65 64 21
                                        Data Ascii: Blocked!


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        9192.168.2.244985634.117.42.1604438932C:\Program Files\Google\Chrome\Application\chrome.exe
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:15:02 UTC781OUTGET /favicon.ico HTTP/1.1
                                        Host: nhlnkc.com
                                        Connection: keep-alive
                                        sec-ch-ua-platform: "Windows"
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
                                        sec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"
                                        sec-ch-ua-mobile: ?0
                                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                        Sec-Fetch-Site: same-origin
                                        Sec-Fetch-Mode: no-cors
                                        Sec-Fetch-Dest: image
                                        Referer: https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ==
                                        Accept-Encoding: gzip, deflate, br, zstd
                                        Accept-Language: en-US,en;q=0.9
                                        2024-12-17 12:15:02 UTC216INHTTP/1.1 404 Not Found
                                        Server: nginx
                                        Date: Tue, 17 Dec 2024 12:15:02 GMT
                                        Content-Type: text/plain
                                        Content-Length: 9
                                        Via: 1.1 google
                                        Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                        Connection: close
                                        2024-12-17 12:15:02 UTC9INData Raw: 4e 6f 74 20 66 6f 75 6e 64
                                        Data Ascii: Not found


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        10192.168.2.24498632.19.198.224443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:15:37 UTC319OUTGET /weathermapdata/1/static/weather/Icons/MSIAWwA=/Teaser/cold.png HTTP/1.1
                                        Accept: */*
                                        Accept-Language: en-CH,en-US;q=0.7,en;q=0.3
                                        UA-CPU: AMD64
                                        Accept-Encoding: gzip, deflate
                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                        Host: assets.msn.com
                                        Connection: Keep-Alive
                                        2024-12-17 12:15:38 UTC1056INHTTP/1.1 200 OK
                                        Content-Type: image/png
                                        Last-Modified: Wed, 04 Sep 2024 02:01:40 GMT
                                        ETag: 0x8DCCC8584415B71
                                        Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0
                                        x-ms-request-id: a3d47320-c01e-00e5-27a7-fe77b7000000
                                        x-ms-version: 2009-09-19
                                        x-ms-lease-status: unlocked
                                        x-ms-blob-type: BlockBlob
                                        Access-Control-Expose-Headers: x-ms-request-id,Server,x-ms-version,Content-Type,Last-Modified,ETag,x-ms-lease-status,x-ms-blob-type,Content-Length,Date,Transfer-Encoding
                                        Access-Control-Allow-Origin: *
                                        Expires: Tue, 24 Dec 2024 08:47:41 GMT
                                        Date: Tue, 17 Dec 2024 12:15:38 GMT
                                        Content-Length: 4995
                                        Connection: close
                                        Alt-Svc: h3=":443"; ma=86400
                                        Akamai-Request-BC: [a=2.19.198.221,b=256978145,c=g,n=DE_HE_FRANKFURT,o=20940]
                                        Server-Timing: clientrtt; dur=85, clienttt; dur=0, origin; dur=0, cdntime; dur=0, wpo;dur=0,1s;dur=0
                                        Akamai-Cache-Status: Hit from child
                                        Akamai-Server-IP: 2.19.198.221
                                        Akamai-Request-ID: f512ce1
                                        Cache-Control: public, max-age=2592000
                                        Timing-Allow-Origin: *
                                        Akamai-GRN: 0.ddc61302.1734437738.f512ce1
                                        Vary: Origin
                                        2024-12-17 12:15:38 UTC4995INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 48 00 00 00 48 08 06 00 00 00 55 ed b3 47 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00 9a 9c 18 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 13 18 49 44 41 54 78 01 ed 5c 0b 90 1c c5 79 fe 7b 66 67 77 ef f6 de 9c 9e 1c b1 8e 93 84 90 84 2c 90 4c 2c 50 19 c9 0e 65 54 80 09 86 e0 8a 31 ae e0 57 82 ed a4 a4 32 a5 38 8e b1 90 13 62 28 17 06 57 30 51 e1 54 01 49 0c 89 a1 e0 1c 59 c6 36 05 3e 81 52 c6 58 82 3d 2b 88 b7 b5 12 a0 93 74 a7 bb db db e7 bc ba fd ff 3d dd b3 b3 a7 13 f7 d8 b3 ee 4c b9 55 ad 99 e9 99 9d 9d fe f6 ff bf ff d5 73 00 7f 6c 7f 6c ef f5 66 60 8f 61 4f 62 af c7 de 30 6f de bc 14 6e eb d6 ac 59 63 a9 f3 bf b7 c6 60 f6 36 9a b8 f5
                                        Data Ascii: PNGIHDRHHUGpHYssRGBgAMAaIDATx\y{fgw,L,PeT1W28b(W0QTIY6>RX=+t=LUsllf`aOb0onYc`6


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        11192.168.2.244986620.198.119.84443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:16:05 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 31 36 0d 0a 4d 53 2d 43 56 3a 20 37 34 69 30 69 37 36 6a 61 45 75 47 76 4b 73 74 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 31 65 38 39 38 66 37 33 62 31 31 36 63 37 39 66 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 316MS-CV: 74i0i76jaEuGvKst.1Context: 1e898f73b116c79f
                                        2024-12-17 12:16:05 UTC260OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 32 32 36 33 31 2e 34 31 36 39 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 30 30 31 38 30 30 31 32 41 38 34 34 37 39 41 41 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.22631.4169</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>00180012A84479AA</deviceName><followRetry>true</followRetry></agent></con
                                        2024-12-17 12:16:05 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 37 34 69 30 69 37 36 6a 61 45 75 47 76 4b 73 74 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 31 65 38 39 38 66 37 33 62 31 31 36 63 37 39 66 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 65 38 66 53 46 32 2b 58 73 50 78 59 6e 67 4e 44 61 6a 38 6e 65 44 52 7a 64 45 44 31 7a 70 7a 47 31 67 32 38 45 54 74 38 6d 72 79 74 54 63 54 50 54 32 63 54 36 6a 71 4b 4c 72 34 54 46 42 38 5a 54 57 67 52 52 4a 61 49 46 48 48 30 61 76 45 77 65 57 44 45 73 4c 43 73 67 64 70 4c 36 4c 53 67 4c 65 4f 31 79 70 48 57 55 2f 76 75 7a
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: 74i0i76jaEuGvKst.2Context: 1e898f73b116c79f<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAe8fSF2+XsPxYngNDaj8neDRzdED1zpzG1g28ETt8mrytTcTPT2cT6jqKLr4TFB8ZTWgRRJaIFHH0avEweWDEsLCsgdpL6LSgLeO1ypHWU/vuz
                                        2024-12-17 12:16:05 UTC224OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 31 30 34 34 34 37 39 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 37 34 69 30 69 37 36 6a 61 45 75 47 76 4b 73 74 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 31 65 38 39 38 66 37 33 62 31 31 36 63 37 39 66 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 1044479 197MS-CV: 74i0i76jaEuGvKst.3Context: 1e898f73b116c79f<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2024-12-17 12:16:06 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2024-12-17 12:16:06 UTC58INData Raw: 4d 53 2d 43 56 3a 20 75 7a 6c 6e 4b 47 43 61 33 6b 75 48 32 59 6a 53 4e 70 61 71 43 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: uzlnKGCa3kuH2YjSNpaqCg.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        12192.168.2.244986820.198.119.84443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:16:09 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 31 36 0d 0a 4d 53 2d 43 56 3a 20 41 75 39 72 53 58 46 37 73 30 61 73 70 6e 71 30 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 61 32 66 61 35 66 63 65 61 64 64 31 66 39 32 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 316MS-CV: Au9rSXF7s0aspnq0.1Context: 8a2fa5fceadd1f92
                                        2024-12-17 12:16:09 UTC260OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 32 32 36 33 31 2e 34 31 36 39 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 30 30 31 38 30 30 31 32 41 38 34 34 37 39 41 41 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.22631.4169</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>00180012A84479AA</deviceName><followRetry>true</followRetry></agent></con
                                        2024-12-17 12:16:09 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 41 75 39 72 53 58 46 37 73 30 61 73 70 6e 71 30 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 61 32 66 61 35 66 63 65 61 64 64 31 66 39 32 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 65 38 66 53 46 32 2b 58 73 50 78 59 6e 67 4e 44 61 6a 38 6e 65 44 52 7a 64 45 44 31 7a 70 7a 47 31 67 32 38 45 54 74 38 6d 72 79 74 54 63 54 50 54 32 63 54 36 6a 71 4b 4c 72 34 54 46 42 38 5a 54 57 67 52 52 4a 61 49 46 48 48 30 61 76 45 77 65 57 44 45 73 4c 43 73 67 64 70 4c 36 4c 53 67 4c 65 4f 31 79 70 48 57 55 2f 76 75 7a
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: Au9rSXF7s0aspnq0.2Context: 8a2fa5fceadd1f92<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAe8fSF2+XsPxYngNDaj8neDRzdED1zpzG1g28ETt8mrytTcTPT2cT6jqKLr4TFB8ZTWgRRJaIFHH0avEweWDEsLCsgdpL6LSgLeO1ypHWU/vuz
                                        2024-12-17 12:16:09 UTC224OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 31 30 34 34 34 37 39 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 41 75 39 72 53 58 46 37 73 30 61 73 70 6e 71 30 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 61 32 66 61 35 66 63 65 61 64 64 31 66 39 32 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 1044479 197MS-CV: Au9rSXF7s0aspnq0.3Context: 8a2fa5fceadd1f92<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2024-12-17 12:16:10 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2024-12-17 12:16:10 UTC58INData Raw: 4d 53 2d 43 56 3a 20 6a 75 33 5a 52 48 70 36 62 45 75 37 42 59 69 6c 61 64 56 59 52 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: ju3ZRHp6bEu7BYiladVYRw.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        13192.168.2.244986920.198.119.84443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:16:15 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 31 36 0d 0a 4d 53 2d 43 56 3a 20 4e 74 4c 55 4f 51 50 6a 44 45 6d 67 61 77 47 59 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 39 35 65 64 37 62 36 32 33 38 39 30 66 65 39 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 316MS-CV: NtLUOQPjDEmgawGY.1Context: b95ed7b623890fe9
                                        2024-12-17 12:16:15 UTC260OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 32 32 36 33 31 2e 34 31 36 39 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 30 30 31 38 30 30 31 32 41 38 34 34 37 39 41 41 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.22631.4169</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>00180012A84479AA</deviceName><followRetry>true</followRetry></agent></con
                                        2024-12-17 12:16:15 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4e 74 4c 55 4f 51 50 6a 44 45 6d 67 61 77 47 59 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 39 35 65 64 37 62 36 32 33 38 39 30 66 65 39 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 65 38 66 53 46 32 2b 58 73 50 78 59 6e 67 4e 44 61 6a 38 6e 65 44 52 7a 64 45 44 31 7a 70 7a 47 31 67 32 38 45 54 74 38 6d 72 79 74 54 63 54 50 54 32 63 54 36 6a 71 4b 4c 72 34 54 46 42 38 5a 54 57 67 52 52 4a 61 49 46 48 48 30 61 76 45 77 65 57 44 45 73 4c 43 73 67 64 70 4c 36 4c 53 67 4c 65 4f 31 79 70 48 57 55 2f 76 75 7a
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: NtLUOQPjDEmgawGY.2Context: b95ed7b623890fe9<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAe8fSF2+XsPxYngNDaj8neDRzdED1zpzG1g28ETt8mrytTcTPT2cT6jqKLr4TFB8ZTWgRRJaIFHH0avEweWDEsLCsgdpL6LSgLeO1ypHWU/vuz
                                        2024-12-17 12:16:15 UTC224OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 31 30 34 34 34 37 39 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 4e 74 4c 55 4f 51 50 6a 44 45 6d 67 61 77 47 59 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 39 35 65 64 37 62 36 32 33 38 39 30 66 65 39 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 1044479 197MS-CV: NtLUOQPjDEmgawGY.3Context: b95ed7b623890fe9<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2024-12-17 12:16:16 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2024-12-17 12:16:16 UTC58INData Raw: 4d 53 2d 43 56 3a 20 54 4f 72 4f 4b 34 7a 43 4d 45 4f 4b 4b 4a 59 53 36 2b 35 46 76 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: TOrOK4zCMEOKKJYS6+5Fvw.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        14192.168.2.244987120.198.119.84443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:16:31 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 31 36 0d 0a 4d 53 2d 43 56 3a 20 7a 71 52 45 39 49 50 2f 65 55 4f 38 71 43 50 46 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 31 62 61 39 38 30 37 66 30 32 61 37 35 62 61 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 316MS-CV: zqRE9IP/eUO8qCPF.1Context: 71ba9807f02a75ba
                                        2024-12-17 12:16:31 UTC260OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 32 32 36 33 31 2e 34 31 36 39 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 30 30 31 38 30 30 31 32 41 38 34 34 37 39 41 41 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.22631.4169</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>00180012A84479AA</deviceName><followRetry>true</followRetry></agent></con
                                        2024-12-17 12:16:31 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 7a 71 52 45 39 49 50 2f 65 55 4f 38 71 43 50 46 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 31 62 61 39 38 30 37 66 30 32 61 37 35 62 61 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 65 38 66 53 46 32 2b 58 73 50 78 59 6e 67 4e 44 61 6a 38 6e 65 44 52 7a 64 45 44 31 7a 70 7a 47 31 67 32 38 45 54 74 38 6d 72 79 74 54 63 54 50 54 32 63 54 36 6a 71 4b 4c 72 34 54 46 42 38 5a 54 57 67 52 52 4a 61 49 46 48 48 30 61 76 45 77 65 57 44 45 73 4c 43 73 67 64 70 4c 36 4c 53 67 4c 65 4f 31 79 70 48 57 55 2f 76 75 7a
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: zqRE9IP/eUO8qCPF.2Context: 71ba9807f02a75ba<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAe8fSF2+XsPxYngNDaj8neDRzdED1zpzG1g28ETt8mrytTcTPT2cT6jqKLr4TFB8ZTWgRRJaIFHH0avEweWDEsLCsgdpL6LSgLeO1ypHWU/vuz
                                        2024-12-17 12:16:31 UTC224OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 31 30 34 34 34 37 39 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 7a 71 52 45 39 49 50 2f 65 55 4f 38 71 43 50 46 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 31 62 61 39 38 30 37 66 30 32 61 37 35 62 61 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 1044479 197MS-CV: zqRE9IP/eUO8qCPF.3Context: 71ba9807f02a75ba<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2024-12-17 12:16:31 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2024-12-17 12:16:31 UTC58INData Raw: 4d 53 2d 43 56 3a 20 66 39 54 63 79 2b 69 74 73 30 79 53 43 73 35 75 68 4e 33 78 55 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: f9Tcy+its0ySCs5uhN3xUQ.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        15192.168.2.244987220.198.119.84443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:16:51 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 31 36 0d 0a 4d 53 2d 43 56 3a 20 54 63 58 36 2f 6b 7a 42 6a 30 53 4f 36 43 51 6b 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 36 63 30 64 63 34 36 37 66 38 34 36 39 31 36 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 316MS-CV: TcX6/kzBj0SO6CQk.1Context: 56c0dc467f846916
                                        2024-12-17 12:16:51 UTC260OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 32 32 36 33 31 2e 34 31 36 39 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 30 30 31 38 30 30 31 32 41 38 34 34 37 39 41 41 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.22631.4169</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>00180012A84479AA</deviceName><followRetry>true</followRetry></agent></con
                                        2024-12-17 12:16:51 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 54 63 58 36 2f 6b 7a 42 6a 30 53 4f 36 43 51 6b 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 36 63 30 64 63 34 36 37 66 38 34 36 39 31 36 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 65 38 66 53 46 32 2b 58 73 50 78 59 6e 67 4e 44 61 6a 38 6e 65 44 52 7a 64 45 44 31 7a 70 7a 47 31 67 32 38 45 54 74 38 6d 72 79 74 54 63 54 50 54 32 63 54 36 6a 71 4b 4c 72 34 54 46 42 38 5a 54 57 67 52 52 4a 61 49 46 48 48 30 61 76 45 77 65 57 44 45 73 4c 43 73 67 64 70 4c 36 4c 53 67 4c 65 4f 31 79 70 48 57 55 2f 76 75 7a
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: TcX6/kzBj0SO6CQk.2Context: 56c0dc467f846916<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAe8fSF2+XsPxYngNDaj8neDRzdED1zpzG1g28ETt8mrytTcTPT2cT6jqKLr4TFB8ZTWgRRJaIFHH0avEweWDEsLCsgdpL6LSgLeO1ypHWU/vuz
                                        2024-12-17 12:16:51 UTC224OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 31 30 34 34 34 37 39 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 54 63 58 36 2f 6b 7a 42 6a 30 53 4f 36 43 51 6b 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 36 63 30 64 63 34 36 37 66 38 34 36 39 31 36 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 1044479 197MS-CV: TcX6/kzBj0SO6CQk.3Context: 56c0dc467f846916<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2024-12-17 12:16:51 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2024-12-17 12:16:51 UTC58INData Raw: 4d 53 2d 43 56 3a 20 6c 6c 34 74 73 45 39 47 4f 45 32 54 63 79 37 38 6f 64 56 6d 72 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: ll4tsE9GOE2Tcy78odVmrg.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        16192.168.2.244987420.198.119.84443
                                        TimestampBytes transferredDirectionData
                                        2024-12-17 12:17:15 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 31 36 0d 0a 4d 53 2d 43 56 3a 20 63 70 66 6b 71 4a 79 6b 65 30 53 74 58 49 63 4d 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 65 63 39 32 36 38 65 31 35 36 65 30 61 34 32 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 316MS-CV: cpfkqJyke0StXIcM.1Context: 2ec9268e156e0a42
                                        2024-12-17 12:17:15 UTC260OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 32 32 36 33 31 2e 34 31 36 39 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 30 30 31 38 30 30 31 32 41 38 34 34 37 39 41 41 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.22631.4169</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>00180012A84479AA</deviceName><followRetry>true</followRetry></agent></con
                                        2024-12-17 12:17:15 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 63 70 66 6b 71 4a 79 6b 65 30 53 74 58 49 63 4d 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 65 63 39 32 36 38 65 31 35 36 65 30 61 34 32 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 65 38 66 53 46 32 2b 58 73 50 78 59 6e 67 4e 44 61 6a 38 6e 65 44 52 7a 64 45 44 31 7a 70 7a 47 31 67 32 38 45 54 74 38 6d 72 79 74 54 63 54 50 54 32 63 54 36 6a 71 4b 4c 72 34 54 46 42 38 5a 54 57 67 52 52 4a 61 49 46 48 48 30 61 76 45 77 65 57 44 45 73 4c 43 73 67 64 70 4c 36 4c 53 67 4c 65 4f 31 79 70 48 57 55 2f 76 75 7a
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: cpfkqJyke0StXIcM.2Context: 2ec9268e156e0a42<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAe8fSF2+XsPxYngNDaj8neDRzdED1zpzG1g28ETt8mrytTcTPT2cT6jqKLr4TFB8ZTWgRRJaIFHH0avEweWDEsLCsgdpL6LSgLeO1ypHWU/vuz
                                        2024-12-17 12:17:15 UTC224OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 31 30 34 34 34 37 39 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 63 70 66 6b 71 4a 79 6b 65 30 53 74 58 49 63 4d 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 65 63 39 32 36 38 65 31 35 36 65 30 61 34 32 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 1044479 197MS-CV: cpfkqJyke0StXIcM.3Context: 2ec9268e156e0a42<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2024-12-17 12:17:15 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2024-12-17 12:17:15 UTC58INData Raw: 4d 53 2d 43 56 3a 20 79 6a 61 78 77 79 4c 51 30 55 57 6a 6b 50 68 2f 43 78 48 2f 42 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: yjaxwyLQ0UWjkPh/CxH/BA.0Payload parsing failed.


                                        Click to jump to process

                                        Click to jump to process

                                        Click to dive into process behavior distribution

                                        Click to jump to process

                                        Target ID:0
                                        Start time:07:14:13
                                        Start date:17/12/2024
                                        Path:C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /Automation -Embedding
                                        Imagebase:0x7ff7dd9d0000
                                        File size:1'637'952 bytes
                                        MD5 hash:A9F0EC89897AC6C878D217DFB64CA752
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Target ID:16
                                        Start time:07:14:50
                                        Start date:17/12/2024
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                                        Imagebase:0x7ff6ce280000
                                        File size:3'001'952 bytes
                                        MD5 hash:290DF23002E9B52249B5549F0C668A86
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:moderate
                                        Has exited:false

                                        Target ID:18
                                        Start time:07:14:52
                                        Start date:17/12/2024
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=1728,i,5776590258799465979,17540366911350167540,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20241208-180523.718000 --mojo-platform-channel-handle=2148 /prefetch:11
                                        Imagebase:0x7ff6ce280000
                                        File size:3'001'952 bytes
                                        MD5 hash:290DF23002E9B52249B5549F0C668A86
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:moderate
                                        Has exited:false

                                        Target ID:23
                                        Start time:07:14:59
                                        Start date:17/12/2024
                                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        Wow64 process (32bit):false
                                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nhlnkc.com/api/v1/track/link/click/63bba6a47a3f62bf2d36bda8/emails.649b108787b7027f9ddac21f?link=https%3A%2F%2F%65%62%72%75%79%6F%6C%63%75%2E%63%6F%6D%2E%74%72%2Fnu/8165130/YWxlcnRzQDE3NHBvd2VyZ2xvYmFsLmNvbQ=="
                                        Imagebase:0x7ff6ce280000
                                        File size:3'001'952 bytes
                                        MD5 hash:290DF23002E9B52249B5549F0C668A86
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:moderate
                                        Has exited:true

                                        No disassembly